<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:08:40.890950+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0698</id>
    <title>certfr-2026-avi-0698 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T10:08:41.191691+00:00</updated>
    <content>certfr-2026-avi-0698</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221</id>
    <title>Withdrawn: CLEANSTART-2026-BE61221 — Security fixes for CVE-2025-62718, CVE-2025-69873, CVE-2026-29045, CVE-2026-29085, CVE-2026-29086, CVE-2026-29087, CVE-…</title>
    <updated>2026-10-02T10:08:41.191782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: opensearch-dashboards-fips</p>
<p>Multiple security vulnerabilities affect the opensearch-dashboards-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366083</id>
    <title>EUVD-2026-366083</title>
    <updated>2026-10-02T10:08:41.191877+00:00</updated>
    <content>EUVD-2026-366083</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42041</id>
    <title>fkie_cve-2026-42041</title>
    <updated>2026-10-02T10:08:41.191899+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript's in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () =&gt; true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42041"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w9j2-pvgh-6h63</id>
    <title>GHSA-w9j2-pvgh-6h63 — Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy</title>
    <updated>2026-10-02T10:08:41.191956+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: axios</p>
<p># Vulnerability Disclosure: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy</p>
<p>## Summary</p>
<p>The Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any `Object.prototype` pollution to **silently suppress all HTTP error responses** (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling.</p>
<p>The root cause is that `validateStatus` is the **only** config property using the `mergeDirectKeys` merge strategy, which uses JavaScript's `in` operator — an operator that inherently traverses the prototype chain. When `Object.prototype.validateStatus` is polluted with `() =&gt; true`, all HTTP status codes are accepted as success.</p>
<p>**Severity:** High (CVSS 8.2)
**Affected Versions:** All versions (v0.x - v1.x including v1.15.0)
**Vulnerable Component:** `lib/core/mergeConfig.js` (`mergeDirectKeys` strategy) + `lib/core/settle.js`</p>
<p>## CWE</p>
<p>- **CWE-1321:** Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- **CWE-287:** Improper Authentication</p>
<p>## CVSS 3.1</p>
<p>**Score: 8.2 (High)**</p>
<p>Vector: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N`</p>
<p>| Metric | Value | Justification |
|---|---|---|
| Attack Vector | Network | PP is triggered remotely |
| Attack Complexity | Low | Once PP exists, a single property assignment exploits this. Consistent with GHSA-fvcv-3m26-pcqx |
| Privileges Required | None | No au…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w9j2-pvgh-6h63"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</id>
    <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
    <updated>2026-10-02T10:08:41.192191+00:00</updated>
    <content>NCSC-2026-0325</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20919-1</id>
    <title>openSUSE-SU-2026:20919-1 — Security update for agama-web-ui</title>
    <updated>2026-10-02T10:08:41.192403+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for agama-web-ui</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20919-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:14937</id>
    <title>RHSA-2026:14937 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
    <updated>2026-10-02T10:08:41.192434+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option axios: Axios: Remote Code Execution via Prototype Pollution escalation follow-redirects: follow-redirects: Information disclosure via cross-domain redirects axios: Axios: HTTP Transport Hijacking via Prototype Pollution axios: Axios: Arbitrary HTTP header injection via prototype pollution axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling axi…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:14937"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42041</id>
    <title>UBUNTU-CVE-2026-42041</title>
    <updated>2026-10-02T10:08:41.192525+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:25.10: node-axios, Ubuntu:Pro:26.04:LTS: node-axios</p>
<p>Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript's in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () =&gt; true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42041"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1450</id>
    <title>WID-SEC-W-2026-1450 — IBM App Connect Enterprise (Axios): Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:08:41.192591+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, wodurch weitere Angriffe möglich werden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1450"/>
  </entry>
</feed>
