<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:03:31 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:5814 — Moderate: nodejs:20 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:5814</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: nodejs-packaging-bundler, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* node-tar: denial of service while parsing a tar file due to lack of folders depth validation (CVE-2024-28863)
* nodejs: Bypass network import restriction via data URL (CVE-2024-22020)
* nodejs: fs.lstat bypasses permission model (CVE-2024-22018)
* nodejs: fs.fchown/fchmod bypasses permission model (CVE-2024-36137)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: nodejs-packaging-bundler, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* node-tar: denial of service while parsing a tar file due to lack of folders depth validation (CVE-2024-28863)
* nodejs: Bypass network import restriction via data URL (CVE-2024-22020)
* nodejs: fs.lstat bypasses permission model (CVE-2024-22018)
* nodejs: fs.fchown/fchmod bypasses permission model (CVE-2024-36137)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:5814</guid>
    </item>
    <item>
      <title>bdu:2024-09418</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-09418</link>
      <description>bdu:2024-09418</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-09418</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0579 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</link>
      <description>certfr-2024-avi-0579</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</guid>
    </item>
    <item>
      <title>EUVD-2026-217372</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217372</link>
      <description>EUVD-2026-217372</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217372</guid>
    </item>
    <item>
      <title>fkie_cve-2024-28863</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-28863</link>
      <description>&lt;p&gt;node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-28863</guid>
    </item>
    <item>
      <title>GHSA-f5x3-32g6-xq36 — Denial of service while parsing a tar file due to lack of folders count validation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f5x3-32g6-xq36</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: node-tar, npm: tar&lt;/p&gt;
&lt;p&gt;## Description: 
During some analysis today on npm&amp;#39;s `node-tar` package I came across the folder creation process, Basicly if you provide node-tar with a path like this `./a/b/c/foo.txt` it would create every folder and sub-folder here a, b and c until it reaches the last folder to create `foo.txt`, In-this case I noticed that there&amp;#39;s no validation at all on the amount of folders being created, that said we&amp;#39;re actually able to CPU and memory consume the system running node-tar and even crash the nodejs client within few seconds of running it using a path with too many sub-folders inside&lt;/p&gt;
&lt;p&gt;## Steps To Reproduce:
You can reproduce this issue by downloading the tar file I provided in the resources and using node-tar to extract it, you should get the same behavior as the video&lt;/p&gt;
&lt;p&gt;## Proof Of Concept:
Here&amp;#39;s a [video](https://hackerone-us-west-2-production-attachments.s3.us-west-2.amazonaws.com/3i7uojw8s52psar6pg8zkdo4h9io?response-content-disposition=attachment%3B%20filename%3D%22tar-dos-poc.webm%22%3B%20filename%2A%3DUTF-8%27%27tar-dos-poc.webm&amp;amp;response-content-type=video%2Fwebm&amp;amp;X-Amz-Algorithm=AWS4-HMAC-SHA256&amp;amp;X-Amz-Credential=ASIAQGK6FURQSWWGDXHA%2F20240312%2Fus-west-2%2Fs3%2Faws4_request&amp;amp;X-Amz-Date=20240312T080103Z&amp;amp;X-Amz-Expires=3600&amp;amp;X-Amz-Security-Token=IQoJb3JpZ2luX2VjEDcaCXVzLXdlc3QtMiJHMEUCID3xYDc6emXVPOg8iVR5dVk0u3gguTPIDJ0OIE%2BKxj17AiEAi%2BGiay1gGMWhH%2F031fvMYnSsa8U7CnpZpxvFAYqNRwgqsQUIQBADGgwwMTM2MTkyNzQ4NDkiDAaj6OgUL3gg4hhLLCqOBUUrOgWSqaK%2FmxN6nKRvB4Who3LIyzswFKm9LV9…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: node-tar, npm: tar&lt;/p&gt;
&lt;p&gt;## Description: 
During some analysis today on npm&amp;#39;s `node-tar` package I came across the folder creation process, Basicly if you provide node-tar with a path like this `./a/b/c/foo.txt` it would create every folder and sub-folder here a, b and c until it reaches the last folder to create `foo.txt`, In-this case I noticed that there&amp;#39;s no validation at all on the amount of folders being created, that said we&amp;#39;re actually able to CPU and memory consume the system running node-tar and even crash the nodejs client within few seconds of running it using a path with too many sub-folders inside&lt;/p&gt;
&lt;p&gt;## Steps To Reproduce:
You can reproduce this issue by downloading the tar file I provided in the resources and using node-tar to extract it, you should get the same behavior as the video&lt;/p&gt;
&lt;p&gt;## Proof Of Concept:
Here&amp;#39;s a [video](https://hackerone-us-west-2-production-attachments.s3.us-west-2.amazonaws.com/3i7uojw8s52psar6pg8zkdo4h9io?response-content-disposition=attachment%3B%20filename%3D%22tar-dos-poc.webm%22%3B%20filename%2A%3DUTF-8%27%27tar-dos-poc.webm&amp;amp;response-content-type=video%2Fwebm&amp;amp;X-Amz-Algorithm=AWS4-HMAC-SHA256&amp;amp;X-Amz-Credential=ASIAQGK6FURQSWWGDXHA%2F20240312%2Fus-west-2%2Fs3%2Faws4_request&amp;amp;X-Amz-Date=20240312T080103Z&amp;amp;X-Amz-Expires=3600&amp;amp;X-Amz-Security-Token=IQoJb3JpZ2luX2VjEDcaCXVzLXdlc3QtMiJHMEUCID3xYDc6emXVPOg8iVR5dVk0u3gguTPIDJ0OIE%2BKxj17AiEAi%2BGiay1gGMWhH%2F031fvMYnSsa8U7CnpZpxvFAYqNRwgqsQUIQBADGgwwMTM2MTkyNzQ4NDkiDAaj6OgUL3gg4hhLLCqOBUUrOgWSqaK%2FmxN6nKRvB4Who3LIyzswFKm9LV9…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f5x3-32g6-xq36</guid>
    </item>
    <item>
      <title>gsd-2024-28863</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-28863</link>
      <description>gsd-2024-28863</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-28863</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-28863 — node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-28863</link>
      <description>msrc_CVE-2024-28863</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-28863</guid>
    </item>
    <item>
      <title>RHBA-2024:4924 — Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.2.2 bugfix release</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2024:4924</link>
      <description>&lt;p&gt;node-tar: denial of service while parsing a tar file due to lack of folders depth validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-tar: denial of service while parsing a tar file due to lack of folders depth validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2024:4924</guid>
    </item>
    <item>
      <title>RHSA-2024:5814 — Red Hat Security Advisory: nodejs:20 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:5814</link>
      <description>&lt;p&gt;nodejs: fs.lstat bypasses permission model nodejs: Bypass network import restriction via data URL node-tar: denial of service while parsing a tar file due to lack of folders depth validation nodejs: fs.fchown/fchmod bypasses permission model&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs: fs.lstat bypasses permission model nodejs: Bypass network import restriction via data URL node-tar: denial of service while parsing a tar file due to lack of folders depth validation nodejs: fs.fchown/fchmod bypasses permission model&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:5814</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-28863</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28863</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-tar, Ubuntu:22.04:LTS: node-tar, Ubuntu:24.04:LTS: node-tar&lt;/p&gt;
&lt;p&gt;node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-tar, Ubuntu:22.04:LTS: node-tar, Ubuntu:24.04:LTS: node-tar&lt;/p&gt;
&lt;p&gt;node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28863</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1215 — IBM App Connect Enterprise: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1215</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1215</guid>
    </item>
  </channel>
</rss>
