<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:54:46 +0000</lastBuildDate>
    <item>
      <title>cnvd-2022-85553</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-85553</link>
      <description>cnvd-2022-85553</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-85553</guid>
    </item>
    <item>
      <title>EUVD-2026-232516</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232516</link>
      <description>EUVD-2026-232516</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232516</guid>
    </item>
    <item>
      <title>fkie_cve-2022-41940</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41940</link>
      <description>&lt;p&gt;Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the engine.io package, including those who uses depending packages like socket.io. There is no known workaround except upgrading to a safe version. There are patches for this issue released in versions 3.6.1 and 6.2.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the engine.io package, including those who uses depending packages like socket.io. There is no known workaround except upgrading to a safe version. There are patches for this issue released in versions 3.6.1 and 6.2.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-41940</guid>
    </item>
    <item>
      <title>GHSA-r7qp-cfhv-p84w — Uncaught exception in engine.io</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r7qp-cfhv-p84w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: engine.io&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.&lt;/p&gt;
&lt;p&gt;```
events.js:292
      throw er; // Unhandled &amp;#39;error&amp;#39; event
      ^&lt;/p&gt;
&lt;p&gt;Error: read ECONNRESET
    at TCP.onStreamRead (internal/stream_base_commons.js:209:20)
Emitted &amp;#39;error&amp;#39; event on Socket instance at:
    at emitErrorNT (internal/streams/destroy.js:106:8)
    at emitErrorCloseNT (internal/streams/destroy.js:74:3)
    at processTicksAndRejections (internal/process/task_queues.js:80:21) {
  errno: -104,
  code: &amp;#39;ECONNRESET&amp;#39;,
  syscall: &amp;#39;read&amp;#39;
}
```&lt;/p&gt;
&lt;p&gt;This impacts all the users of the [`engine.io`](https://www.npmjs.com/package/engine.io) package, including those who uses depending packages like [`socket.io`](https://www.npmjs.com/package/socket.io).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;A fix has been released today (2022/11/20):&lt;/p&gt;
&lt;p&gt;| Version range     | Fixed version |
|-------------------|---------------|
| `engine.io@3.x.y` | `3.6.1`       |
| `engine.io@6.x.y` | `6.2.1`       |&lt;/p&gt;
&lt;p&gt;For `socket.io` users:&lt;/p&gt;
&lt;p&gt;| Version range               | `engine.io` version | Needs minor update?                                                                                    |
|-----------------------------|---------------------|--------------------------------------------------------------------------------------------------------|
| `socket.io@4.5.x`           | `~6.2.0`            | `npm audit fix` should be sufficient…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: engine.io&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.&lt;/p&gt;
&lt;p&gt;```
events.js:292
      throw er; // Unhandled &amp;#39;error&amp;#39; event
      ^&lt;/p&gt;
&lt;p&gt;Error: read ECONNRESET
    at TCP.onStreamRead (internal/stream_base_commons.js:209:20)
Emitted &amp;#39;error&amp;#39; event on Socket instance at:
    at emitErrorNT (internal/streams/destroy.js:106:8)
    at emitErrorCloseNT (internal/streams/destroy.js:74:3)
    at processTicksAndRejections (internal/process/task_queues.js:80:21) {
  errno: -104,
  code: &amp;#39;ECONNRESET&amp;#39;,
  syscall: &amp;#39;read&amp;#39;
}
```&lt;/p&gt;
&lt;p&gt;This impacts all the users of the [`engine.io`](https://www.npmjs.com/package/engine.io) package, including those who uses depending packages like [`socket.io`](https://www.npmjs.com/package/socket.io).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;A fix has been released today (2022/11/20):&lt;/p&gt;
&lt;p&gt;| Version range     | Fixed version |
|-------------------|---------------|
| `engine.io@3.x.y` | `3.6.1`       |
| `engine.io@6.x.y` | `6.2.1`       |&lt;/p&gt;
&lt;p&gt;For `socket.io` users:&lt;/p&gt;
&lt;p&gt;| Version range               | `engine.io` version | Needs minor update?                                                                                    |
|-----------------------------|---------------------|--------------------------------------------------------------------------------------------------------|
| `socket.io@4.5.x`           | `~6.2.0`            | `npm audit fix` should be sufficient…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r7qp-cfhv-p84w</guid>
    </item>
    <item>
      <title>gsd-2022-41940</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-41940</link>
      <description>gsd-2022-41940</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-41940</guid>
    </item>
    <item>
      <title>RHSA-2023:3954 — Red Hat Security Advisory: Red Hat Fuse 7.12 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:3954</link>
      <description>&lt;p&gt;jakarta-commons-httpclient: missing connection hostname check against X.509 certificate name apache-httpclient: incorrect handling of malformed authority component in request URIs undertow: Server identity in https connection is not checked by the undertow client Moment.js: Path traversal  in moment.locale spring-security: Authorization rules can be bypassed via forward or include dispatcher types in Spring Security hazelcast: Hazelcast connection caching batik: Server-Side Request Forgery batik: Server-Side Request Forgery batik: Server-Side Request Forgery (SSRF) vulnerability batik: Apache XML Graphics Batik vulnerable to code execution via SVG dev-java/snakeyaml: DoS via stack overflow codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS engine.io: Specially crafted HTTP request can trigger an uncaught exception postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions xstream: Denial of Service by injecting recursive collections or maps based on element&amp;#39;s hash values raising a stack overflow batik: Untrusted code execution in Apache XML Graphics Batik Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing tomcat: JsonErrorReportValve injection CXF: directory listing / code exfiltration CXF: SSRF Vulnerability Undertow: Infinite loop in SslConduit during close json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) springframework: Security Bypass With Un-Prefix…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jakarta-commons-httpclient: missing connection hostname check against X.509 certificate name apache-httpclient: incorrect handling of malformed authority component in request URIs undertow: Server identity in https connection is not checked by the undertow client Moment.js: Path traversal  in moment.locale spring-security: Authorization rules can be bypassed via forward or include dispatcher types in Spring Security hazelcast: Hazelcast connection caching batik: Server-Side Request Forgery batik: Server-Side Request Forgery batik: Server-Side Request Forgery (SSRF) vulnerability batik: Apache XML Graphics Batik vulnerable to code execution via SVG dev-java/snakeyaml: DoS via stack overflow codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS engine.io: Specially crafted HTTP request can trigger an uncaught exception postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions xstream: Denial of Service by injecting recursive collections or maps based on element&amp;#39;s hash values raising a stack overflow batik: Untrusted code execution in Apache XML Graphics Batik Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing tomcat: JsonErrorReportValve injection CXF: directory listing / code exfiltration CXF: SSRF Vulnerability Undertow: Infinite loop in SslConduit during close json-smart: Uncontrolled Resource Consumption vulnerability in json-smart (Resource Exhaustion) springframework: Security Bypass With Un-Prefix…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:3954</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0180 — Dell Data Protection Advisor: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu erzeugen, Sicherheitsmaßnahmen zu umgehen und nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0180</guid>
    </item>
  </channel>
</rss>
