<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:00:21 +0000</lastBuildDate>
    <item>
      <title>cnvd-2022-19502</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-19502</link>
      <description>cnvd-2022-19502</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-19502</guid>
    </item>
    <item>
      <title>EUVD-2026-232789</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232789</link>
      <description>EUVD-2026-232789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232789</guid>
    </item>
    <item>
      <title>fkie_cve-2022-24723</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24723</link>
      <description>&lt;p&gt;URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-24723</guid>
    </item>
    <item>
      <title>GHSA-gmv4-r438-p67f — Leading white space bypasses protocol validation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gmv4-r438-p67f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: urijs&lt;/p&gt;
&lt;p&gt;### Impact
Whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly and protocol validation mechanisms may fail.&lt;/p&gt;
&lt;p&gt;### Patches
Patched in 1.19.9&lt;/p&gt;
&lt;p&gt;### Workarounds
Remove leading whitespace from values before passing them to URI.parse (e.g. via `.href(value)` or `new URI(value)`), e.g. by using&lt;/p&gt;
&lt;p&gt;```js
function remove_whitespace(url){
     const whitespace = /^[\x00-\x20\u00a0\u1680\u2000-\u200a\u2028\u2029\u202f\u205f\u3000\ufeff]+/;
     url = url.replace(whitespace, &amp;#39;&amp;#39;)
     return url
}
```&lt;/p&gt;
&lt;p&gt;### References
* https://huntr.dev/bounties/82ef23b8-7025-49c9-b5fc-1bb9885788e5/&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [medialize/URI.js](https://github.com/medialize/URI.js/)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: urijs&lt;/p&gt;
&lt;p&gt;### Impact
Whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly and protocol validation mechanisms may fail.&lt;/p&gt;
&lt;p&gt;### Patches
Patched in 1.19.9&lt;/p&gt;
&lt;p&gt;### Workarounds
Remove leading whitespace from values before passing them to URI.parse (e.g. via `.href(value)` or `new URI(value)`), e.g. by using&lt;/p&gt;
&lt;p&gt;```js
function remove_whitespace(url){
     const whitespace = /^[\x00-\x20\u00a0\u1680\u2000-\u200a\u2028\u2029\u202f\u205f\u3000\ufeff]+/;
     url = url.replace(whitespace, &amp;#39;&amp;#39;)
     return url
}
```&lt;/p&gt;
&lt;p&gt;### References
* https://huntr.dev/bounties/82ef23b8-7025-49c9-b5fc-1bb9885788e5/&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Open an issue in [medialize/URI.js](https://github.com/medialize/URI.js/)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gmv4-r438-p67f</guid>
    </item>
    <item>
      <title>gsd-2022-24723</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-24723</link>
      <description>gsd-2022-24723</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-24723</guid>
    </item>
    <item>
      <title>RHSA-2022:1681 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4.4 security updates and bug fixes</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:1681</link>
      <description>&lt;p&gt;vm2: vulnerable to Sandbox Bypass golang.org/x/crypto: empty plaintext packet causes panic follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor node-fetch: exposure of sensitive information to an unauthorized actor follow-redirects: Exposure of Sensitive Information via Authorization Header leak urijs: Authorization Bypass Through User-Controlled Key cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor nconf: Prototype pollution in memory store nats-server: misusing the &amp;#34;dynamically provisioned sandbox accounts&amp;#34; feature  authenticated user can obtain the privileges of the System account urijs: Leading white space bypasses protocol validation node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery node-forge: Signature verification leniency in checking `DigestInfo` structure Moment.js: Path traversal  in moment.locale&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2: vulnerable to Sandbox Bypass golang.org/x/crypto: empty plaintext packet causes panic follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor node-fetch: exposure of sensitive information to an unauthorized actor follow-redirects: Exposure of Sensitive Information via Authorization Header leak urijs: Authorization Bypass Through User-Controlled Key cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor nconf: Prototype pollution in memory store nats-server: misusing the &amp;#34;dynamically provisioned sandbox accounts&amp;#34; feature  authenticated user can obtain the privileges of the System account urijs: Leading white space bypasses protocol validation node-forge: Signature verification leniency in checking `digestAlgorithm` structure can lead to signature forgery node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery node-forge: Signature verification leniency in checking `DigestInfo` structure Moment.js: Path traversal  in moment.locale&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:1681</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-24723</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24723</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-uri-js, Ubuntu:22.04:LTS: node-uri-js, Ubuntu:24.04:LTS: node-uri-js, Ubuntu:25.10: node-uri-js, Ubuntu:26.04:LTS: node-uri-js&lt;/p&gt;
&lt;p&gt;URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-uri-js, Ubuntu:22.04:LTS: node-uri-js, Ubuntu:24.04:LTS: node-uri-js, Ubuntu:25.10: node-uri-js, Ubuntu:26.04:LTS: node-uri-js&lt;/p&gt;
&lt;p&gt;URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24723</guid>
    </item>
  </channel>
</rss>
