<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:50:30 +0000</lastBuildDate>
    <item>
      <title>9AKK108470A8565 — RMC-100 Vulnerability in the Web UI (REST Interface)</title>
      <link>https://cve.radiocsirt.org/vuln/9akk108470a8565</link>
      <description>&lt;p&gt;An update is available that resolves a vulnerability in the product versions listed as affected in this advisory.
An attacker who successfully exploited this vulnerability could cause the web UI to stop.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An update is available that resolves a vulnerability in the product versions listed as affected in this advisory.
An attacker who successfully exploited this vulnerability could cause the web UI to stop.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/9akk108470a8565</guid>
    </item>
    <item>
      <title>ALSA-2023:0050 — Moderate: nodejs:14 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:0050</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (14.21.1), nodejs-nodemon (2.0.20).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* minimist: prototype pollution (CVE-2021-44906)
* node-fetch: exposure of sensitive information to an unauthorized actor (CVE-2022-0235)
* nodejs-minimatch: ReDoS via the braceExpand function (CVE-2022-3517)
* express: &amp;#34;qs&amp;#34; prototype poisoning causes the hang of the node process (CVE-2022-24999)
* nodejs: DNS rebinding in inspect via invalid octal IP address (CVE-2022-43548)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (14.21.1), nodejs-nodemon (2.0.20).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* minimist: prototype pollution (CVE-2021-44906)
* node-fetch: exposure of sensitive information to an unauthorized actor (CVE-2022-0235)
* nodejs-minimatch: ReDoS via the braceExpand function (CVE-2022-3517)
* express: &amp;#34;qs&amp;#34; prototype poisoning causes the hang of the node process (CVE-2022-24999)
* nodejs: DNS rebinding in inspect via invalid octal IP address (CVE-2022-43548)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:0050</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0276 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à un attaquant d…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276</link>
      <description>certfr-2023-avi-0276</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276</guid>
    </item>
    <item>
      <title>EUVD-2026-235584</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-235584</link>
      <description>EUVD-2026-235584</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-235584</guid>
    </item>
    <item>
      <title>fkie_cve-2022-24999</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24999</link>
      <description>&lt;p&gt;qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&amp;amp;a[__proto__]&amp;amp;a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has &amp;#34;deps: qs@6.9.7&amp;#34; in its release description, is not vulnerable).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&amp;amp;a[__proto__]&amp;amp;a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has &amp;#34;deps: qs@6.9.7&amp;#34; in its release description, is not vulnerable).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-24999</guid>
    </item>
    <item>
      <title>GHSA-hrpp-h998-j3pp — qs vulnerable to Prototype Pollution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hrpp-h998-j3pp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: qs&lt;/p&gt;
&lt;p&gt;qs before 6.10.3 allows attackers to cause a Node process hang because an `__ proto__` key can be used. In many typical web framework use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as `a[__proto__]=b&amp;amp;a[__proto__]&amp;amp;a[length]=100000000`. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: qs&lt;/p&gt;
&lt;p&gt;qs before 6.10.3 allows attackers to cause a Node process hang because an `__ proto__` key can be used. In many typical web framework use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as `a[__proto__]=b&amp;amp;a[__proto__]&amp;amp;a[length]=100000000`. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hrpp-h998-j3pp</guid>
    </item>
    <item>
      <title>gsd-2022-24999</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-24999</link>
      <description>gsd-2022-24999</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-24999</guid>
    </item>
    <item>
      <title>ICSA-25-084-01 — ABB RMC-100</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-084-01</link>
      <description>&lt;p&gt;An update is available that resolves a vulnerability in the product versions listed as affected in this advisory.
An attacker who successfully exploited this vulnerability could cause the web UI to stop.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An update is available that resolves a vulnerability in the product versions listed as affected in this advisory.
An attacker who successfully exploited this vulnerability could cause the web UI to stop.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-084-01</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-24999 — qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang fo…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-24999</link>
      <description>msrc_CVE-2022-24999</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-24999</guid>
    </item>
    <item>
      <title>OESA-2024-1338 — nodejs-qs security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1338</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: nodejs-qs&lt;/p&gt;
&lt;p&gt;This is a query string parser for node and the browser supporting nesting, as it was removed from 0.3.x, so this library provides the previous and commonly desired behavior (and twice as fast). Used by express, connect and others.&#13;
&#13;
Security Fix(es):&#13;
&#13;
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&amp;amp;amp;a[__proto__]&amp;amp;amp;a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has &amp;amp;quot;deps: qs@6.9.7&amp;amp;quot; in its release description, is not vulnerable).(CVE-2022-24999)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: nodejs-qs&lt;/p&gt;
&lt;p&gt;This is a query string parser for node and the browser supporting nesting, as it was removed from 0.3.x, so this library provides the previous and commonly desired behavior (and twice as fast). Used by express, connect and others.&#13;
&#13;
Security Fix(es):&#13;
&#13;
qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&amp;amp;amp;a[__proto__]&amp;amp;amp;a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has &amp;amp;quot;deps: qs@6.9.7&amp;amp;quot; in its release description, is not vulnerable).(CVE-2022-24999)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1338</guid>
    </item>
    <item>
      <title>RHSA-2023:0050 — Red Hat Security Advisory: nodejs:14 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:0050</link>
      <description>&lt;p&gt;minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor nodejs-minimatch: ReDoS via the braceExpand function express: &amp;#34;qs&amp;#34; prototype poisoning causes the hang of the node process nodejs: DNS rebinding in inspect via invalid octal IP address&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor nodejs-minimatch: ReDoS via the braceExpand function express: &amp;#34;qs&amp;#34; prototype poisoning causes the hang of the node process nodejs: DNS rebinding in inspect via invalid octal IP address&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:0050</guid>
    </item>
    <item>
      <title>RHSA-2023:0612 — Red Hat Security Advisory: rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:0612</link>
      <description>&lt;p&gt;glob-parent: Regular Expression Denial of Service minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor nodejs-minimatch: ReDoS via the braceExpand function express: &amp;#34;qs&amp;#34; prototype poisoning causes the hang of the node process nodejs: DNS rebinding in inspect via invalid octal IP address&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glob-parent: Regular Expression Denial of Service minimist: prototype pollution node-fetch: exposure of sensitive information to an unauthorized actor nodejs-minimatch: ReDoS via the braceExpand function express: &amp;#34;qs&amp;#34; prototype poisoning causes the hang of the node process nodejs: DNS rebinding in inspect via invalid octal IP address&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:0612</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-24999</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24999</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-express, Ubuntu:Pro:20.04:LTS: node-qs&lt;/p&gt;
&lt;p&gt;qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&amp;amp;a[__proto__]&amp;amp;a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has &amp;#34;deps: qs@6.9.7&amp;#34; in its release description, is not vulnerable).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-express, Ubuntu:Pro:20.04:LTS: node-qs&lt;/p&gt;
&lt;p&gt;qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&amp;amp;a[__proto__]&amp;amp;a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has &amp;#34;deps: qs@6.9.7&amp;#34; in its release description, is not vulnerable).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-24999</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0398 — Red Hat Advanced Cluster Management for Kubernetes: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0398</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle im Red Hat Advanced Cluster Management for Kubernetes ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle im Red Hat Advanced Cluster Management for Kubernetes ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0398</guid>
    </item>
  </channel>
</rss>
