<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T22:35:10.365245+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-363747</id>
    <title>EUVD-2026-363747</title>
    <updated>2026-10-06T22:35:10.442150+00:00</updated>
    <content>EUVD-2026-363747</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-363747"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-77465</id>
    <title>fkie_cve-2026-77465</title>
    <updated>2026-10-06T22:35:10.442195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions recurse through nested arrays and inline tables without a depth limit. A remote unauthenticated application parsing an attacker-controlled TOML document containing a few thousand nested arrays or inline tables can exhaust the Node.js call stack, raise an unexpected RangeError rather than the parser's SyntaxError, and terminate an unprotected request worker or process. The corresponding grammar source is src/toml.pegjs, where the generated parser must be bounded. This issue is fixed in version 4.2.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-77465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-82x6-q7mm-w9cf</id>
    <title>GHSA-82x6-q7mm-w9cf — toml-node: Uncontrolled Recursion</title>
    <updated>2026-10-06T22:35:10.442245+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: toml</p>
<p>### Summary</p>
<p>`toml.parse()` crashes with an uncaught `RangeError: Maximum call stack size exceeded` when parsing deeply nested arrays or inline tables. The parser is generated by **Peggy 5.1.0** (a PEG parser generator) as a recursive-descent parser; the value rule mutually recurses with the array and inline-table rules with **no depth limit**, so nesting depth equal to the input depth exhausts Node's call stack.</p>
<p>A small payload — a bare array nested a few thousand levels deep (**~5–6 KB**) — reliably crashes the process on a default Node.js configuration. `toml` has **~47 million monthly downloads**.</p>
<p>---</p>
<p>## Vulnerable Code</p>
<p>The parser is a **generated** recursive-descent parser (`lib/parser.js`, header: `// @generated by Peggy 5.1.0.`). The recursion sink is the mutual recursion between the `value`, `array`, and `inline_table` rule functions — none carry a depth counter:</p>
<p>```javascript
// lib/parser.js — peg$parsevalue() @ line 1008
function peg$parsevalue() {
  ...
  s0 = peg$parsearray();          // line 1017  ← value → array
  if (s0 === peg$FAILED) {
    s0 = peg$parseinline_table(); // line 1019  ← value → inline_table
  }
  ...
}</p>
<p>// peg$parsearray() @ line 2879
function peg$parsearray() {
  ...
  s3 = peg$parsevalue();          // line 2931  ← array element → value (back-edge)
  ...
}</p>
<p>// peg$parseinline_table() @ line 3066 → peg$parseinline_table_entry() @ line 3239
function peg$parseinline_table_entry() {
  ...
  s5 = peg$parsevalue();          // line 3266  ←…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-82x6-q7mm-w9cf"/>
  </entry>
</feed>
