<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:14:33 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:0548 — Moderate: nodejs:10 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:0548</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (10.23.1).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libuv: buffer overflow in realpath (CVE-2020-8252)&lt;/p&gt;
&lt;p&gt;* nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS (CVE-2020-7754)&lt;/p&gt;
&lt;p&gt;* nodejs-y18n: prototype pollution vulnerability (CVE-2020-7774)&lt;/p&gt;
&lt;p&gt;* nodejs-ini: prototype pollution via malicious INI file (CVE-2020-7788)&lt;/p&gt;
&lt;p&gt;* nodejs-dot-prop: prototype pollution (CVE-2020-8116)&lt;/p&gt;
&lt;p&gt;* nodejs: use-after-free in the TLS implementation (CVE-2020-8265)&lt;/p&gt;
&lt;p&gt;* npm: sensitive information exposure through logs (CVE-2020-15095)&lt;/p&gt;
&lt;p&gt;* nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function (CVE-2020-15366)&lt;/p&gt;
&lt;p&gt;* nodejs-yargs-parser: prototype pollution vulnerability (CVE-2020-7608)&lt;/p&gt;
&lt;p&gt;* nodejs: HTTP request smuggling via two copies of a header field in an http request (CVE-2020-8287)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (10.23.1).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libuv: buffer overflow in realpath (CVE-2020-8252)&lt;/p&gt;
&lt;p&gt;* nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS (CVE-2020-7754)&lt;/p&gt;
&lt;p&gt;* nodejs-y18n: prototype pollution vulnerability (CVE-2020-7774)&lt;/p&gt;
&lt;p&gt;* nodejs-ini: prototype pollution via malicious INI file (CVE-2020-7788)&lt;/p&gt;
&lt;p&gt;* nodejs-dot-prop: prototype pollution (CVE-2020-8116)&lt;/p&gt;
&lt;p&gt;* nodejs: use-after-free in the TLS implementation (CVE-2020-8265)&lt;/p&gt;
&lt;p&gt;* npm: sensitive information exposure through logs (CVE-2020-15095)&lt;/p&gt;
&lt;p&gt;* nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function (CVE-2020-15366)&lt;/p&gt;
&lt;p&gt;* nodejs-yargs-parser: prototype pollution vulnerability (CVE-2020-7608)&lt;/p&gt;
&lt;p&gt;* nodejs: HTTP request smuggling via two copies of a header field in an http request (CVE-2020-8287)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:0548</guid>
    </item>
    <item>
      <title>bdu:2024-01510</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01510</link>
      <description>bdu:2024-01510</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01510</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0575 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575</link>
      <description>certfr-2024-avi-0575</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575</guid>
    </item>
    <item>
      <title>EUVD-2026-185774</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-185774</link>
      <description>EUVD-2026-185774</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-185774</guid>
    </item>
    <item>
      <title>fkie_cve-2020-7754</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7754</link>
      <description>&lt;p&gt;This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-7754</guid>
    </item>
    <item>
      <title>GHSA-pw54-mh39-w3hc — Regular expression denial of service in npm-user-validate</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pw54-mh39-w3hc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: npm-user-validate&lt;/p&gt;
&lt;p&gt;This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: npm-user-validate&lt;/p&gt;
&lt;p&gt;This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pw54-mh39-w3hc</guid>
    </item>
    <item>
      <title>gsd-2020-7754</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-7754</link>
      <description>gsd-2020-7754</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-7754</guid>
    </item>
    <item>
      <title>OESA-2022-1769 — nodejs security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1769</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nodejs, openEuler:20.03-LTS-SP3: nodejs&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like &amp;amp;quot;&amp;amp;lt;protocol&amp;amp;gt;://[&amp;amp;lt;user&amp;amp;gt;[:&amp;amp;lt;password&amp;amp;gt;]@]&amp;amp;lt;hostname&amp;amp;gt;[:&amp;amp;lt;port&amp;amp;gt;][:][/]&amp;amp;lt;path&amp;amp;gt;&amp;amp;quot;. The password value is not redacted and is printed to stdout and also to any generated log files.(CVE-2020-15095)&lt;/p&gt;
&lt;p&gt;This affects the package y18n before 3.2.2, 4.0.1 and 5.0.5. PoC by po6ix: const y18n = require( y18n )(); y18n.setLocale( proto ); y18n.updateLocale({polluted: true}); console.log(polluted); // true(CVE-2020-7774)&lt;/p&gt;
&lt;p&gt;This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.(CVE-2020-7754)&lt;/p&gt;
&lt;p&gt;This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.(CVE-2020-7788)&lt;/p&gt;
&lt;p&gt;json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ( Prototype Pollution )(CVE-2021-39…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nodejs, openEuler:20.03-LTS-SP3: nodejs&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like &amp;amp;quot;&amp;amp;lt;protocol&amp;amp;gt;://[&amp;amp;lt;user&amp;amp;gt;[:&amp;amp;lt;password&amp;amp;gt;]@]&amp;amp;lt;hostname&amp;amp;gt;[:&amp;amp;lt;port&amp;amp;gt;][:][/]&amp;amp;lt;path&amp;amp;gt;&amp;amp;quot;. The password value is not redacted and is printed to stdout and also to any generated log files.(CVE-2020-15095)&lt;/p&gt;
&lt;p&gt;This affects the package y18n before 3.2.2, 4.0.1 and 5.0.5. PoC by po6ix: const y18n = require( y18n )(); y18n.setLocale( proto ); y18n.updateLocale({polluted: true}); console.log(polluted); // true(CVE-2020-7774)&lt;/p&gt;
&lt;p&gt;This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.(CVE-2020-7754)&lt;/p&gt;
&lt;p&gt;This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.(CVE-2020-7788)&lt;/p&gt;
&lt;p&gt;json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ( Prototype Pollution )(CVE-2021-39…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1769</guid>
    </item>
    <item>
      <title>RHSA-2021:0421 — Red Hat Security Advisory: rh-nodejs14-nodejs security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0421</link>
      <description>&lt;p&gt;nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs: use-after-free in the TLS implementation c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS nodejs: HTTP request smuggling via two copies of a header field in an http request nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs: use-after-free in the TLS implementation c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS nodejs: HTTP request smuggling via two copies of a header field in an http request nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0421</guid>
    </item>
    <item>
      <title>RHSA-2021:0548 — Red Hat Security Advisory: nodejs:10 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0548</link>
      <description>&lt;p&gt;nodejs-yargs-parser: prototype pollution vulnerability nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs-dot-prop: prototype pollution libuv: buffer overflow in realpath nodejs: use-after-free in the TLS implementation nodejs: HTTP request smuggling via two copies of a header field in an http request npm: sensitive information exposure through logs nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-yargs-parser: prototype pollution vulnerability nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs-dot-prop: prototype pollution libuv: buffer overflow in realpath nodejs: use-after-free in the TLS implementation nodejs: HTTP request smuggling via two copies of a header field in an http request npm: sensitive information exposure through logs nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0548</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1591 — Juniper JUNOS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1591</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Juniper JUNOS ausnutzen, um einen Denial of Service  zu verursachen, Informationen offenzulegen, Privilegien zu erweitern und Sicherheitsmechanismen inklusive zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Juniper JUNOS ausnutzen, um einen Denial of Service  zu verursachen, Informationen offenzulegen, Privilegien zu erweitern und Sicherheitsmechanismen inklusive zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1591</guid>
    </item>
  </channel>
</rss>
