<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:07:30.084635+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:73428</id>
    <title>ALSA-2026:73428 — Important: nodejs24 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T11:07:30.277028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: nodejs24, AlmaLinux:10: nodejs24-devel, AlmaLinux:10: nodejs24-docs, AlmaLinux:10: nodejs24-full-i18n, AlmaLinux:10: nodejs24-libs, AlmaLinux:10: nodejs24-npm</p>
<p>Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.</p>
<p>Security Fix(es):</p>
<p>* undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152)
  * undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961)
  * undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* nodejs24: Rebase to the latest Node.js 24 release [almalinux-10] (JIRA:AlmaLinux-249187)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:73428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</id>
    <title>certfr-2026-avi-1233 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T11:07:30.277108+00:00</updated>
    <content>certfr-2026-avi-1233</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ec11110</id>
    <title>Withdrawn: CLEANSTART-2026-EC11110 — undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier pa…</title>
    <updated>2026-10-02T11:07:30.277130+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-superset</p>
<p>Multiple security vulnerabilities affect the apache-superset package. undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ec11110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364022</id>
    <title>EUVD-2026-364022</title>
    <updated>2026-10-02T11:07:30.277155+00:00</updated>
    <content>EUVD-2026-364022</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-19534</id>
    <title>fkie_cve-2026-19534</title>
    <updated>2026-10-02T11:07:30.277168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-19534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rfgv-xxqx-mfg5</id>
    <title>GHSA-rfgv-xxqx-mfg5 — undici vulnerable to Denial of Service via unrequested WebSocket subprotocol</title>
    <updated>2026-10-02T11:07:30.277196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: undici</p>
<p>### Impact</p>
<p>The undici WebSocket client throws an uncaught `TypeError` during the opening handshake when a server's `101` response includes a `Sec-WebSocket-Protocol` header that the client never requested. The throw occurs in a `queueMicrotask` callback with no surrounding `try`/`catch`, so it propagates as an uncaught exception and terminates the Node.js process. This is a remote, unauthenticated denial of service against any application that opens a WebSocket to an attacker controlled or compromised server, or over a plaintext `ws://` connection subject to a machine-in-the-middle. It affects the default `new WebSocket(url)` usage, where no subprotocol is requested. Per RFC 6455 section 4.1, an unrequested subprotocol must fail the connection, not crash it.</p>
<p>All releases starting at undici 6.7.0 are affected.</p>
<p>### Patches</p>
<p>Upgrade to undici 6.28.1, 7.29.1, or 8.10.2.</p>
<p>### Workarounds</p>
<p>No workaround is available. The fix must be applied through an upgrade.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rfgv-xxqx-mfg5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:66008</id>
    <title>RHSA-2026:66008 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T11:07:30.277269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana: Grafana: Session takeover via Auth Proxy cache key collision undici: undici: Denial of Service due to orphaned response body in retry handler undici: undici: HTTP response splitting via retry interceptor undici: undici: Denial of Service via unrequested WebSocket subprotocol grafana: Grafana: Unauthorized public dashboard deletion across organizations undici: undici: Denial of Service via unbounded decompression of compressed responses undici: undici: Cross-user cookie disclosure via Set-Cookie caching undici: Undici: Response truncation and connection termination undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options undici: undici: Integrity failure due to caching of unsafe HTTP method responses undici: undici: Denial of Service via WebSocketStream unclean close</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:66008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:73428</id>
    <title>RHSA-2026:73428 — Red Hat Security Advisory: nodejs24 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T11:07:30.277303+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici: undici: Denial of Service via unrequested WebSocket subprotocol undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:73428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:73428</id>
    <title>RLSA-2026:73428 — Important: nodejs24 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T11:07:30.277322+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: nodejs24</p>
<p>Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.</p>
<p>Security Fix(es):</p>
<p>* undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152)</p>
<p>* undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961)</p>
<p>* undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* nodejs24: Rebase to the latest Node.js 24 release [rhel-10] (JIRA:Rocky Linux-249187)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:73428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-19534</id>
    <title>UBUNTU-CVE-2026-19534</title>
    <updated>2026-10-02T11:07:30.277349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-undici, Ubuntu:26.04:LTS: node-undici</p>
<p>undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-19534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</id>
    <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:07:30.277376+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596"/>
  </entry>
</feed>
