<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:57:59 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:0050 — Moderate: nodejs:14 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:0050</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (14.21.1), nodejs-nodemon (2.0.20).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* minimist: prototype pollution (CVE-2021-44906)
* node-fetch: exposure of sensitive information to an unauthorized actor (CVE-2022-0235)
* nodejs-minimatch: ReDoS via the braceExpand function (CVE-2022-3517)
* express: &amp;#34;qs&amp;#34; prototype poisoning causes the hang of the node process (CVE-2022-24999)
* nodejs: DNS rebinding in inspect via invalid octal IP address (CVE-2022-43548)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (14.21.1), nodejs-nodemon (2.0.20).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* minimist: prototype pollution (CVE-2021-44906)
* node-fetch: exposure of sensitive information to an unauthorized actor (CVE-2022-0235)
* nodejs-minimatch: ReDoS via the braceExpand function (CVE-2022-3517)
* express: &amp;#34;qs&amp;#34; prototype poisoning causes the hang of the node process (CVE-2022-24999)
* nodejs: DNS rebinding in inspect via invalid octal IP address (CVE-2022-43548)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:0050</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1025 — De multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1025</link>
      <description>certfr-2022-avi-1025</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1025</guid>
    </item>
    <item>
      <title>EUVD-2026-10804</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-10804</link>
      <description>EUVD-2026-10804</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-10804</guid>
    </item>
    <item>
      <title>fkie_cve-2022-0235</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-0235</link>
      <description>&lt;p&gt;node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-0235</guid>
    </item>
    <item>
      <title>GHSA-r683-j2x4-v87g — node-fetch forwards secure headers to untrusted sites</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r683-j2x4-v87g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: node-fetch&lt;/p&gt;
&lt;p&gt;node-fetch forwards secure headers such as `authorization`, `www-authenticate`, `cookie`, &amp;amp; `cookie2` when redirecting to a untrusted site.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: node-fetch&lt;/p&gt;
&lt;p&gt;node-fetch forwards secure headers such as `authorization`, `www-authenticate`, `cookie`, &amp;amp; `cookie2` when redirecting to a untrusted site.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r683-j2x4-v87g</guid>
    </item>
    <item>
      <title>gsd-2022-0235</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-0235</link>
      <description>gsd-2022-0235</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-0235</guid>
    </item>
    <item>
      <title>ICSA-22-258-05 — Siemens SINEC INS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-22-258-05</link>
      <description>&lt;p&gt;The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info). json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. axios is vulnerable to Inefficient Regular Expression Complexity There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH private key among multip…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info). json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address. Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. axios is vulnerable to Inefficient Regular Expression Complexity There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH private key among multip…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-22-258-05</guid>
    </item>
    <item>
      <title>RHSA-2022:0735 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4.2 security updates and bug fixes</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0735</link>
      <description>&lt;p&gt;nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes nodejs-json-schema: Prototype pollution vulnerability fastify-static: open redirect via an URL with double slash followed by a domain moby: `docker cp` allows unexpected chmod of host file moby: data directory contains subdirectories with insufficiently restricted permissions, which could lead to directory traversal golang.org/x/crypto: empty plaintext packet causes panic containerd: Unprivileged pod may bind mount any privileged regular file on disk minio: user privilege escalation in AddUser() admin API node-fetch: exposure of sensitive information to an unauthorized actor nats-server: misusing the &amp;#34;dynamically provisioned sandbox accounts&amp;#34; feature  authenticated user can obtain the privileges of the System account&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes nodejs-json-schema: Prototype pollution vulnerability fastify-static: open redirect via an URL with double slash followed by a domain moby: `docker cp` allows unexpected chmod of host file moby: data directory contains subdirectories with insufficiently restricted permissions, which could lead to directory traversal golang.org/x/crypto: empty plaintext packet causes panic containerd: Unprivileged pod may bind mount any privileged regular file on disk minio: user privilege escalation in AddUser() admin API node-fetch: exposure of sensitive information to an unauthorized actor nats-server: misusing the &amp;#34;dynamically provisioned sandbox accounts&amp;#34; feature  authenticated user can obtain the privileges of the System account&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0735</guid>
    </item>
    <item>
      <title>RHSA-2023:0050 — Red Hat Security Advisory: nodejs:14 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:0050</link>
      <description>&lt;p&gt;minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor nodejs-minimatch: ReDoS via the braceExpand function express: &amp;#34;qs&amp;#34; prototype poisoning causes the hang of the node process nodejs: DNS rebinding in inspect via invalid octal IP address&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor nodejs-minimatch: ReDoS via the braceExpand function express: &amp;#34;qs&amp;#34; prototype poisoning causes the hang of the node process nodejs: DNS rebinding in inspect via invalid octal IP address&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:0050</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:1459-1 — Security update for nodejs14</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:1459-1</link>
      <description>&lt;p&gt;Security update for nodejs14&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs14&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:1459-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-0235</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-0235</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: node-fetch, Ubuntu:20.04:LTS: node-fetch&lt;/p&gt;
&lt;p&gt;node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: node-fetch, Ubuntu:20.04:LTS: node-fetch&lt;/p&gt;
&lt;p&gt;node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-0235</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0235 — Red Hat Advanced Cluster Management: Mehrere Schwachstellen ermöglichen Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0235</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Advanced Cluster Management ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Advanced Cluster Management ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0235</guid>
    </item>
  </channel>
</rss>
