<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T16:47:00.070233+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-354748</id>
    <title>EUVD-2026-354748</title>
    <updated>2026-10-09T16:47:00.123004+00:00</updated>
    <content>EUVD-2026-354748</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-354748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73561</id>
    <title>fkie_cve-2026-73561</title>
    <updated>2026-10-09T16:47:00.123044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadDefaultConnectionEventListeners to call requestClientId, which calls rpc.send for the get-client-id action and pushes a request into RPC.requests. The RPC.waitForReply function starts a setInterval polling loop every 10 milliseconds that is cleared only after a matching reply; if the client remains silent and closes, the timer and pending request stay allocated because the socket close path does not cancel them. Repeated connections therefore cause unbounded timers and heap entries, exhausting CPU and memory and making the server unavailable. This issue is fixed in version 0.2.16.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g5vv-q72c-7j78</id>
    <title>GHSA-g5vv-q72c-7j78 — @anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion</title>
    <updated>2026-10-09T16:47:00.123080+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @anephenix/hub</p>
<p>### Summary</p>
<p>`@anephenix/hub` starts a `setInterval` polling loop for every incoming WebSocket connection to request a client ID via RPC. If the remote client never replies — which requires no authentication or special configuration — the interval and the pending request object are never cleaned up, even after the socket is closed. An unauthenticated attacker who opens many WebSocket connections and ignores all server RPC messages will therefore cause the server to accumulate unbounded timers and heap entries, leading to CPU and memory exhaustion (DoS).</p>
<p>### Details</p>
<p>When a client connects, `loadDefaultConnectionEventListeners` (registered in `src/lib/index.ts:128`) adds a connection listener that calls `requestClientId({ ws, rpc })` for every new WebSocket (`src/lib/index.ts:262`). `requestClientId` issues an RPC send for the `get-client-id` action (`src/lib/clientId.ts:112`), which internally calls `rpc.send`.</p>
<p>Inside `rpc.send`, the payload is pushed onto `this.requests` (`src/lib/rpc.ts:282`) and `waitForReply` is invoked. `waitForReply` starts a `setInterval` that polls `responses[]` every 10 ms for a matching reply (`src/lib/rpc.ts:250`):</p>
<p>```ts
// src/lib/rpc.ts:250–267
interval = setInterval(() =&gt; {
    const response = responses.find(
        (r) =&gt; r.id === id &amp;&amp; r.action === action,
    );
    if (response) {
        if (interval) clearInterval(interval);
        // ... resolve and cleanup
        this.cleanupRPCCall(response);
    }
}, 10);
```</p>
<p>`clearInterval` i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g5vv-q72c-7j78"/>
  </entry>
</feed>
