<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:17:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09399</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09399</link>
      <description>bdu:2026-09399</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09399</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0015 — De multiples vulnérabilités ont été découvertes dans les produits
Splunk. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0015</link>
      <description>certfr-2024-avi-0015</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0015</guid>
    </item>
    <item>
      <title>EUVD-2026-210278</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-210278</link>
      <description>EUVD-2026-210278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-210278</guid>
    </item>
    <item>
      <title>fkie_cve-2023-32695</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-32695</link>
      <description>&lt;p&gt;socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. A patch has been released in version 4.2.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. A patch has been released in version 4.2.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-32695</guid>
    </item>
    <item>
      <title>GHSA-cqmj-92xf-r6r9 — Insufficient validation when decoding a Socket.IO packet</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cqmj-92xf-r6r9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: socket.io-parser&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process.&lt;/p&gt;
&lt;p&gt;```
TypeError: Cannot convert object to primitive value
       at Socket.emit (node:events:507:25)
       at .../node_modules/socket.io/lib/socket.js:531:14
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;A fix has been released today (2023/05/22):&lt;/p&gt;
&lt;p&gt;- https://github.com/socketio/socket.io-parser/commit/3b78117bf6ba7e99d7a5cfc1ba54d0477554a7f3, included in `socket.io-parser@4.2.3`
- https://github.com/socketio/socket.io-parser/commit/2dc3c92622dad113b8676be06f23b1ed46b02ced, included in `socket.io-parser@3.4.3`&lt;/p&gt;
&lt;p&gt;Another fix has been released for the `3.3.x` branch:&lt;/p&gt;
&lt;p&gt;- https://github.com/socketio/socket.io-parser/commit/ee006607495eca4ec7262ad080dd3a91439a5ba4, included in `socket.io-parser@3.3.4&lt;/p&gt;
&lt;p&gt;| `socket.io` version | `socket.io-parser` version                                                                              | Needs minor update?                  |
|---------------------|---------------------------------------------------------------------------------------------------------|--------------------------------------|
| `4.5.2...latest`    | `~4.2.0` ([ref](https://github.com/socketio/socket.io/commit/9890b036cf942f6b6ad2afeb6a8361c32cd5d528)) | `npm audit fix` should be sufficient |
| `4.1.3...4.5.1`     | `~4.1.1` ([ref](https://github.com/socketio/socket.io/commit/7c44893d7878cd5bba1eff43150c3e664f88fb57)) | Please upgrade to `socket.io@4.6.x`  |
| `3…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: socket.io-parser&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process.&lt;/p&gt;
&lt;p&gt;```
TypeError: Cannot convert object to primitive value
       at Socket.emit (node:events:507:25)
       at .../node_modules/socket.io/lib/socket.js:531:14
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;A fix has been released today (2023/05/22):&lt;/p&gt;
&lt;p&gt;- https://github.com/socketio/socket.io-parser/commit/3b78117bf6ba7e99d7a5cfc1ba54d0477554a7f3, included in `socket.io-parser@4.2.3`
- https://github.com/socketio/socket.io-parser/commit/2dc3c92622dad113b8676be06f23b1ed46b02ced, included in `socket.io-parser@3.4.3`&lt;/p&gt;
&lt;p&gt;Another fix has been released for the `3.3.x` branch:&lt;/p&gt;
&lt;p&gt;- https://github.com/socketio/socket.io-parser/commit/ee006607495eca4ec7262ad080dd3a91439a5ba4, included in `socket.io-parser@3.3.4&lt;/p&gt;
&lt;p&gt;| `socket.io` version | `socket.io-parser` version                                                                              | Needs minor update?                  |
|---------------------|---------------------------------------------------------------------------------------------------------|--------------------------------------|
| `4.5.2...latest`    | `~4.2.0` ([ref](https://github.com/socketio/socket.io/commit/9890b036cf942f6b6ad2afeb6a8361c32cd5d528)) | `npm audit fix` should be sufficient |
| `4.1.3...4.5.1`     | `~4.1.1` ([ref](https://github.com/socketio/socket.io/commit/7c44893d7878cd5bba1eff43150c3e664f88fb57)) | Please upgrade to `socket.io@4.6.x`  |
| `3…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cqmj-92xf-r6r9</guid>
    </item>
    <item>
      <title>gsd-2023-32695</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-32695</link>
      <description>gsd-2023-32695</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-32695</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-32695</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-32695</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-socket.io-parser, Ubuntu:20.04:LTS: node-socket.io-parser, Ubuntu:22.04:LTS: node-socket.io-parser, Ubuntu:24.04:LTS: node-socket.io-parser&lt;/p&gt;
&lt;p&gt;socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. A patch has been released in version 4.2.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-socket.io-parser, Ubuntu:20.04:LTS: node-socket.io-parser, Ubuntu:22.04:LTS: node-socket.io-parser, Ubuntu:24.04:LTS: node-socket.io-parser&lt;/p&gt;
&lt;p&gt;socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. A patch has been released in version 4.2.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-32695</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1800 — HCL BigFix: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in HCL BigFix WebUI ausnutzen, um seine Privilegien zu erweitern, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in HCL BigFix WebUI ausnutzen, um seine Privilegien zu erweitern, Dateien zu manipulieren, Informationen offenzulegen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1800</guid>
    </item>
  </channel>
</rss>
