<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:40:29 +0000</lastBuildDate>
    <item>
      <title>certfr-2024-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0958</link>
      <description>certfr-2024-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0958</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-NQ54168 — Security fix for CVE-2024-47764 applied in: argo-workflows 3.6.19-r7</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-nq54168</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-nq54168</guid>
    </item>
    <item>
      <title>EUVD-2026-193015</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-193015</link>
      <description>EUVD-2026-193015</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-193015</guid>
    </item>
    <item>
      <title>fkie_cve-2024-47764</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47764</link>
      <description>&lt;p&gt;cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-47764</guid>
    </item>
    <item>
      <title>GHSA-pxg6-pf52-xh8x — cookie accepts cookie name, path, and domain with out of bounds characters</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pxg6-pf52-xh8x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: cookie&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. For example, `serialize(&amp;#34;userName=&amp;lt;script&amp;gt;alert(&amp;#39;XSS3&amp;#39;)&amp;lt;/script&amp;gt;; Max-Age=2592000; a&amp;#34;, value)` would result in `&amp;#34;userName=&amp;lt;script&amp;gt;alert(&amp;#39;XSS3&amp;#39;)&amp;lt;/script&amp;gt;; Max-Age=2592000; a=test&amp;#34;`, setting `userName` cookie to `&amp;lt;script&amp;gt;` and ignoring `value`.&lt;/p&gt;
&lt;p&gt;A similar escape can be used for `path` and `domain`, which could be abused to alter other fields of the cookie.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Upgrade to 0.7.0, which updates the validation for `name`, `path`, and `domain`.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Avoid passing untrusted or arbitrary values for these fields, ensure they are set by the application instead of user input.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://github.com/jshttp/cookie/pull/167&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: cookie&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. For example, `serialize(&amp;#34;userName=&amp;lt;script&amp;gt;alert(&amp;#39;XSS3&amp;#39;)&amp;lt;/script&amp;gt;; Max-Age=2592000; a&amp;#34;, value)` would result in `&amp;#34;userName=&amp;lt;script&amp;gt;alert(&amp;#39;XSS3&amp;#39;)&amp;lt;/script&amp;gt;; Max-Age=2592000; a=test&amp;#34;`, setting `userName` cookie to `&amp;lt;script&amp;gt;` and ignoring `value`.&lt;/p&gt;
&lt;p&gt;A similar escape can be used for `path` and `domain`, which could be abused to alter other fields of the cookie.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Upgrade to 0.7.0, which updates the validation for `name`, `path`, and `domain`.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Avoid passing untrusted or arbitrary values for these fields, ensure they are set by the application instead of user input.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://github.com/jshttp/cookie/pull/167&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pxg6-pf52-xh8x</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-47764 — cookie accepts cookie name path and domain with out of bounds characters</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-47764</link>
      <description>msrc_CVE-2024-47764</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-47764</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-47764</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47764</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-cookie, Ubuntu:18.04:LTS: node-cookie, Ubuntu:20.04:LTS: node-cookie, Ubuntu:22.04:LTS: node-cookie, Ubuntu:24.04:LTS: node-cookie&lt;/p&gt;
&lt;p&gt;cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-cookie, Ubuntu:18.04:LTS: node-cookie, Ubuntu:20.04:LTS: node-cookie, Ubuntu:22.04:LTS: node-cookie, Ubuntu:24.04:LTS: node-cookie&lt;/p&gt;
&lt;p&gt;cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47764</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0034 — IBM App Connect Enterprise: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0034</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0034</guid>
    </item>
  </channel>
</rss>
