<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:28:40 +0000</lastBuildDate>
    <item>
      <title>certfr-2024-avi-0923 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0923</link>
      <description>certfr-2024-avi-0923</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0923</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-DG43720 — Security fix for CVE-2024-45296 applied in: argo-workflows 3.6.19-r6, argo-workflows 3.7.17-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-dg43720</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;CVE-2024-45296 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;CVE-2024-45296 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-dg43720</guid>
    </item>
    <item>
      <title>EUVD-2026-211839</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-211839</link>
      <description>EUVD-2026-211839</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-211839</guid>
    </item>
    <item>
      <title>fkie_cve-2024-45296</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45296</link>
      <description>&lt;p&gt;path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-45296</guid>
    </item>
    <item>
      <title>GHSA-9wv6-86v2-598j — path-to-regexp outputs backtracking regular expressions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9wv6-86v2-598j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: path-to-regexp&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (`.`). For example, `/:a-:b`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;For users of 0.1, upgrade to `0.1.10`. All other users should upgrade to `8.0.0`.&lt;/p&gt;
&lt;p&gt;These versions add backtrack protection when a custom regex pattern is not provided:&lt;/p&gt;
&lt;p&gt;- [0.1.10](https://github.com/pillarjs/path-to-regexp/releases/tag/v0.1.10)
- [1.9.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v1.9.0)
- [3.3.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v3.3.0)
- [6.3.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v6.3.0)&lt;/p&gt;
&lt;p&gt;They do not protect against vulnerable user supplied capture groups. Protecting against explicit user patterns is out of scope for old versions and not considered a vulnerability.&lt;/p&gt;
&lt;p&gt;Version [7.1.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v7.1.0) can enable `strict: true` and get an error when the regular expression might be bad.&lt;/p&gt;
&lt;p&gt;Version [8.0.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v8.0.0) removes the features that can cause a ReDoS.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;All versions can be patched by providing a custom regular expression for parameters after the first in a single segment. As long as the custom regular expression does not match the text before the parameter, you will be safe. For example, change `/:a-:b` to `/:a-:b([^-/]+)`.&lt;/p&gt;
&lt;p&gt;If paths cannot be rewritten and versions cannot be upgraded, anothe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: path-to-regexp&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (`.`). For example, `/:a-:b`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;For users of 0.1, upgrade to `0.1.10`. All other users should upgrade to `8.0.0`.&lt;/p&gt;
&lt;p&gt;These versions add backtrack protection when a custom regex pattern is not provided:&lt;/p&gt;
&lt;p&gt;- [0.1.10](https://github.com/pillarjs/path-to-regexp/releases/tag/v0.1.10)
- [1.9.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v1.9.0)
- [3.3.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v3.3.0)
- [6.3.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v6.3.0)&lt;/p&gt;
&lt;p&gt;They do not protect against vulnerable user supplied capture groups. Protecting against explicit user patterns is out of scope for old versions and not considered a vulnerability.&lt;/p&gt;
&lt;p&gt;Version [7.1.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v7.1.0) can enable `strict: true` and get an error when the regular expression might be bad.&lt;/p&gt;
&lt;p&gt;Version [8.0.0](https://github.com/pillarjs/path-to-regexp/releases/tag/v8.0.0) removes the features that can cause a ReDoS.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;All versions can be patched by providing a custom regular expression for parameters after the first in a single segment. As long as the custom regular expression does not match the text before the parameter, you will be safe. For example, change `/:a-:b` to `/:a-:b([^-/]+)`.&lt;/p&gt;
&lt;p&gt;If paths cannot be rewritten and versions cannot be upgraded, anothe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9wv6-86v2-598j</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-45296 — path-to-regexp outputs backtracking regular expressions</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-45296</link>
      <description>msrc_CVE-2024-45296</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-45296</guid>
    </item>
    <item>
      <title>NCSC-2026-0034 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0034</link>
      <description>NCSC-2026-0034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0034</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14374-1 — argocd-cli-2.12.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14374-1</link>
      <description>&lt;p&gt;argocd-cli-2.12.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;argocd-cli-2.12.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14374-1</guid>
    </item>
    <item>
      <title>RHBA-2024:11265 — Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.4.0 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2024:11265</link>
      <description>&lt;p&gt;http-proxy-middleware: http-proxy-middleware: Denial of Service via unhandled error during path matching cross-spawn: regular expression denial of service path-to-regexp: Backtracking regular expressions cause ReDoS body-parser: Denial of Service Vulnerability in body-parser plugin-catalog-backend: prototype pollution vulnerability plugin-techdocs-backend: storage bucket directory traversal in TechDocs plugin-techdocs-backend: circumvention of XSS protection in TechDocs backstage/plugin-app-backend: Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;http-proxy-middleware: http-proxy-middleware: Denial of Service via unhandled error during path matching cross-spawn: regular expression denial of service path-to-regexp: Backtracking regular expressions cause ReDoS body-parser: Denial of Service Vulnerability in body-parser plugin-catalog-backend: prototype pollution vulnerability plugin-techdocs-backend: storage bucket directory traversal in TechDocs plugin-techdocs-backend: circumvention of XSS protection in TechDocs backstage/plugin-app-backend: Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2024:11265</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-45296</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-45296</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: node-path-to-regexp, Ubuntu:Pro:18.04:LTS: node-path-to-regexp, Ubuntu:Pro:20.04:LTS: node-path-to-regexp, Ubuntu:Pro:22.04:LTS: node-path-to-regexp, Ubuntu:Pro:24.04:LTS: node-path-to-regexp, Ubuntu:25.10: node-express, Ubuntu:26.04:LTS: node-express&lt;/p&gt;
&lt;p&gt;path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: node-path-to-regexp, Ubuntu:Pro:18.04:LTS: node-path-to-regexp, Ubuntu:Pro:20.04:LTS: node-path-to-regexp, Ubuntu:Pro:22.04:LTS: node-path-to-regexp, Ubuntu:Pro:24.04:LTS: node-path-to-regexp, Ubuntu:25.10: node-express, Ubuntu:26.04:LTS: node-express&lt;/p&gt;
&lt;p&gt;path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-45296</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3211 — IBM App Connect Enterprise: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3211</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3211</guid>
    </item>
  </channel>
</rss>
