<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:05:18 +0000</lastBuildDate>
    <item>
      <title>certfr-2024-avi-0514 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0514</link>
      <description>certfr-2024-avi-0514</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0514</guid>
    </item>
    <item>
      <title>EUVD-2026-5464</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-5464</link>
      <description>EUVD-2026-5464</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-5464</guid>
    </item>
    <item>
      <title>fkie_cve-2024-34351</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-34351</link>
      <description>&lt;p&gt;Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are 1) Next.js is running in a self-hosted manner; 2) the Next.js application makes use of Server Actions; and 3) the Server Action performs a redirect to a relative path which starts with a `/`. This vulnerability was fixed in Next.js `14.1.1`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are 1) Next.js is running in a self-hosted manner; 2) the Next.js application makes use of Server Actions; and 3) the Server Action performs a redirect to a relative path which starts with a `/`. This vulnerability was fixed in Next.js `14.1.1`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-34351</guid>
    </item>
    <item>
      <title>GHSA-fr5h-rqp8-mj6g — Next.js Server-Side Request Forgery in Server Actions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fr5h-rqp8-mj6g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: next&lt;/p&gt;
&lt;p&gt;### Impact
A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions by security researchers at Assetnote. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself.&lt;/p&gt;
&lt;p&gt;#### Prerequisites
* Next.js (`&amp;lt;14.1.1`) is running in a self-hosted* manner.
* The Next.js application makes use of Server Actions.
* The Server Action performs a redirect to a relative path which starts with a `/`.&lt;/p&gt;
&lt;p&gt;\* Many hosting providers (including Vercel) route requests based on the Host header, so we do not believe that this vulnerability affects any Next.js applications where routing is done in this manner.&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability was patched in [#62561](https://github.com/vercel/next.js/pull/62561) and fixed in Next.js `14.1.1`.
 
### Workarounds
There are no official workarounds for this vulnerability. We recommend upgrading to Next.js `14.1.1`.&lt;/p&gt;
&lt;p&gt;### Credit
Vercel and the Next.js team thank Assetnote for responsibly disclosing this issue to us, and for working with us to verify the fix. Thanks to:&lt;/p&gt;
&lt;p&gt;Adam Kues - Assetnote
Shubham Shah - Assetnote&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: next&lt;/p&gt;
&lt;p&gt;### Impact
A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions by security researchers at Assetnote. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself.&lt;/p&gt;
&lt;p&gt;#### Prerequisites
* Next.js (`&amp;lt;14.1.1`) is running in a self-hosted* manner.
* The Next.js application makes use of Server Actions.
* The Server Action performs a redirect to a relative path which starts with a `/`.&lt;/p&gt;
&lt;p&gt;\* Many hosting providers (including Vercel) route requests based on the Host header, so we do not believe that this vulnerability affects any Next.js applications where routing is done in this manner.&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability was patched in [#62561](https://github.com/vercel/next.js/pull/62561) and fixed in Next.js `14.1.1`.
 
### Workarounds
There are no official workarounds for this vulnerability. We recommend upgrading to Next.js `14.1.1`.&lt;/p&gt;
&lt;p&gt;### Credit
Vercel and the Next.js team thank Assetnote for responsibly disclosing this issue to us, and for working with us to verify the fix. Thanks to:&lt;/p&gt;
&lt;p&gt;Adam Kues - Assetnote
Shubham Shah - Assetnote&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fr5h-rqp8-mj6g</guid>
    </item>
    <item>
      <title>RHSA-2026:13571 — Red Hat Security Advisory: Streams for Apache Kafka 3.2.0 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13571</link>
      <description>&lt;p&gt;jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression next: Next.js Server-Side Request Forgery in Server Actions golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files lodash: lodash: Arbitrary code execution via untrusted input in template imports react-server-dom-webpack: react-server-dom-parcel: reactreact-server-dom-turbopack: React Server Components: Denial of Service via specially crafted HTTP requests next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood axios: Axios: Remote Code Execution via Prototype Pollution escalation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression next: Next.js Server-Side Request Forgery in Server Actions golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files lodash: lodash: Arbitrary code execution via untrusted input in template imports react-server-dom-webpack: react-server-dom-parcel: reactreact-server-dom-turbopack: React Server Components: Denial of Service via specially crafted HTTP requests next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood axios: Axios: Remote Code Execution via Prototype Pollution escalation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13571</guid>
    </item>
  </channel>
</rss>
