<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:31:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-216443</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-216443</link>
      <description>EUVD-2026-216443</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-216443</guid>
    </item>
    <item>
      <title>fkie_cve-2023-31125</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-31125</link>
      <description>&lt;p&gt;Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. An uncaught exception vulnerability was introduced in version 5.1.0 and included in version 4.1.0 of the `socket.io` parent package. Older versions are not impacted. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the `engine.io` package, including those who use depending packages like `socket.io`. This issue was fixed in version 6.4.2 of Engine.IO. There is no known workaround except upgrading to a safe version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. An uncaught exception vulnerability was introduced in version 5.1.0 and included in version 4.1.0 of the `socket.io` parent package. Older versions are not impacted. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the `engine.io` package, including those who use depending packages like `socket.io`. This issue was fixed in version 6.4.2 of Engine.IO. There is no known workaround except upgrading to a safe version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-31125</guid>
    </item>
    <item>
      <title>GHSA-q9mw-68c2-j6m5 — engine.io Uncaught Exception vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q9mw-68c2-j6m5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: engine.io&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.&lt;/p&gt;
&lt;p&gt;```
TypeError: Cannot read properties of undefined (reading &amp;#39;handlesUpgrades&amp;#39;)
    at Server.onWebSocket (build/server.js:515:67)
```&lt;/p&gt;
&lt;p&gt;This impacts all the users of the [`engine.io`](https://www.npmjs.com/package/engine.io) package, including those who uses depending packages like [`socket.io`](https://www.npmjs.com/package/socket.io).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;A fix has been released today (2023/05/02): [6.4.2](https://github.com/socketio/engine.io/releases/tag/6.4.2)&lt;/p&gt;
&lt;p&gt;This bug was introduced in version 5.1.0 and included in version 4.1.0 of the `socket.io` parent package. Older versions are not impacted.&lt;/p&gt;
&lt;p&gt;For `socket.io` users:&lt;/p&gt;
&lt;p&gt;| Version range               | `engine.io` version | Needs minor update?                                                                                    |
|-----------------------------|---------------------|--------------------------------------------------------------------------------------------------------|
| `socket.io@4.6.x`           | `~6.4.0`            | `npm audit fix` should be sufficient                                                                   |
| `socket.io@4.5.x`           | `~6.2.0`            | Please upgrade to `socket.io@4.6.x`                                                                    |
| `socket.io@4.4.x`           | `~6.1.0`            | Please upgrade to `socket.io@4.6.x`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: engine.io&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.&lt;/p&gt;
&lt;p&gt;```
TypeError: Cannot read properties of undefined (reading &amp;#39;handlesUpgrades&amp;#39;)
    at Server.onWebSocket (build/server.js:515:67)
```&lt;/p&gt;
&lt;p&gt;This impacts all the users of the [`engine.io`](https://www.npmjs.com/package/engine.io) package, including those who uses depending packages like [`socket.io`](https://www.npmjs.com/package/socket.io).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;A fix has been released today (2023/05/02): [6.4.2](https://github.com/socketio/engine.io/releases/tag/6.4.2)&lt;/p&gt;
&lt;p&gt;This bug was introduced in version 5.1.0 and included in version 4.1.0 of the `socket.io` parent package. Older versions are not impacted.&lt;/p&gt;
&lt;p&gt;For `socket.io` users:&lt;/p&gt;
&lt;p&gt;| Version range               | `engine.io` version | Needs minor update?                                                                                    |
|-----------------------------|---------------------|--------------------------------------------------------------------------------------------------------|
| `socket.io@4.6.x`           | `~6.4.0`            | `npm audit fix` should be sufficient                                                                   |
| `socket.io@4.5.x`           | `~6.2.0`            | Please upgrade to `socket.io@4.6.x`                                                                    |
| `socket.io@4.4.x`           | `~6.1.0`            | Please upgrade to `socket.io@4.6.x`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q9mw-68c2-j6m5</guid>
    </item>
    <item>
      <title>gsd-2023-31125</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-31125</link>
      <description>gsd-2023-31125</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-31125</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1800 — HCL BigFix: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in HCL BigFix WebUI ausnutzen, um seine Privilegien zu erweitern, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in HCL BigFix WebUI ausnutzen, um seine Privilegien zu erweitern, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800</guid>
    </item>
  </channel>
</rss>
