<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:05:14.460147+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</id>
    <title>certfr-2026-avi-1233 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T11:05:14.486483+00:00</updated>
    <content>certfr-2026-avi-1233</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bg21634</id>
    <title>Withdrawn: CLEANSTART-2026-BG21634 — Security fixes in langfuse-worker 3.216.0-r1</title>
    <updated>2026-10-02T11:05:14.486524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: langfuse-worker</p>
<p>Package langfuse-worker version 3.216.0-r1 fixes 29 vulnerabilities: ghsa-frvp-7c67-39w9, ghsa-p63j-vcc4-9vmv, ghsa-55q2-fjhq-7xh7, ghsa-c2j3-45gr-mqc4, CVE-2026-69192...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bg21634"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342741</id>
    <title>EUVD-2026-342741</title>
    <updated>2026-10-02T11:05:14.486557+00:00</updated>
    <content>EUVD-2026-342741</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-15157</id>
    <title>fkie_cve-2026-15157</title>
    <updated>2026-10-02T11:05:14.486570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob shapes from user input can reach the vulnerable path. This is the same defect class as CVE-2022-35948 and CVE-2026-1527, on a header sink that the earlier fixes did not cover. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-15157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m8rv-5g2x-5cg5</id>
    <title>GHSA-m8rv-5g2x-5cg5 — undici vulnerable to CRLF Injection via blob-like body 'type' property</title>
    <updated>2026-10-02T11:05:14.486596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: undici</p>
<p>### Impact</p>
<p>When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via `request()`, `stream()`, `pipeline()`, or `dispatch()`) with a `.type` derived from untrusted input, an attacker can inject CRLF sequences (`\r\n`) to append arbitrary HTTP headers and potentially smuggle a second request past the upstream.</p>
<p>The vulnerable branch in `lib/dispatcher/client-h1.js` pushes `body.type` directly into the outgoing headers with no validation, while every other header path in undici goes through `isValidHeaderValue()`:</p>
<p>```javascript
} else if (util.isBlobLike(body) &amp;&amp; request.contentType == null &amp;&amp; body.type) {
  headers.push('content-type', body.type)  // bypasses isValidHeaderValue()
}
```</p>
<p>The bug requires a hand-rolled duck-typed blob object or a Blob subclass with a controlled `.type`. Native `Blob` is safe because its constructor strips CRLF from `.type`. `fetch()` is unaffected because it validates via the `Headers` class. Ecosystem consumers that build duck-typed blob shapes from user input include `form-data-encoder`, `formdata-polyfill`, and `formdata-node`.</p>
<p>Same defect class as `CVE-2022-35948` (explicit `content-type` sink, fixed in undici 5.8.2) and `CVE-2026-1527` (`upgrade` option sink, fixed in 6.24.0 / 7.24.0), both closed by adding `isValidHeaderValue()` on their respective sinks. This branch was missed.</p>
<p>### Patches</p>
<p>Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later.</p>
<p>### Wor…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m8rv-5g2x-5cg5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-15157</id>
    <title>msrc_CVE-2026-15157 — undici vulnerable to CRLF Injection via blob-like body 'type' property</title>
    <updated>2026-10-02T11:05:14.486638+00:00</updated>
    <content>msrc_CVE-2026-15157</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-15157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:48273</id>
    <title>RHSA-2026:48273 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T11:05:14.486654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing undici: undici: HTTP header injection via unvalidated blob-like body type property undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length undici: Undici: Cookie attribute injection allows bypassing security protections nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw nodejs: Information disclosure due to improper permission enforcement nodejs: HTTPS Agent TLS session reuse skips hostname verification nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:48273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:4248-1</id>
    <title>SUSE-SU-2026:4248-1 — Security update for nodejs18</title>
    <updated>2026-10-02T11:05:14.486682+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs18</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:4248-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15157</id>
    <title>UBUNTU-CVE-2026-15157</title>
    <updated>2026-10-02T11:05:14.486707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-undici, Ubuntu:26.04:LTS: node-undici</p>
<p>undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob shapes from user input can reach the vulnerable path. This is the same defect class as CVE-2022-35948 and CVE-2026-1527, on a header sink that the earlier fixes did not cover. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</id>
    <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:05:14.486731+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596"/>
  </entry>
</feed>
