<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:29:29 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:3623 — Important: nodejs:12 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:3623</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22930)&lt;/p&gt;
&lt;p&gt;* nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22940)&lt;/p&gt;
&lt;p&gt;* c-ares: Missing input validation of host names may lead to domain hijacking (CVE-2021-3672)&lt;/p&gt;
&lt;p&gt;* nodejs: Improper handling of untypical characters in domain names (CVE-2021-22931)&lt;/p&gt;
&lt;p&gt;* nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite (CVE-2021-32803)&lt;/p&gt;
&lt;p&gt;* nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite (CVE-2021-32804)&lt;/p&gt;
&lt;p&gt;* nodejs: Incomplete validation of tls rejectUnauthorized parameter (CVE-2021-22939)&lt;/p&gt;
&lt;p&gt;* nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe (CVE-2021-23343)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs:12/nodejs: Make FIPS options always available (BZ#1993927)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22930)&lt;/p&gt;
&lt;p&gt;* nodejs: Use-after-free on close http2 on stream canceling (CVE-2021-22940)&lt;/p&gt;
&lt;p&gt;* c-ares: Missing input validation of host names may lead to domain hijacking (CVE-2021-3672)&lt;/p&gt;
&lt;p&gt;* nodejs: Improper handling of untypical characters in domain names (CVE-2021-22931)&lt;/p&gt;
&lt;p&gt;* nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite (CVE-2021-32803)&lt;/p&gt;
&lt;p&gt;* nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite (CVE-2021-32804)&lt;/p&gt;
&lt;p&gt;* nodejs: Incomplete validation of tls rejectUnauthorized parameter (CVE-2021-22939)&lt;/p&gt;
&lt;p&gt;* nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe (CVE-2021-23343)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs:12/nodejs: Make FIPS options always available (BZ#1993927)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:3623</guid>
    </item>
    <item>
      <title>certfr-2022-avi-510 — De multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-510</link>
      <description>certfr-2022-avi-510</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-510</guid>
    </item>
    <item>
      <title>EUVD-2026-173755</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-173755</link>
      <description>EUVD-2026-173755</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-173755</guid>
    </item>
    <item>
      <title>fkie_cve-2021-23343</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-23343</link>
      <description>&lt;p&gt;All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-23343</guid>
    </item>
    <item>
      <title>GHSA-hj48-42vr-x3v9 — Regular Expression Denial of Service in path-parse</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hj48-42vr-x3v9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: path-parse&lt;/p&gt;
&lt;p&gt;Affected versions of npm package `path-parse` are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: path-parse&lt;/p&gt;
&lt;p&gt;Affected versions of npm package `path-parse` are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hj48-42vr-x3v9</guid>
    </item>
    <item>
      <title>gsd-2021-23343</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-23343</link>
      <description>gsd-2021-23343</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-23343</guid>
    </item>
    <item>
      <title>OESA-2021-1262 — nodejs-path-parse security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1262</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nodejs-path-parse&lt;/p&gt;
&lt;p&gt;Node.js path.parse() ponyfill&#13;
&#13;
Security Fix(es):&#13;
&#13;
All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.(CVE-2021-23343)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: nodejs-path-parse&lt;/p&gt;
&lt;p&gt;Node.js path.parse() ponyfill&#13;
&#13;
Security Fix(es):&#13;
&#13;
All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.(CVE-2021-23343)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1262</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0657-1 — Security update for nodejs12</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0657-1</link>
      <description>&lt;p&gt;Security update for nodejs12&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs12&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0657-1</guid>
    </item>
    <item>
      <title>RHSA-2021:2865 — Red Hat Security Advisory: RHV Manager (ovirt-engine) security update [ovirt-4.4.7]</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:2865</link>
      <description>&lt;p&gt;nodejs-ua-parser-js: Regular expression denial of service via the regex nodejs-glob-parent: Regular expression denial of service nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe nodejs-underscore: Arbitrary code execution via the template function&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-ua-parser-js: Regular expression denial of service via the regex nodejs-glob-parent: Regular expression denial of service nodejs-path-parse: ReDoS via splitDeviceRe, splitTailRe and splitPathRe nodejs-underscore: Arbitrary code execution via the template function&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:2865</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:0531-1 — Security update for nodejs12</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:0531-1</link>
      <description>&lt;p&gt;Security update for nodejs12&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs12&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:0531-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0809 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</guid>
    </item>
  </channel>
</rss>
