<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 15:37:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-232559</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232559</link>
      <description>EUVD-2026-232559</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232559</guid>
    </item>
    <item>
      <title>fkie_cve-2022-39381</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-39381</link>
      <description>&lt;p&gt;Muhammara is a node module with c/cpp bindings to modify PDF with js for node or electron (based/replacement on/of galkhana/hummusjs). The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be appended to another. This issue has been patched in 2.6.0 for muhammara and not at all for hummus. As a workaround, do not process files from untrusted sources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Muhammara is a node module with c/cpp bindings to modify PDF with js for node or electron (based/replacement on/of galkhana/hummusjs). The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be appended to another. This issue has been patched in 2.6.0 for muhammara and not at all for hummus. As a workaround, do not process files from untrusted sources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-39381</guid>
    </item>
    <item>
      <title>GHSA-rcrx-fpjp-mfrw — Unchecked Return Value to NULL Pointer Dereference in PDFDocumentHandler.cpp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rcrx-fpjp-mfrw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: muhammara, npm: hummus&lt;/p&gt;
&lt;p&gt;### Impact
The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be appended to another.&lt;/p&gt;
&lt;p&gt;### Patches
It has been patched in 2.6.0 for muhammara and not at all for hummus&lt;/p&gt;
&lt;p&gt;### Workarounds
Do not process files from untrusted sources&lt;/p&gt;
&lt;p&gt;### References
PR: https://github.com/julianhille/MuhammaraJS/pull/194
Issue: https://github.com/julianhille/MuhammaraJS/issues/191
Issue in hummus: https://github.com/galkahana/HummusJS/issues/293&lt;/p&gt;
&lt;p&gt;### Outline differences to https://nvd.nist.gov/vuln/detail/CVE-2022-25892&lt;/p&gt;
&lt;p&gt;The difference is one is in [src/deps/PDFWriter/PDFParser.cpp](https://github.com/julianhille/MuhammaraJS/commit/1890fb555eaf171db79b73fdc3ea543bbd63c002#diff-09ac2c64aeab42b14b2ae7b11a5648314286986f8c8444a5b3739ba7203b1e9b) and the other is [PDFDocumentHandler.cpp](https://github.com/julianhille/MuhammaraJS/pull/194/files#diff-38d338ea4c047fd7dd9a05b5ffe7c964f0fa7e79aff4c307ccee7596457b1ef2) both is a null pointer but for different cases
These are totally diffent issues, one is in reading a pdf the other is in appendending a maliciously crafted one. The function calls are different the versions in which they are solved are diffent.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: muhammara, npm: hummus&lt;/p&gt;
&lt;p&gt;### Impact
The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be appended to another.&lt;/p&gt;
&lt;p&gt;### Patches
It has been patched in 2.6.0 for muhammara and not at all for hummus&lt;/p&gt;
&lt;p&gt;### Workarounds
Do not process files from untrusted sources&lt;/p&gt;
&lt;p&gt;### References
PR: https://github.com/julianhille/MuhammaraJS/pull/194
Issue: https://github.com/julianhille/MuhammaraJS/issues/191
Issue in hummus: https://github.com/galkahana/HummusJS/issues/293&lt;/p&gt;
&lt;p&gt;### Outline differences to https://nvd.nist.gov/vuln/detail/CVE-2022-25892&lt;/p&gt;
&lt;p&gt;The difference is one is in [src/deps/PDFWriter/PDFParser.cpp](https://github.com/julianhille/MuhammaraJS/commit/1890fb555eaf171db79b73fdc3ea543bbd63c002#diff-09ac2c64aeab42b14b2ae7b11a5648314286986f8c8444a5b3739ba7203b1e9b) and the other is [PDFDocumentHandler.cpp](https://github.com/julianhille/MuhammaraJS/pull/194/files#diff-38d338ea4c047fd7dd9a05b5ffe7c964f0fa7e79aff4c307ccee7596457b1ef2) both is a null pointer but for different cases
These are totally diffent issues, one is in reading a pdf the other is in appendending a maliciously crafted one. The function calls are different the versions in which they are solved are diffent.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rcrx-fpjp-mfrw</guid>
    </item>
    <item>
      <title>gsd-2022-39381</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-39381</link>
      <description>gsd-2022-39381</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-39381</guid>
    </item>
  </channel>
</rss>
