<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 11:12:30 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-03242</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03242</link>
      <description>bdu:2021-03242</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03242</guid>
    </item>
    <item>
      <title>certfr-2021-avi-943 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-943</link>
      <description>certfr-2021-avi-943</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-943</guid>
    </item>
    <item>
      <title>EUVD-2026-26197</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-26197</link>
      <description>EUVD-2026-26197</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-26197</guid>
    </item>
    <item>
      <title>fkie_cve-2021-29060</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-29060</link>
      <description>&lt;p&gt;A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-29060</guid>
    </item>
    <item>
      <title>GHSA-257v-vj4p-3w2h — Regular Expression Denial of Service (ReDOS)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-257v-vj4p-3w2h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: color-string&lt;/p&gt;
&lt;p&gt;In the npm package `color-string`, there is a  ReDos (Regular Expression Denial of Service) vulnerability regarding an exponential time complexity for
linearly increasing input lengths for `hwb()` color strings.&lt;/p&gt;
&lt;p&gt;Strings reaching more than 5000 characters would see several
milliseconds of processing time; strings reaching more than
50,000 characters began seeing 1500ms (1.5s) of processing time.&lt;/p&gt;
&lt;p&gt;The cause was due to a the regular expression that parses
hwb() strings - specifically, the hue value - where
the integer portion of the hue value used a 0-or-more quantifier
shortly thereafter followed by a 1-or-more quantifier.&lt;/p&gt;
&lt;p&gt;This caused excessive backtracking and a cartesian scan,
resulting in exponential time complexity given a linear
increase in input length.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: color-string&lt;/p&gt;
&lt;p&gt;In the npm package `color-string`, there is a  ReDos (Regular Expression Denial of Service) vulnerability regarding an exponential time complexity for
linearly increasing input lengths for `hwb()` color strings.&lt;/p&gt;
&lt;p&gt;Strings reaching more than 5000 characters would see several
milliseconds of processing time; strings reaching more than
50,000 characters began seeing 1500ms (1.5s) of processing time.&lt;/p&gt;
&lt;p&gt;The cause was due to a the regular expression that parses
hwb() strings - specifically, the hue value - where
the integer portion of the hue value used a 0-or-more quantifier
shortly thereafter followed by a 1-or-more quantifier.&lt;/p&gt;
&lt;p&gt;This caused excessive backtracking and a cartesian scan,
resulting in exponential time complexity given a linear
increase in input length.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-257v-vj4p-3w2h</guid>
    </item>
    <item>
      <title>gsd-2021-29060</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-29060</link>
      <description>gsd-2021-29060</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-29060</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-29060</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-29060</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-color-string, Ubuntu:20.04:LTS: node-color-string, Ubuntu:22.04:LTS: node-color-string, Ubuntu:24.04:LTS: node-color-string, Ubuntu:25.10: node-color-string, Ubuntu:26.04:LTS: node-color-string&lt;/p&gt;
&lt;p&gt;A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-color-string, Ubuntu:20.04:LTS: node-color-string, Ubuntu:22.04:LTS: node-color-string, Ubuntu:24.04:LTS: node-color-string, Ubuntu:25.10: node-color-string, Ubuntu:26.04:LTS: node-color-string&lt;/p&gt;
&lt;p&gt;A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-29060</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0809 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, Informationen offenzulegen, Informationen falsch darzustellen, einen Denial of Service Zustand herbeizuführen, Sicherheitsvorkehrungen zu umgehen, einen Cross-Site-Scripting-Angriff durchzuführen oder unbekannte Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0809</guid>
    </item>
  </channel>
</rss>
