<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T03:39:50.339464+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337495</id>
    <title>EUVD-2026-337495</title>
    <updated>2026-10-06T03:39:50.387492+00:00</updated>
    <content>EUVD-2026-337495</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22774</id>
    <title>fkie_cve-2026-22774</title>
    <updated>2026-10-06T03:39:50.387531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted sources. This affects applications using devalue.parse on externally-supplied data. The root cause is the typed array hydration expecting an ArrayBuffer as input, but not checking the assumption before creating the typed array. This vulnerability is fixed in 5.6.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22774"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vw5p-8cq8-m7mv</id>
    <title>GHSA-vw5p-8cq8-m7mv — Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse</title>
    <updated>2026-10-06T03:39:50.387568+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: devalue</p>
<p>## Summary</p>
<p>Certain inputs can cause `devalue.parse` to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input from untrusted sources. This affects applications using `devalue.parse` on externally-supplied data. The root cause is the typed array hydration expecting an `ArrayBuffer` as input, but not checking the assumption before creating the typed array.</p>
<p>## Details</p>
<p>The parser's typed array hydration logic does not properly validate input before processing. Specially crafted inputs can cause disproportionate memory allocation or CPU usage on the receiving system.</p>
<p>## Impact</p>
<p>This is a denial of service vulnerability affecting systems that use `devalue.parse` to handle data from potentially untrusted sources.</p>
<p>Affected systems should upgrade to patched versions immediately.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vw5p-8cq8-m7mv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:2144</id>
    <title>RHSA-2026:2144 — Red Hat Security Advisory: RHTAS 1.3.2 - Red Hat Trusted Artifact Signer Release</title>
    <updated>2026-10-06T03:39:50.387601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate glob: glob: Command Injection Vulnerability via Malicious Filenames urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token github.com/sigstore/timestamp-authority: Sigstore Timestamp Authority: Denial of Service via excessive OID or Content-Type header parsing urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation devalue: devalue: Denial of Service due to excessive resource consumption from untrusted input devalue: devalue: Denial of Service due to improper input validation node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:2144"/>
  </entry>
</feed>
