<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:01:18.948115+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:71543</id>
    <title>ALSA-2026:71543 — Important: cockpit-image-builder security update</title>
    <updated>2026-10-02T10:01:19.290570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: cockpit-image-builder</p>
<p>The image-builder-frontend generates custom images suitable for deploying systems or uploading to the cloud. It integrates into Cockpit as a frontend for osbuild.</p>
<p>Security Fix(es):</p>
<p>* fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)
  * fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)
  * fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)
  * fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:71543"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</id>
    <title>certfr-2026-avi-1233 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T10:01:19.290671+00:00</updated>
    <content>certfr-2026-avi-1233</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-lz46216</id>
    <title>CLEANSTART-2026-LZ46216 — fast-uri is a URI parser for Node</title>
    <updated>2026-10-02T10:01:19.290718+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: langfuse</p>
<p>Security vulnerability affects the langfuse package. fast-uri is a URI parser for Node.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-lz46216"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-358129</id>
    <title>EUVD-2026-358129</title>
    <updated>2026-10-02T10:01:19.290764+00:00</updated>
    <content>EUVD-2026-358129</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-358129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-76172</id>
    <title>fkie_cve-2026-76172</title>
    <updated>2026-10-02T10:01:19.290780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme carries percent-encoded slashes parses as a scheme with no authority, so the parsed host and error are both undefined, yet resolving or normalizing that same input emits a network-path reference whose authority is attacker-chosen and re-parses to that host. An application that allowlists on the parsed host, or treats a reference with no authority as safe to resolve against its base, gets the opposite of what it checked, giving an off-site redirect, server-side request forgery, or address-policy bypass. The legacy decoder also expands non-standard escape forms, widening the issue past upstream filters, and control characters in the scheme can reach the output as raw carriage return and line feed. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which reject a scheme that is not valid after decoding. Users should upgrade to a patched version.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-76172"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jqff-g426-hqxp</id>
    <title>GHSA-jqff-g426-hqxp — fast-uri vulnerable to host confusion via percent-encoded scheme normalization</title>
    <updated>2026-10-02T10:01:19.290811+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: fast-uri</p>
<p>### Impact</p>
<p>`fast-uri` decodes percent-encoded characters in the scheme component with the legacy global `unescape()` and serializes the result back as raw characters, without re-escaping it or validating it as a scheme. A scheme that decodes to characters outside the RFC 3986 scheme grammar can therefore introduce structure the original input did not contain.</p>
<p>For example, `%2f%2fevil.example:/pwn` parses with no authority (`parse().host` is `undefined`), but `resolve()` and `normalize()` return `//evil.example:/pwn`, which reparses with host `evil.example`. The `%uXXXX` form (`%u002f%u002fevil.example:/pwn`) produces the same result, and a scheme containing `%0d%0a` reaches the output as a raw CR LF.</p>
<p>Applications that normalize or resolve untrusted URLs before a redirect check, host allowlist, or outbound request decision, especially ones that treat a missing authority as same-origin, can be steered to an attacker-chosen authority, and a normalized URI placed in a response header can carry an injected CR LF.</p>
<p>### Patches</p>
<p>Upgrade to `fast-uri` &gt;= 4.1.3, or &gt;= 3.1.6 in the v3.x release line, or &gt;= 2.4.5 in the v2.x release line.</p>
<p>### Workarounds</p>
<p>None. Upgrade to the patched version.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jqff-g426-hqxp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:60855</id>
    <title>RHSA-2026:60855 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T10:01:19.290849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-uri: fast-uri: URI authority bypass due to improper delimiter handling fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:60855"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:71543</id>
    <title>RLSA-2026:71543 — Important: cockpit-image-builder security update</title>
    <updated>2026-10-02T10:01:19.290875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: cockpit-image-builder</p>
<p>The image-builder-frontend generates custom images suitable for deploying systems or uploading to the cloud. It integrates into Cockpit as a frontend for osbuild.</p>
<p>Security Fix(es):</p>
<p>* fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)</p>
<p>* fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)</p>
<p>* fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)</p>
<p>* fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:71543"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-76172</id>
    <title>UBUNTU-CVE-2026-76172</title>
    <updated>2026-10-02T10:01:19.290902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-ajv, Ubuntu:20.04:LTS: node-ajv, Ubuntu:22.04:LTS: node-ajv, Ubuntu:24.04:LTS: node-ajv, Ubuntu:26.04:LTS: node-ajv</p>
<p>fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme carries percent-encoded slashes parses as a scheme with no authority, so the parsed host and error are both undefined, yet resolving or normalizing that same input emits a network-path reference whose authority is attacker-chosen and re-parses to that host. An application that allowlists on the parsed host, or treats a reference with no authority as safe to resolve against its base, gets the opposite of what it checked, giving an off-site redirect, server-side request forgery, or address-policy bypass. The legacy decoder also expands non-standard escape forms, widening the issue past upstream filters, and control characters in the scheme can reach the output as raw carriage return and line feed. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which reject a scheme that is not valid after decoding. Users should upgrade to a patched version.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-76172"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3376</id>
    <title>WID-SEC-W-2026-3376 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management: Mehrere Schwachst…</title>
    <updated>2026-10-02T10:01:19.290935+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, serverseitige Request-Forgery-Angriffe (SSRF) durchzuführen, Cross-Site-Scripting-Angriffe zu starten, sensible Informationen offenzulegen, Daten zu manipulieren oder Denial-of-Service-Zustände herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3376"/>
  </entry>
</feed>
