<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:15:50 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-05169</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05169</link>
      <description>bdu:2023-05169</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05169</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0484 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0484</link>
      <description>certfr-2023-avi-0484</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0484</guid>
    </item>
    <item>
      <title>EUVD-2026-8348</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-8348</link>
      <description>EUVD-2026-8348</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-8348</guid>
    </item>
    <item>
      <title>fkie_cve-2023-28155</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-28155</link>
      <description>&lt;p&gt;The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-28155</guid>
    </item>
    <item>
      <title>GHSA-p8p7-x288-28g6 — Server-Side Request Forgery in Request</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p8p7-x288-28g6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: request, npm: @cypress/request&lt;/p&gt;
&lt;p&gt;The `request` package through 2.88.2 for Node.js and the `@cypress/request` package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).&lt;/p&gt;
&lt;p&gt;NOTE: The `request` package is no longer supported by the maintainer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: request, npm: @cypress/request&lt;/p&gt;
&lt;p&gt;The `request` package through 2.88.2 for Node.js and the `@cypress/request` package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).&lt;/p&gt;
&lt;p&gt;NOTE: The `request` package is no longer supported by the maintainer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p8p7-x288-28g6</guid>
    </item>
    <item>
      <title>gsd-2023-28155</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-28155</link>
      <description>gsd-2023-28155</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-28155</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-28155 — The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server th…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-28155</link>
      <description>msrc_CVE-2023-28155</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-28155</guid>
    </item>
    <item>
      <title>RHSA-2026:62115 — Red Hat Security Advisory: Red Hat Ceph Storage</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:62115</link>
      <description>&lt;p&gt;taffy: taffydb: Internal Property Tampering containerd: OCI image importer memory exhaustion request: bypass of SSRF mitigations when following a cross-protocol redirect npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation urllib3: urllib3 does not control redirects in browsers and Node.js ip: Node ip SSRF urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;taffy: taffydb: Internal Property Tampering containerd: OCI image importer memory exhaustion request: bypass of SSRF mitigations when following a cross-protocol redirect npm-serialize-javascript: Cross-site Scripting (XSS) in serialize-javascript urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation urllib3: urllib3 does not control redirects in browsers and Node.js ip: Node ip SSRF urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:62115</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-28155</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28155</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: node-request, Ubuntu:16.04:LTS: node-request, Ubuntu:18.04:LTS: node-request, Ubuntu:20.04:LTS: node-request, Ubuntu:22.04:LTS: node-request, Ubuntu:24.04:LTS: node-request&lt;/p&gt;
&lt;p&gt;The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: node-request, Ubuntu:16.04:LTS: node-request, Ubuntu:18.04:LTS: node-request, Ubuntu:20.04:LTS: node-request, Ubuntu:22.04:LTS: node-request, Ubuntu:24.04:LTS: node-request&lt;/p&gt;
&lt;p&gt;The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-28155</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1800 — HCL BigFix: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in HCL BigFix WebUI ausnutzen, um seine Privilegien zu erweitern, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in HCL BigFix WebUI ausnutzen, um seine Privilegien zu erweitern, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800</guid>
    </item>
  </channel>
</rss>
