<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:34:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-168103</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-168103</link>
      <description>EUVD-2026-168103</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-168103</guid>
    </item>
    <item>
      <title>fkie_cve-2021-23518</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-23518</link>
      <description>&lt;p&gt;The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-23518</guid>
    </item>
    <item>
      <title>GHSA-wg6g-ppvx-927h — Prototype Pollution in cached-path-relative</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wg6g-ppvx-927h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: cached-path-relative&lt;/p&gt;
&lt;p&gt;The package cached-path-relative before 1.1.0 is vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: cached-path-relative&lt;/p&gt;
&lt;p&gt;The package cached-path-relative before 1.1.0 is vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wg6g-ppvx-927h</guid>
    </item>
    <item>
      <title>gsd-2021-23518</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-23518</link>
      <description>gsd-2021-23518</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-23518</guid>
    </item>
    <item>
      <title>RHSA-2022:1476 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4.3 security updates and bug fixes</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:1476</link>
      <description>&lt;p&gt;cached-path-relative: Prototype Pollution via the cache variable nanoid: Information disclosure via valueOf() function opencontainers: OCI manifest and index parsing confusion golang.org/x/crypto: empty plaintext packet causes panic nodejs-shelljs: improper privilege management follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor node-fetch: exposure of sensitive information to an unauthorized actor follow-redirects: Exposure of Sensitive Information via Authorization Header leak openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates nats-server: misusing the &amp;#34;dynamically provisioned sandbox accounts&amp;#34; feature  authenticated user can obtain the privileges of the System account imgcrypt: Unauthorized access to encryted container image on a shared system due to missing check in CheckAuthorization() code path golang: crash in a golang.org/x/crypto/ssh server&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cached-path-relative: Prototype Pollution via the cache variable nanoid: Information disclosure via valueOf() function opencontainers: OCI manifest and index parsing confusion golang.org/x/crypto: empty plaintext packet causes panic nodejs-shelljs: improper privilege management follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor node-fetch: exposure of sensitive information to an unauthorized actor follow-redirects: Exposure of Sensitive Information via Authorization Header leak openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates nats-server: misusing the &amp;#34;dynamically provisioned sandbox accounts&amp;#34; feature  authenticated user can obtain the privileges of the System account imgcrypt: Unauthorized access to encryted container image on a shared system due to missing check in CheckAuthorization() code path golang: crash in a golang.org/x/crypto/ssh server&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:1476</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-23518</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23518</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-cached-path-relative, Ubuntu:20.04:LTS: node-cached-path-relative, Ubuntu:22.04:LTS: node-cached-path-relative, Ubuntu:24.04:LTS: node-cached-path-relative, Ubuntu:25.10: node-cached-path-relative, Ubuntu:26.04:LTS: node-cached-path-relative&lt;/p&gt;
&lt;p&gt;The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-cached-path-relative, Ubuntu:20.04:LTS: node-cached-path-relative, Ubuntu:22.04:LTS: node-cached-path-relative, Ubuntu:24.04:LTS: node-cached-path-relative, Ubuntu:25.10: node-cached-path-relative, Ubuntu:26.04:LTS: node-cached-path-relative&lt;/p&gt;
&lt;p&gt;The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23518</guid>
    </item>
  </channel>
</rss>
