<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:11:59 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-11157</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-11157</link>
      <description>EUVD-2026-11157</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-11157</guid>
    </item>
    <item>
      <title>fkie_cve-2022-0691</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-0691</link>
      <description>&lt;p&gt;Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-0691</guid>
    </item>
    <item>
      <title>GHSA-jf5r-8hm2-f872 — url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jf5r-8hm2-f872</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: url-parse&lt;/p&gt;
&lt;p&gt;Leading control characters in a URL are not stripped when passed into url-parse. This can cause input URLs to be mistakenly be interpreted as a relative URL without a hostname and protocol, while the WHATWG URL parser will trim control characters and treat it as an absolute URL.&lt;/p&gt;
&lt;p&gt;If url-parse is used in security decisions involving the hostname / protocol, and the input URL is used in a client which uses the WHATWG URL parser, the decision may be incorrect.&lt;/p&gt;
&lt;p&gt;This can also lead to a cross-site scripting (XSS) vulnerability if url-parse is used to check for the javascript: protocol in URLs. See following example:
```js
const parse = require(&amp;#39;url-parse&amp;#39;)
const express = require(&amp;#39;express&amp;#39;)
const app = express()
const port = 3000&lt;/p&gt;
&lt;p&gt;url = parse(\&amp;#34;\\bjavascript:alert(1)\&amp;#34;)&lt;/p&gt;
&lt;p&gt;console.log(url)&lt;/p&gt;
&lt;p&gt;app.get(&amp;#39;/&amp;#39;, (req, res) =&amp;gt; {
 if (url.protocol !== \&amp;#34;javascript:\&amp;#34;) {res.send(\&amp;#34;&amp;lt;a href=\\&amp;#39;\&amp;#34; + url.href + \&amp;#34;\\&amp;#39;&amp;gt;CLICK ME!&amp;lt;/a&amp;gt;\&amp;#34;)}
 })&lt;/p&gt;
&lt;p&gt;app.listen(port, () =&amp;gt; {
 console.log(`Example app listening on port ${port}`)
 })
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: url-parse&lt;/p&gt;
&lt;p&gt;Leading control characters in a URL are not stripped when passed into url-parse. This can cause input URLs to be mistakenly be interpreted as a relative URL without a hostname and protocol, while the WHATWG URL parser will trim control characters and treat it as an absolute URL.&lt;/p&gt;
&lt;p&gt;If url-parse is used in security decisions involving the hostname / protocol, and the input URL is used in a client which uses the WHATWG URL parser, the decision may be incorrect.&lt;/p&gt;
&lt;p&gt;This can also lead to a cross-site scripting (XSS) vulnerability if url-parse is used to check for the javascript: protocol in URLs. See following example:
```js
const parse = require(&amp;#39;url-parse&amp;#39;)
const express = require(&amp;#39;express&amp;#39;)
const app = express()
const port = 3000&lt;/p&gt;
&lt;p&gt;url = parse(\&amp;#34;\\bjavascript:alert(1)\&amp;#34;)&lt;/p&gt;
&lt;p&gt;console.log(url)&lt;/p&gt;
&lt;p&gt;app.get(&amp;#39;/&amp;#39;, (req, res) =&amp;gt; {
 if (url.protocol !== \&amp;#34;javascript:\&amp;#34;) {res.send(\&amp;#34;&amp;lt;a href=\\&amp;#39;\&amp;#34; + url.href + \&amp;#34;\\&amp;#39;&amp;gt;CLICK ME!&amp;lt;/a&amp;gt;\&amp;#34;)}
 })&lt;/p&gt;
&lt;p&gt;app.listen(port, () =&amp;gt; {
 console.log(`Example app listening on port ${port}`)
 })
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jf5r-8hm2-f872</guid>
    </item>
    <item>
      <title>gsd-2022-0691</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-0691</link>
      <description>gsd-2022-0691</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-0691</guid>
    </item>
    <item>
      <title>RHSA-2022:6429 — Red Hat Security Advisory: Migration Toolkit for Containers (MTC) 1.7.4 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6429</link>
      <description>&lt;p&gt;nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions nodejs-lodash: command injection via template nodejs-url-parse: authorization bypass through user-controlled key npm-url-parse: Authorization Bypass Through User-Controlled Key npm-url-parse: Authorization bypass through user-controlled key npm-url-parse: authorization bypass through user-controlled key eventsource: Exposure of Sensitive Information golang: compress/gzip: stack exhaustion in Reader.Read&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions nodejs-lodash: command injection via template nodejs-url-parse: authorization bypass through user-controlled key npm-url-parse: Authorization Bypass Through User-Controlled Key npm-url-parse: Authorization bypass through user-controlled key npm-url-parse: authorization bypass through user-controlled key eventsource: Exposure of Sensitive Information golang: compress/gzip: stack exhaustion in Reader.Read&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6429</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-0691</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-0691</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: node-url-parse, Ubuntu:18.04:LTS: node-url-parse, Ubuntu:20.04:LTS: node-url-parse&lt;/p&gt;
&lt;p&gt;Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: node-url-parse, Ubuntu:18.04:LTS: node-url-parse, Ubuntu:20.04:LTS: node-url-parse&lt;/p&gt;
&lt;p&gt;Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-0691</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1401 — Red Hat OpenShift (Migration Toolkit for Containers): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1401</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1401</guid>
    </item>
  </channel>
</rss>
