<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:53:12 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:6595 — Moderate: nodejs and nodejs-nodemon security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:6595</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: nodejs, AlmaLinux:9: nodejs-docs, AlmaLinux:9: nodejs-full-i18n, AlmaLinux:9: nodejs-libs, AlmaLinux:9: nodejs-nodemon, AlmaLinux:9: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (16.16.0), nodejs-nodemon (2.0.19). (BZ#2124230, BZ#2124233)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs-ini: Prototype pollution via malicious INI file (CVE-2020-7788)
* nodejs-glob-parent: Regular expression denial of service (CVE-2020-28469)
* nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807)
* normalize-url: ReDoS for data URLs (CVE-2021-33502)
* nodejs: npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace (CVE-2022-29244)
* nodejs: DNS rebinding in --inspect via invalid IP addresses (CVE-2022-32212)
* nodejs: HTTP request smuggling due to flawed parsing of Transfer-Encoding (CVE-2022-32213)
* nodejs: HTTP request smuggling due to improper delimiting of header fields (CVE-2022-32214)
* nodejs: HTTP request smuggling due to incorrect parsing of multi-line Transfer-Encoding (CVE-2022-32215)
* got: missing verification of requested URLs allows redirects to UNIX sockets (CVE-2022-33987)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs:16/nodejs: Rebase to the latest Nodejs 16 release [almalinux-9] (BZ#2121019)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: nodejs, AlmaLinux:9: nodejs-docs, AlmaLinux:9: nodejs-full-i18n, AlmaLinux:9: nodejs-libs, AlmaLinux:9: nodejs-nodemon, AlmaLinux:9: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (16.16.0), nodejs-nodemon (2.0.19). (BZ#2124230, BZ#2124233)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs-ini: Prototype pollution via malicious INI file (CVE-2020-7788)
* nodejs-glob-parent: Regular expression denial of service (CVE-2020-28469)
* nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807)
* normalize-url: ReDoS for data URLs (CVE-2021-33502)
* nodejs: npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace (CVE-2022-29244)
* nodejs: DNS rebinding in --inspect via invalid IP addresses (CVE-2022-32212)
* nodejs: HTTP request smuggling due to flawed parsing of Transfer-Encoding (CVE-2022-32213)
* nodejs: HTTP request smuggling due to improper delimiting of header fields (CVE-2022-32214)
* nodejs: HTTP request smuggling due to incorrect parsing of multi-line Transfer-Encoding (CVE-2022-32215)
* got: missing verification of requested URLs allows redirects to UNIX sockets (CVE-2022-33987)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs:16/nodejs: Rebase to the latest Nodejs 16 release [almalinux-9] (BZ#2121019)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:6595</guid>
    </item>
    <item>
      <title>bdu:2023-03309</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03309</link>
      <description>bdu:2023-03309</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03309</guid>
    </item>
    <item>
      <title>BREW-node-CVE-2022-29244 — npm packing does not respect root-level ignore files in workspaces</title>
      <link>https://cve.radiocsirt.org/vuln/brew-node-cve-2022-29244</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: node&lt;/p&gt;
&lt;p&gt;npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=&amp;lt;name&amp;gt;`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: node&lt;/p&gt;
&lt;p&gt;npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=&amp;lt;name&amp;gt;`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-node-cve-2022-29244</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0238 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0238</link>
      <description>certfr-2023-avi-0238</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0238</guid>
    </item>
    <item>
      <title>EUVD-2026-233282</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-233282</link>
      <description>EUVD-2026-233282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-233282</guid>
    </item>
    <item>
      <title>fkie_cve-2022-29244</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-29244</link>
      <description>&lt;p&gt;npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=&amp;lt;name&amp;gt;`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=&amp;lt;name&amp;gt;`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-29244</guid>
    </item>
    <item>
      <title>GHSA-hj9c-8jmm-8c52 — Packing does not respect root-level ignore files in workspaces</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hj9c-8jmm-8c52</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: npm&lt;/p&gt;
&lt;p&gt;### Impact
`npm pack` ignores root-level `.gitignore` &amp;amp; `.npmignore` file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=&amp;lt;name&amp;gt;`). Anyone who has run `npm pack` or `npm publish` with workspaces, as of [v7.9.0](https://github.com/npm/cli/releases/tag/v7.9.0) &amp;amp; [v7.13.0](https://github.com/npm/cli/releases/tag/v7.13.0) respectively, may be affected and have published files into the npm registry they did not intend to include.&lt;/p&gt;
&lt;p&gt;### Patch
- Upgrade to the latest, patched version of `npm` ([`v8.11.0`](https://github.com/npm/cli/releases/tag/v8.11.0) or greater), run: `npm i -g npm@latest`
- Node.js versions [`v16.15.1`](https://github.com/nodejs/node/releases/tag/v16.15.1), [`v17.19.1`](https://github.com/nodejs/node/releases/tag/v17.9.1) &amp;amp; [`v18.3.0`](https://github.com/nodejs/node/releases/tag/v18.3.0) include the patched `v8.11.0` version of `npm`&lt;/p&gt;
&lt;p&gt;#### Steps to take to see if you&amp;#39;re impacted
1. Run `npm publish --dry-run` or `npm pack` with an `npm` version `&amp;gt;=7.9.0` &amp;amp; `&amp;lt;8.11.0` inside the project&amp;#39;s root directory using a workspace flag like: `--workspaces` or `--workspace=&amp;lt;name&amp;gt;` (ex. `npm pack --workspace=foo`)
2. Check the output in your terminal which will list the package contents (note: `tar -tvf &amp;lt;package-on-disk&amp;gt;` also works)
3. If you find that there are files included you did not expect, you should:
  3.1. Create &amp;amp; publish a new release excluding those files (ref. [&amp;#34;Keeping files out of your Package&amp;#34;](https://d…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: npm&lt;/p&gt;
&lt;p&gt;### Impact
`npm pack` ignores root-level `.gitignore` &amp;amp; `.npmignore` file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=&amp;lt;name&amp;gt;`). Anyone who has run `npm pack` or `npm publish` with workspaces, as of [v7.9.0](https://github.com/npm/cli/releases/tag/v7.9.0) &amp;amp; [v7.13.0](https://github.com/npm/cli/releases/tag/v7.13.0) respectively, may be affected and have published files into the npm registry they did not intend to include.&lt;/p&gt;
&lt;p&gt;### Patch
- Upgrade to the latest, patched version of `npm` ([`v8.11.0`](https://github.com/npm/cli/releases/tag/v8.11.0) or greater), run: `npm i -g npm@latest`
- Node.js versions [`v16.15.1`](https://github.com/nodejs/node/releases/tag/v16.15.1), [`v17.19.1`](https://github.com/nodejs/node/releases/tag/v17.9.1) &amp;amp; [`v18.3.0`](https://github.com/nodejs/node/releases/tag/v18.3.0) include the patched `v8.11.0` version of `npm`&lt;/p&gt;
&lt;p&gt;#### Steps to take to see if you&amp;#39;re impacted
1. Run `npm publish --dry-run` or `npm pack` with an `npm` version `&amp;gt;=7.9.0` &amp;amp; `&amp;lt;8.11.0` inside the project&amp;#39;s root directory using a workspace flag like: `--workspaces` or `--workspace=&amp;lt;name&amp;gt;` (ex. `npm pack --workspace=foo`)
2. Check the output in your terminal which will list the package contents (note: `tar -tvf &amp;lt;package-on-disk&amp;gt;` also works)
3. If you find that there are files included you did not expect, you should:
  3.1. Create &amp;amp; publish a new release excluding those files (ref. [&amp;#34;Keeping files out of your Package&amp;#34;](https://d…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hj9c-8jmm-8c52</guid>
    </item>
    <item>
      <title>gsd-2022-29244</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-29244</link>
      <description>gsd-2022-29244</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-29244</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-29244 — npm packing does not respect root-level ignore files in workspaces</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-29244</link>
      <description>msrc_CVE-2022-29244</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-29244</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12280-1 — corepack16-16.17.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12280-1</link>
      <description>&lt;p&gt;corepack16-16.17.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;corepack16-16.17.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12280-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3196-1 — Security update for nodejs16</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3196-1</link>
      <description>&lt;p&gt;Security update for nodejs16&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs16&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3196-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-29244</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-29244</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: npm, Ubuntu:Pro:16.04:LTS: npm, Ubuntu:Pro:18.04:LTS: npm, Ubuntu:20.04:LTS: npm, Ubuntu:22.04:LTS: npm, Ubuntu:24.04:LTS: npm, Ubuntu:25.10: npm, Ubuntu:26.04:LTS: npm&lt;/p&gt;
&lt;p&gt;npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=&amp;lt;name&amp;gt;`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: npm, Ubuntu:Pro:16.04:LTS: npm, Ubuntu:Pro:18.04:LTS: npm, Ubuntu:20.04:LTS: npm, Ubuntu:22.04:LTS: npm, Ubuntu:24.04:LTS: npm, Ubuntu:25.10: npm, Ubuntu:26.04:LTS: npm&lt;/p&gt;
&lt;p&gt;npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=&amp;lt;name&amp;gt;`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-29244</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0293 — npm: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0293</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in npm ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in npm ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0293</guid>
    </item>
  </channel>
</rss>
