<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:48:37 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:0548 — Moderate: nodejs:10 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:0548</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (10.23.1).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libuv: buffer overflow in realpath (CVE-2020-8252)&lt;/p&gt;
&lt;p&gt;* nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS (CVE-2020-7754)&lt;/p&gt;
&lt;p&gt;* nodejs-y18n: prototype pollution vulnerability (CVE-2020-7774)&lt;/p&gt;
&lt;p&gt;* nodejs-ini: prototype pollution via malicious INI file (CVE-2020-7788)&lt;/p&gt;
&lt;p&gt;* nodejs-dot-prop: prototype pollution (CVE-2020-8116)&lt;/p&gt;
&lt;p&gt;* nodejs: use-after-free in the TLS implementation (CVE-2020-8265)&lt;/p&gt;
&lt;p&gt;* npm: sensitive information exposure through logs (CVE-2020-15095)&lt;/p&gt;
&lt;p&gt;* nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function (CVE-2020-15366)&lt;/p&gt;
&lt;p&gt;* nodejs-yargs-parser: prototype pollution vulnerability (CVE-2020-7608)&lt;/p&gt;
&lt;p&gt;* nodejs: HTTP request smuggling via two copies of a header field in an http request (CVE-2020-8287)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (10.23.1).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libuv: buffer overflow in realpath (CVE-2020-8252)&lt;/p&gt;
&lt;p&gt;* nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS (CVE-2020-7754)&lt;/p&gt;
&lt;p&gt;* nodejs-y18n: prototype pollution vulnerability (CVE-2020-7774)&lt;/p&gt;
&lt;p&gt;* nodejs-ini: prototype pollution via malicious INI file (CVE-2020-7788)&lt;/p&gt;
&lt;p&gt;* nodejs-dot-prop: prototype pollution (CVE-2020-8116)&lt;/p&gt;
&lt;p&gt;* nodejs: use-after-free in the TLS implementation (CVE-2020-8265)&lt;/p&gt;
&lt;p&gt;* npm: sensitive information exposure through logs (CVE-2020-15095)&lt;/p&gt;
&lt;p&gt;* nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function (CVE-2020-15366)&lt;/p&gt;
&lt;p&gt;* nodejs-yargs-parser: prototype pollution vulnerability (CVE-2020-7608)&lt;/p&gt;
&lt;p&gt;* nodejs: HTTP request smuggling via two copies of a header field in an http request (CVE-2020-8287)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:0548</guid>
    </item>
    <item>
      <title>bdu:2021-02874</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-02874</link>
      <description>bdu:2021-02874</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-02874</guid>
    </item>
    <item>
      <title>certfr-2022-avi-510 — De multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-510</link>
      <description>certfr-2022-avi-510</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-510</guid>
    </item>
    <item>
      <title>EUVD-2026-176554</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-176554</link>
      <description>EUVD-2026-176554</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-176554</guid>
    </item>
    <item>
      <title>fkie_cve-2020-7788</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-7788</link>
      <description>&lt;p&gt;This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-7788</guid>
    </item>
    <item>
      <title>GHSA-qqgx-2p2h-9c37 — ini before 1.3.6 vulnerable to Prototype Pollution via ini.parse</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qqgx-2p2h-9c37</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ini&lt;/p&gt;
&lt;p&gt;### Overview
The `ini` npm package before version 1.3.6 has a Prototype Pollution vulnerability.&lt;/p&gt;
&lt;p&gt;If an attacker submits a malicious INI file to an application that parses it with `ini.parse`, they will pollute the prototype on the application. This can be exploited further depending on the context.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been patched in 1.3.6.&lt;/p&gt;
&lt;p&gt;### Steps to reproduce&lt;/p&gt;
&lt;p&gt;payload.ini
```
[__proto__]
polluted = &amp;#34;polluted&amp;#34;
```&lt;/p&gt;
&lt;p&gt;poc.js:
```
var fs = require(&amp;#39;fs&amp;#39;)
var ini = require(&amp;#39;ini&amp;#39;)&lt;/p&gt;
&lt;p&gt;var parsed = ini.parse(fs.readFileSync(&amp;#39;./payload.ini&amp;#39;, &amp;#39;utf-8&amp;#39;))
console.log(parsed)
console.log(parsed.__proto__)
console.log(polluted)
```&lt;/p&gt;
&lt;p&gt;```
&amp;gt; node poc.js
{}
{ polluted: &amp;#39;polluted&amp;#39; }
{ polluted: &amp;#39;polluted&amp;#39; }
polluted
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ini&lt;/p&gt;
&lt;p&gt;### Overview
The `ini` npm package before version 1.3.6 has a Prototype Pollution vulnerability.&lt;/p&gt;
&lt;p&gt;If an attacker submits a malicious INI file to an application that parses it with `ini.parse`, they will pollute the prototype on the application. This can be exploited further depending on the context.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been patched in 1.3.6.&lt;/p&gt;
&lt;p&gt;### Steps to reproduce&lt;/p&gt;
&lt;p&gt;payload.ini
```
[__proto__]
polluted = &amp;#34;polluted&amp;#34;
```&lt;/p&gt;
&lt;p&gt;poc.js:
```
var fs = require(&amp;#39;fs&amp;#39;)
var ini = require(&amp;#39;ini&amp;#39;)&lt;/p&gt;
&lt;p&gt;var parsed = ini.parse(fs.readFileSync(&amp;#39;./payload.ini&amp;#39;, &amp;#39;utf-8&amp;#39;))
console.log(parsed)
console.log(parsed.__proto__)
console.log(polluted)
```&lt;/p&gt;
&lt;p&gt;```
&amp;gt; node poc.js
{}
{ polluted: &amp;#39;polluted&amp;#39; }
{ polluted: &amp;#39;polluted&amp;#39; }
polluted
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qqgx-2p2h-9c37</guid>
    </item>
    <item>
      <title>gsd-2020-7788</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-7788</link>
      <description>gsd-2020-7788</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-7788</guid>
    </item>
    <item>
      <title>OESA-2022-1769 — nodejs security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1769</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nodejs, openEuler:20.03-LTS-SP3: nodejs&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like &amp;amp;quot;&amp;amp;lt;protocol&amp;amp;gt;://[&amp;amp;lt;user&amp;amp;gt;[:&amp;amp;lt;password&amp;amp;gt;]@]&amp;amp;lt;hostname&amp;amp;gt;[:&amp;amp;lt;port&amp;amp;gt;][:][/]&amp;amp;lt;path&amp;amp;gt;&amp;amp;quot;. The password value is not redacted and is printed to stdout and also to any generated log files.(CVE-2020-15095)&lt;/p&gt;
&lt;p&gt;This affects the package y18n before 3.2.2, 4.0.1 and 5.0.5. PoC by po6ix: const y18n = require( y18n )(); y18n.setLocale( proto ); y18n.updateLocale({polluted: true}); console.log(polluted); // true(CVE-2020-7774)&lt;/p&gt;
&lt;p&gt;This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.(CVE-2020-7754)&lt;/p&gt;
&lt;p&gt;This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.(CVE-2020-7788)&lt;/p&gt;
&lt;p&gt;json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ( Prototype Pollution )(CVE-2021-39…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nodejs, openEuler:20.03-LTS-SP3: nodejs&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like &amp;amp;quot;&amp;amp;lt;protocol&amp;amp;gt;://[&amp;amp;lt;user&amp;amp;gt;[:&amp;amp;lt;password&amp;amp;gt;]@]&amp;amp;lt;hostname&amp;amp;gt;[:&amp;amp;lt;port&amp;amp;gt;][:][/]&amp;amp;lt;path&amp;amp;gt;&amp;amp;quot;. The password value is not redacted and is printed to stdout and also to any generated log files.(CVE-2020-15095)&lt;/p&gt;
&lt;p&gt;This affects the package y18n before 3.2.2, 4.0.1 and 5.0.5. PoC by po6ix: const y18n = require( y18n )(); y18n.setLocale( proto ); y18n.updateLocale({polluted: true}); console.log(polluted); // true(CVE-2020-7774)&lt;/p&gt;
&lt;p&gt;This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.(CVE-2020-7754)&lt;/p&gt;
&lt;p&gt;This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.(CVE-2020-7788)&lt;/p&gt;
&lt;p&gt;json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ( Prototype Pollution )(CVE-2021-39…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1769</guid>
    </item>
    <item>
      <title>RHSA-2021:0421 — Red Hat Security Advisory: rh-nodejs14-nodejs security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0421</link>
      <description>&lt;p&gt;nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs: use-after-free in the TLS implementation c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS nodejs: HTTP request smuggling via two copies of a header field in an http request nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs: use-after-free in the TLS implementation c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS nodejs: HTTP request smuggling via two copies of a header field in an http request nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0421</guid>
    </item>
    <item>
      <title>RHSA-2021:0548 — Red Hat Security Advisory: nodejs:10 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0548</link>
      <description>&lt;p&gt;nodejs-yargs-parser: prototype pollution vulnerability nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs-dot-prop: prototype pollution libuv: buffer overflow in realpath nodejs: use-after-free in the TLS implementation nodejs: HTTP request smuggling via two copies of a header field in an http request npm: sensitive information exposure through logs nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-yargs-parser: prototype pollution vulnerability nodejs-npm-user-validate: improper input validation when validating user emails leads to ReDoS nodejs-y18n: prototype pollution vulnerability nodejs-ini: Prototype pollution via malicious INI file nodejs-dot-prop: prototype pollution libuv: buffer overflow in realpath nodejs: use-after-free in the TLS implementation nodejs: HTTP request smuggling via two copies of a header field in an http request npm: sensitive information exposure through logs nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0548</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-7788</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7788</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: node-ini, Ubuntu:16.04:LTS: node-ini, Ubuntu:18.04:LTS: node-ini, Ubuntu:20.04:LTS: node-ini, Ubuntu:22.04:LTS: node-ini, Ubuntu:24.04:LTS: node-ini, Ubuntu:25.10: node-ini, Ubuntu:26.04:LTS: node-ini&lt;/p&gt;
&lt;p&gt;This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: node-ini, Ubuntu:16.04:LTS: node-ini, Ubuntu:18.04:LTS: node-ini, Ubuntu:20.04:LTS: node-ini, Ubuntu:22.04:LTS: node-ini, Ubuntu:24.04:LTS: node-ini, Ubuntu:25.10: node-ini, Ubuntu:26.04:LTS: node-ini&lt;/p&gt;
&lt;p&gt;This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-7788</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1603 — IBM Tivoli Netcool/OMNIbus: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1603</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Tivoli Netcool/OMNIbus ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Tivoli Netcool/OMNIbus ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1603</guid>
    </item>
  </channel>
</rss>
