<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:53:47 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:4796 — Important: nodejs:16 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:4796</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* npm: npm ci succeeds when package-lock.json doesn&amp;#39;t match package.json (CVE-2021-43616)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* npm: npm ci succeeds when package-lock.json doesn&amp;#39;t match package.json (CVE-2021-43616)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:4796</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-43616 — CVE-2021-43616 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-43616</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-43616</guid>
    </item>
    <item>
      <title>certfr-2022-avi-278 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
discover. Certaines d'entre elles permettent à un att…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-278</link>
      <description>certfr-2022-avi-278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-278</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-FF52474 — Security fix for CVE-2021-43616 applied in: npm 8.1.4-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ff52474</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: npm&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the npm package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: npm&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the npm package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ff52474</guid>
    </item>
    <item>
      <title>EUVD-2026-32647</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-32647</link>
      <description>EUVD-2026-32647</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-32647</guid>
    </item>
    <item>
      <title>fkie_cve-2021-43616</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43616</link>
      <description>&lt;p&gt;The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-43616</guid>
    </item>
    <item>
      <title>GHSA-ppxp-px5q-gwqm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ppxp-px5q-gwqm</link>
      <description>&lt;p&gt;The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ppxp-px5q-gwqm</guid>
    </item>
    <item>
      <title>gsd-2021-43616</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-43616</link>
      <description>gsd-2021-43616</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-43616</guid>
    </item>
    <item>
      <title>RHSA-2022:4796 — Red Hat Security Advisory: nodejs:16 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:4796</link>
      <description>&lt;p&gt;npm: npm ci succeeds when package-lock.json doesn&amp;#39;t match package.json&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;npm: npm ci succeeds when package-lock.json doesn&amp;#39;t match package.json&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:4796</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-43616</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43616</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: npm, Ubuntu:24.04:LTS: npm, Ubuntu:25.10: npm, Ubuntu:26.04:LTS: npm&lt;/p&gt;
&lt;p&gt;The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: npm, Ubuntu:24.04:LTS: npm, Ubuntu:25.10: npm, Ubuntu:26.04:LTS: npm&lt;/p&gt;
&lt;p&gt;The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43616</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2278 — npm: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2278</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in npm ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in npm ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2278</guid>
    </item>
  </channel>
</rss>
