<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:01:26 +0000</lastBuildDate>
    <item>
      <title>cnvd-2018-25046</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-25046</link>
      <description>cnvd-2018-25046</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-25046</guid>
    </item>
    <item>
      <title>EUVD-2026-173050</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-173050</link>
      <description>EUVD-2026-173050</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-173050</guid>
    </item>
    <item>
      <title>fkie_cve-2017-16031</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-16031</link>
      <description>&lt;p&gt;Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-16031</guid>
    </item>
    <item>
      <title>GHSA-qv2v-m59f-v5fw — Insecure randomness in socket.io</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qv2v-m59f-v5fw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: socket.io&lt;/p&gt;
&lt;p&gt;Affected versions of `socket.io` depend on `Math.random()` to create socket IDs, and therefore the IDs are predictable. With enough information on prior IDs, an attacker may be able to guess the socket ID and gain access to socket.io servers without authorization.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Update to v0.9.7 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: socket.io&lt;/p&gt;
&lt;p&gt;Affected versions of `socket.io` depend on `Math.random()` to create socket IDs, and therefore the IDs are predictable. With enough information on prior IDs, an attacker may be able to guess the socket ID and gain access to socket.io servers without authorization.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Update to v0.9.7 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qv2v-m59f-v5fw</guid>
    </item>
    <item>
      <title>gsd-2017-16031</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-16031</link>
      <description>gsd-2017-16031</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-16031</guid>
    </item>
  </channel>
</rss>
