<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:19:20 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:5171 — Moderate: nodejs:16 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:5171</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (16.13.1), nodejs-nodemon (2.0.15). (BZ#2027610)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs-json-schema: Prototype pollution vulnerability (CVE-2021-3918)&lt;/p&gt;
&lt;p&gt;* nodejs-ini: Prototype pollution via malicious INI file (CVE-2020-7788)&lt;/p&gt;
&lt;p&gt;* nodejs-glob-parent: Regular expression denial of service (CVE-2020-28469)&lt;/p&gt;
&lt;p&gt;* nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807)&lt;/p&gt;
&lt;p&gt;* normalize-url: ReDoS for data URLs (CVE-2021-33502)&lt;/p&gt;
&lt;p&gt;* llhttp: HTTP Request Smuggling due to spaces in headers (CVE-2021-22959)&lt;/p&gt;
&lt;p&gt;* llhttp: HTTP Request Smuggling when parsing the body of chunked requests (CVE-2021-22960)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (16.13.1), nodejs-nodemon (2.0.15). (BZ#2027610)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs-json-schema: Prototype pollution vulnerability (CVE-2021-3918)&lt;/p&gt;
&lt;p&gt;* nodejs-ini: Prototype pollution via malicious INI file (CVE-2020-7788)&lt;/p&gt;
&lt;p&gt;* nodejs-glob-parent: Regular expression denial of service (CVE-2020-28469)&lt;/p&gt;
&lt;p&gt;* nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807)&lt;/p&gt;
&lt;p&gt;* normalize-url: ReDoS for data URLs (CVE-2021-33502)&lt;/p&gt;
&lt;p&gt;* llhttp: HTTP Request Smuggling due to spaces in headers (CVE-2021-22959)&lt;/p&gt;
&lt;p&gt;* llhttp: HTTP Request Smuggling when parsing the body of chunked requests (CVE-2021-22960)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:5171</guid>
    </item>
    <item>
      <title>BIT-gulp-2020-28469 — Regular Expression Denial of Service (ReDoS)</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gulp-2020-28469</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gulp&lt;/p&gt;
&lt;p&gt;This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gulp&lt;/p&gt;
&lt;p&gt;This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gulp-2020-28469</guid>
    </item>
    <item>
      <title>certfr-2021-avi-791 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</link>
      <description>certfr-2021-avi-791</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</guid>
    </item>
    <item>
      <title>EUVD-2026-168452</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-168452</link>
      <description>EUVD-2026-168452</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-168452</guid>
    </item>
    <item>
      <title>fkie_cve-2020-28469</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-28469</link>
      <description>&lt;p&gt;This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-28469</guid>
    </item>
    <item>
      <title>GHSA-ww39-953v-wcq6 — glob-parent vulnerable to Regular Expression Denial of Service in enclosure regex</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ww39-953v-wcq6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: glob-parent&lt;/p&gt;
&lt;p&gt;This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: glob-parent&lt;/p&gt;
&lt;p&gt;This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ww39-953v-wcq6</guid>
    </item>
    <item>
      <title>gsd-2020-28469</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-28469</link>
      <description>gsd-2020-28469</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-28469</guid>
    </item>
    <item>
      <title>RHSA-2021:1499 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.2.3 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:1499</link>
      <description>&lt;p&gt;nodejs-glob-parent: Regular expression denial of service nodejs-underscore: Arbitrary code execution via the template function nodejs-is-svg: ReDoS via malicious string nodejs-netmask: improper input validation of octal input data nodejs-netmask: incorrectly parses an IP address that has octal integer with invalid character&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-glob-parent: Regular expression denial of service nodejs-underscore: Arbitrary code execution via the template function nodejs-is-svg: ReDoS via malicious string nodejs-netmask: improper input validation of octal input data nodejs-netmask: incorrectly parses an IP address that has octal integer with invalid character&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:1499</guid>
    </item>
    <item>
      <title>RHSA-2021:5171 — Red Hat Security Advisory: nodejs:16 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:5171</link>
      <description>&lt;p&gt;nodejs-ini: Prototype pollution via malicious INI file nodejs-glob-parent: Regular expression denial of service nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes nodejs-json-schema: Prototype pollution vulnerability llhttp: HTTP Request Smuggling due to spaces in headers llhttp: HTTP Request Smuggling when parsing the body of chunked requests nodejs-normalize-url: ReDoS for data URLs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-ini: Prototype pollution via malicious INI file nodejs-glob-parent: Regular expression denial of service nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes nodejs-json-schema: Prototype pollution vulnerability llhttp: HTTP Request Smuggling due to spaces in headers llhttp: HTTP Request Smuggling when parsing the body of chunked requests nodejs-normalize-url: ReDoS for data URLs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:5171</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1354 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1354</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1354</guid>
    </item>
  </channel>
</rss>
