<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:42:44 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-30434</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-30434</link>
      <description>EUVD-2026-30434</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-30434</guid>
    </item>
    <item>
      <title>fkie_cve-2021-39131</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-39131</link>
      <description>&lt;p&gt;ced detects character encoding using Google’s compact_enc_det library. In ced v0.1.0, passing data types other than `Buffer` causes the Node.js process to crash. The problem has been patched in ced v1.0.0. As a workaround, before passing an argument to ced, verify it’s a `Buffer` using `Buffer.isBuffer(obj)`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ced detects character encoding using Google’s compact_enc_det library. In ced v0.1.0, passing data types other than `Buffer` causes the Node.js process to crash. The problem has been patched in ced v1.0.0. As a workaround, before passing an argument to ced, verify it’s a `Buffer` using `Buffer.isBuffer(obj)`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-39131</guid>
    </item>
    <item>
      <title>GHSA-27wq-qx3q-fxm9 — Improper Handling of Unexpected Data Type in ced</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-27wq-qx3q-fxm9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ced&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In ced v0.1.0, passing data types other than `Buffer` causes the Node.js process to crash.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The problem has been patched in [ced v1.0.0](https://github.com/sonicdoe/ced/releases/tag/v1.0.0). You can upgrade from v0.1.0 without any breaking changes.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Before passing an argument to ced, verify it’s a `Buffer` using [`Buffer.isBuffer(obj)`](https://nodejs.org/api/buffer.html#buffer_static_method_buffer_isbuffer_obj).&lt;/p&gt;
&lt;p&gt;### CVSS score&lt;/p&gt;
&lt;p&gt;[CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:O/RC:C](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:O/RC:C)&lt;/p&gt;
&lt;p&gt;Base Score: 7.5 (High)
Temporal Score: 7.2 (High)&lt;/p&gt;
&lt;p&gt;Since ced is a library, the scoring is based on the “[reasonable worst-case implementation scenario](https://www.first.org/cvss/v3.1/user-guide#3-7-Scoring-Vulnerabilities-in-Software-Libraries-and-Similar)”, namely, accepting data from untrusted sources over a network and passing it directly to ced. Depending on your specific implementation, the vulnerability’s severity in your program may be different.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```js
const express = require(&amp;#34;express&amp;#34;);
const bodyParser = require(&amp;#34;body-parser&amp;#34;);
const ced = require(&amp;#34;ced&amp;#34;);&lt;/p&gt;
&lt;p&gt;const app = express();&lt;/p&gt;
&lt;p&gt;app.use(bodyParser.raw());&lt;/p&gt;
&lt;p&gt;app.post(&amp;#34;/&amp;#34;, (req, res) =&amp;gt; {
  const encoding = ced(req.body);&lt;/p&gt;
&lt;p&gt;res.end(encoding);
});&lt;/p&gt;
&lt;p&gt;app.listen(3000);
```&lt;/p&gt;
&lt;p&gt;`curl --request POST --header &amp;#34;Content-Type: text/plain&amp;#34; --data foo http://localhost:3000` crashes the se…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ced&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In ced v0.1.0, passing data types other than `Buffer` causes the Node.js process to crash.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The problem has been patched in [ced v1.0.0](https://github.com/sonicdoe/ced/releases/tag/v1.0.0). You can upgrade from v0.1.0 without any breaking changes.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Before passing an argument to ced, verify it’s a `Buffer` using [`Buffer.isBuffer(obj)`](https://nodejs.org/api/buffer.html#buffer_static_method_buffer_isbuffer_obj).&lt;/p&gt;
&lt;p&gt;### CVSS score&lt;/p&gt;
&lt;p&gt;[CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:O/RC:C](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:O/RC:C)&lt;/p&gt;
&lt;p&gt;Base Score: 7.5 (High)
Temporal Score: 7.2 (High)&lt;/p&gt;
&lt;p&gt;Since ced is a library, the scoring is based on the “[reasonable worst-case implementation scenario](https://www.first.org/cvss/v3.1/user-guide#3-7-Scoring-Vulnerabilities-in-Software-Libraries-and-Similar)”, namely, accepting data from untrusted sources over a network and passing it directly to ced. Depending on your specific implementation, the vulnerability’s severity in your program may be different.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```js
const express = require(&amp;#34;express&amp;#34;);
const bodyParser = require(&amp;#34;body-parser&amp;#34;);
const ced = require(&amp;#34;ced&amp;#34;);&lt;/p&gt;
&lt;p&gt;const app = express();&lt;/p&gt;
&lt;p&gt;app.use(bodyParser.raw());&lt;/p&gt;
&lt;p&gt;app.post(&amp;#34;/&amp;#34;, (req, res) =&amp;gt; {
  const encoding = ced(req.body);&lt;/p&gt;
&lt;p&gt;res.end(encoding);
});&lt;/p&gt;
&lt;p&gt;app.listen(3000);
```&lt;/p&gt;
&lt;p&gt;`curl --request POST --header &amp;#34;Content-Type: text/plain&amp;#34; --data foo http://localhost:3000` crashes the se…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-27wq-qx3q-fxm9</guid>
    </item>
    <item>
      <title>gsd-2021-39131</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-39131</link>
      <description>gsd-2021-39131</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-39131</guid>
    </item>
  </channel>
</rss>
