<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 07:00:28 +0000</lastBuildDate>
    <item>
      <title>certfr-2022-avi-767 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-767</link>
      <description>certfr-2022-avi-767</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-767</guid>
    </item>
    <item>
      <title>cnvd-2020-51419</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-51419</link>
      <description>cnvd-2020-51419</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-51419</guid>
    </item>
    <item>
      <title>EUVD-2026-42636</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42636</link>
      <description>EUVD-2026-42636</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42636</guid>
    </item>
    <item>
      <title>fkie_cve-2020-15084</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15084</link>
      <description>&lt;p&gt;In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass. You are affected by this vulnerability if all of the following conditions apply: - You are using express-jwt - You do not have **algorithms** configured in your express-jwt configuration. - You are using libraries such as jwks-rsa as the **secret**. You can fix this by specifying **algorithms** in the express-jwt configuration. See linked GHSA for example. This is also fixed in version 6.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass. You are affected by this vulnerability if all of the following conditions apply: - You are using express-jwt - You do not have **algorithms** configured in your express-jwt configuration. - You are using libraries such as jwks-rsa as the **secret**. You can fix this by specifying **algorithms** in the express-jwt configuration. See linked GHSA for example. This is also fixed in version 6.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-15084</guid>
    </item>
    <item>
      <title>GHSA-6g6m-m6h5-w9gf — Authorization bypass in express-jwt</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6g6m-m6h5-w9gf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: express-jwt&lt;/p&gt;
&lt;p&gt;### Overview
Versions before and including 5.3.3, we are not enforcing the **algorithms** entry to be specified in the configuration.
When **algorithms** is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass.&lt;/p&gt;
&lt;p&gt;### Am I affected?
You are affected by this vulnerability if all of the following conditions apply:&lt;/p&gt;
&lt;p&gt;You are using express-jwt
AND 
You do not have **algorithms**  configured in your express-jwt configuration.
AND
You are using libraries such as jwks-rsa as the **secret**.&lt;/p&gt;
&lt;p&gt;### How to fix that?
Specify **algorithms** in the express-jwt configuration. The following is an example of a proper configuration&lt;/p&gt;
&lt;p&gt;``` 
const checkJwt = jwt({
  secret: jwksRsa.expressJwtSecret({
    rateLimit: true,
    jwksRequestsPerMinute: 5,
    jwksUri: `https://${DOMAIN}/.well-known/jwks.json`
  }),
  // Validate the audience and the issuer.
  audience: process.env.AUDIENCE,
  issuer: `https://${DOMAIN}/`,
  // restrict allowed algorithms
  algorithms: [&amp;#39;RS256&amp;#39;]
}); 
```&lt;/p&gt;
&lt;p&gt;### Will this update impact my users?
The fix provided in patch will not affect your users if you specified the algorithms allowed. The patch now makes **algorithms** a required configuration.&lt;/p&gt;
&lt;p&gt;### Credit
IST Group&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: express-jwt&lt;/p&gt;
&lt;p&gt;### Overview
Versions before and including 5.3.3, we are not enforcing the **algorithms** entry to be specified in the configuration.
When **algorithms** is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass.&lt;/p&gt;
&lt;p&gt;### Am I affected?
You are affected by this vulnerability if all of the following conditions apply:&lt;/p&gt;
&lt;p&gt;You are using express-jwt
AND 
You do not have **algorithms**  configured in your express-jwt configuration.
AND
You are using libraries such as jwks-rsa as the **secret**.&lt;/p&gt;
&lt;p&gt;### How to fix that?
Specify **algorithms** in the express-jwt configuration. The following is an example of a proper configuration&lt;/p&gt;
&lt;p&gt;``` 
const checkJwt = jwt({
  secret: jwksRsa.expressJwtSecret({
    rateLimit: true,
    jwksRequestsPerMinute: 5,
    jwksUri: `https://${DOMAIN}/.well-known/jwks.json`
  }),
  // Validate the audience and the issuer.
  audience: process.env.AUDIENCE,
  issuer: `https://${DOMAIN}/`,
  // restrict allowed algorithms
  algorithms: [&amp;#39;RS256&amp;#39;]
}); 
```&lt;/p&gt;
&lt;p&gt;### Will this update impact my users?
The fix provided in patch will not affect your users if you specified the algorithms allowed. The patch now makes **algorithms** a required configuration.&lt;/p&gt;
&lt;p&gt;### Credit
IST Group&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6g6m-m6h5-w9gf</guid>
    </item>
    <item>
      <title>gsd-2020-15084</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-15084</link>
      <description>gsd-2020-15084</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-15084</guid>
    </item>
  </channel>
</rss>
