<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:49:56 +0000</lastBuildDate>
    <item>
      <title>certfr-2024-avi-0010 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0010</link>
      <description>certfr-2024-avi-0010</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0010</guid>
    </item>
    <item>
      <title>EUVD-2026-187570</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-187570</link>
      <description>EUVD-2026-187570</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-187570</guid>
    </item>
    <item>
      <title>fkie_cve-2023-43646</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-43646</link>
      <description>&lt;p&gt;get-func-name is a module to retrieve a function&amp;#39;s name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious input. This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input: &amp;#39;\t&amp;#39;.repeat(54773) + &amp;#39;\t/function/i&amp;#39;. This issue has been addressed in commit `f934b228b` which has been included in releases from 2.0.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;get-func-name is a module to retrieve a function&amp;#39;s name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious input. This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input: &amp;#39;\t&amp;#39;.repeat(54773) + &amp;#39;\t/function/i&amp;#39;. This issue has been addressed in commit `f934b228b` which has been included in releases from 2.0.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-43646</guid>
    </item>
    <item>
      <title>GHSA-4q6p-r6v2-jvc5 — Chaijs/get-func-name vulnerable to ReDoS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4q6p-r6v2-jvc5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: get-func-name&lt;/p&gt;
&lt;p&gt;The current regex implementation for parsing values in the module is susceptible to excessive backtracking, leading to potential DoS attacks. The regex implementation in question is as follows:&lt;/p&gt;
&lt;p&gt;```js
const functionNameMatch = /\s*function(?:\s|\s*\/\*[^(?:*/)]+\*\/\s*)*([^\s(/]+)/;
```&lt;/p&gt;
&lt;p&gt;This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input:&lt;/p&gt;
&lt;p&gt;```js
&amp;#39;\t&amp;#39;.repeat(54773) + &amp;#39;\t/function/i&amp;#39;
```&lt;/p&gt;
&lt;p&gt;Here is a simple PoC code to demonstrate the issue:&lt;/p&gt;
&lt;p&gt;```js
const protocolre = /\sfunction(?:\s|\s/*[^(?:*\/)]+*/\s*)*([^\(\/]+)/;&lt;/p&gt;
&lt;p&gt;const startTime = Date.now();
const maliciousInput = &amp;#39;\t&amp;#39;.repeat(54773) + &amp;#39;\t/function/i&amp;#39;&lt;/p&gt;
&lt;p&gt;protocolre.test(maliciousInput);&lt;/p&gt;
&lt;p&gt;const endTime = Date.now();&lt;/p&gt;
&lt;p&gt;console.log(&amp;#34;process time: &amp;#34;, endTime - startTime, &amp;#34;ms&amp;#34;);
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: get-func-name&lt;/p&gt;
&lt;p&gt;The current regex implementation for parsing values in the module is susceptible to excessive backtracking, leading to potential DoS attacks. The regex implementation in question is as follows:&lt;/p&gt;
&lt;p&gt;```js
const functionNameMatch = /\s*function(?:\s|\s*\/\*[^(?:*/)]+\*\/\s*)*([^\s(/]+)/;
```&lt;/p&gt;
&lt;p&gt;This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input:&lt;/p&gt;
&lt;p&gt;```js
&amp;#39;\t&amp;#39;.repeat(54773) + &amp;#39;\t/function/i&amp;#39;
```&lt;/p&gt;
&lt;p&gt;Here is a simple PoC code to demonstrate the issue:&lt;/p&gt;
&lt;p&gt;```js
const protocolre = /\sfunction(?:\s|\s/*[^(?:*\/)]+*/\s*)*([^\(\/]+)/;&lt;/p&gt;
&lt;p&gt;const startTime = Date.now();
const maliciousInput = &amp;#39;\t&amp;#39;.repeat(54773) + &amp;#39;\t/function/i&amp;#39;&lt;/p&gt;
&lt;p&gt;protocolre.test(maliciousInput);&lt;/p&gt;
&lt;p&gt;const endTime = Date.now();&lt;/p&gt;
&lt;p&gt;console.log(&amp;#34;process time: &amp;#34;, endTime - startTime, &amp;#34;ms&amp;#34;);
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4q6p-r6v2-jvc5</guid>
    </item>
    <item>
      <title>gsd-2023-43646</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-43646</link>
      <description>gsd-2023-43646</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-43646</guid>
    </item>
    <item>
      <title>RHSA-2024:1383 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.15.0 security, enhancement, &amp; bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:1383</link>
      <description>&lt;p&gt;rpm: TOCTOU race in checks for unsafe symlinks rpm: races with chown/chmod/capabilities calls during installation rpm: checks for unsafe symlinks are not performed for intermediary directories Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration openssl: Incorrect cipher key and IV length processing vault: inbound client requests can trigger a denial of service gnutls: timing side-channel in the RSA-PSK authentication sqlite: heap-buffer-overflow at sessionfuzz golang: crypto/internal/nistec: specific unreduced P-256 scalars produce incorrect results follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple sudo: Sudo does not escape control characters in log messages sudo: Sudo does not escape control characters in sudoreplay output golang: net/http: insufficient sanitization of Host header golang: crypto/tls: slow verification of certificate chains containing large RSA keys golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake libxml2: crafted xml can cause global buffer overflow nodejs-ip: arbitrary code execution via the isPublic() function sudo: Targeted Cor…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rpm: TOCTOU race in checks for unsafe symlinks rpm: races with chown/chmod/capabilities calls during installation rpm: checks for unsafe symlinks are not performed for intermediary directories Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration openssl: Incorrect cipher key and IV length processing vault: inbound client requests can trigger a denial of service gnutls: timing side-channel in the RSA-PSK authentication sqlite: heap-buffer-overflow at sessionfuzz golang: crypto/internal/nistec: specific unreduced P-256 scalars produce incorrect results follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse() python: Parsing errors in email/_parseaddr.py lead to incorrect value in email address part of tuple sudo: Sudo does not escape control characters in log messages sudo: Sudo does not escape control characters in sudoreplay output golang: net/http: insufficient sanitization of Host header golang: crypto/tls: slow verification of certificate chains containing large RSA keys golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake libxml2: crafted xml can cause global buffer overflow nodejs-ip: arbitrary code execution via the isPublic() function sudo: Targeted Cor…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:1383</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-43646</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43646</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-get-func-name, Ubuntu:20.04:LTS: node-get-func-name, Ubuntu:22.04:LTS: node-get-func-name, Ubuntu:22.04:LTS: qt6-webengine, Ubuntu:24.04:LTS: node-get-func-name, Ubuntu:24.04:LTS: qt6-webengine, Ubuntu:25.10: node-get-func-name, Ubuntu:25.10: qt6-webengine, Ubuntu:26.04:LTS: node-get-func-name, Ubuntu:26.04:LTS: qt6-webengine&lt;/p&gt;
&lt;p&gt;get-func-name is a module to retrieve a function&amp;#39;s name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious input. This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input: &amp;#39;\t&amp;#39;.repeat(54773) + &amp;#39;\t/function/i&amp;#39;. This issue has been addressed in commit `f934b228b` which has been included in releases from 2.0.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-get-func-name, Ubuntu:20.04:LTS: node-get-func-name, Ubuntu:22.04:LTS: node-get-func-name, Ubuntu:22.04:LTS: qt6-webengine, Ubuntu:24.04:LTS: node-get-func-name, Ubuntu:24.04:LTS: qt6-webengine, Ubuntu:25.10: node-get-func-name, Ubuntu:25.10: qt6-webengine, Ubuntu:26.04:LTS: node-get-func-name, Ubuntu:26.04:LTS: qt6-webengine&lt;/p&gt;
&lt;p&gt;get-func-name is a module to retrieve a function&amp;#39;s name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious input. This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input: &amp;#39;\t&amp;#39;.repeat(54773) + &amp;#39;\t/function/i&amp;#39;. This issue has been addressed in commit `f934b228b` which has been included in releases from 2.0.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43646</guid>
    </item>
  </channel>
</rss>
