<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:20:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-181182</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-181182</link>
      <description>EUVD-2026-181182</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-181182</guid>
    </item>
    <item>
      <title>fkie_cve-2018-3750</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-3750</link>
      <description>&lt;p&gt;The utilities function in all versions &amp;lt;= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The utilities function in all versions &amp;lt;= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-3750</guid>
    </item>
    <item>
      <title>GHSA-hr2v-3952-633q — Prototype Pollution in deep-extend</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hr2v-3952-633q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: deep-extend&lt;/p&gt;
&lt;p&gt;Versions of `deep-extend` before 0.5.1 are vulnerable to prototype pollution.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Update to version 0.5.1 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: deep-extend&lt;/p&gt;
&lt;p&gt;Versions of `deep-extend` before 0.5.1 are vulnerable to prototype pollution.&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;Update to version 0.5.1 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hr2v-3952-633q</guid>
    </item>
    <item>
      <title>gsd-2018-3750</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-3750</link>
      <description>gsd-2018-3750</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-3750</guid>
    </item>
    <item>
      <title>RHSA-2020:2625 — Red Hat Security Advisory: rh-nodejs8-nodejs security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:2625</link>
      <description>&lt;p&gt;nodejs-brace-expansion: Regular expression denial of service nodejs-chownr: TOCTOU vulnerability in `chownr` function in chownr.js nodejs-sshpk: ReDoS when parsing crafted invalid public keys in lib/formats/ssh.js nodejs-deep-extend: Prototype pollution can allow attackers to modify object properties npm: Symlink reference outside of node_modules folder through the bin field upon installation npm: Arbitrary file write via constructed entry in the package.json bin field npm: Global node_modules Binary Overwrite&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-brace-expansion: Regular expression denial of service nodejs-chownr: TOCTOU vulnerability in `chownr` function in chownr.js nodejs-sshpk: ReDoS when parsing crafted invalid public keys in lib/formats/ssh.js nodejs-deep-extend: Prototype pollution can allow attackers to modify object properties npm: Symlink reference outside of node_modules folder through the bin field upon installation npm: Arbitrary file write via constructed entry in the package.json bin field npm: Global node_modules Binary Overwrite&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:2625</guid>
    </item>
    <item>
      <title>RHSA-2021:0549 — Red Hat Security Advisory: nodejs:12 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0549</link>
      <description>&lt;p&gt;nodejs-deep-extend: Prototype pollution can allow attackers to modify object properties nodejs-mixin-deep: prototype pollution in function mixin-deep nodejs-set-value: prototype pollution in function set-value nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-ini: Prototype pollution via malicious INI file nodejs: use-after-free in the TLS implementation nodejs: HTTP request smuggling via two copies of a header field in an http request&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-deep-extend: Prototype pollution can allow attackers to modify object properties nodejs-mixin-deep: prototype pollution in function mixin-deep nodejs-set-value: prototype pollution in function set-value nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-ini: Prototype pollution via malicious INI file nodejs: use-after-free in the TLS implementation nodejs: HTTP request smuggling via two copies of a header field in an http request&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0549</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-3750</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-3750</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-deep-extend&lt;/p&gt;
&lt;p&gt;The utilities function in all versions &amp;lt;= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-deep-extend&lt;/p&gt;
&lt;p&gt;The utilities function in all versions &amp;lt;= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-3750</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2183 — Red Hat Software Collections: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2183</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Software Collections ausnutzen, um die Vertraulichkeit, Verfügbarkeit und die Integrität der Anwendungen zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Software Collections ausnutzen, um die Vertraulichkeit, Verfügbarkeit und die Integrität der Anwendungen zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2183</guid>
    </item>
  </channel>
</rss>
