<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:43:37 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0281 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0281</link>
      <description>certfr-2026-avi-0281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0281</guid>
    </item>
    <item>
      <title>EUVD-2026-265137</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265137</link>
      <description>EUVD-2026-265137</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265137</guid>
    </item>
    <item>
      <title>fkie_cve-2025-14874</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14874</link>
      <description>&lt;p&gt;A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-14874</guid>
    </item>
    <item>
      <title>GHSA-rcmh-qjqh-p98v — Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rcmh-qjqh-p98v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nodemailer, Maven: org.webjars.npm:nodemailer&lt;/p&gt;
&lt;p&gt;### Summary
A DoS can occur that immediately halts the system due to the use of an unsafe function.&lt;/p&gt;
&lt;p&gt;### Details
According to **RFC 5322**, nested group structures (a group inside another group) are not allowed. Therefore, in lib/addressparser/index.js, the email address parser performs flattening when nested groups appear, since such input is likely to be abnormal. (If the address is valid, it is added as-is.) In other words, the parser flattens all nested groups and inserts them into the final group list.
However, the code implemented for this flattening process can be exploited by malicious input and triggers DoS&lt;/p&gt;
&lt;p&gt;RFC 5322 uses a colon (:) to define a group, and commas (,) are used to separate members within a group.
At the following location in lib/addressparser/index.js:&lt;/p&gt;
&lt;p&gt;https://github.com/nodemailer/nodemailer/blob/master/lib/addressparser/index.js#L90&lt;/p&gt;
&lt;p&gt;there is code that performs this flattening. The issue occurs when the email address parser attempts to process the following kind of malicious address header:&lt;/p&gt;
&lt;p&gt;```g0: g1: g2: g3: ... gN: victim@example.com;```&lt;/p&gt;
&lt;p&gt;Because no recursion depth limit is enforced, the parser repeatedly invokes itself in the pattern
`addressparser → _handleAddress → addressparser → ...`
for each nested group. As a result, when an attacker sends a header containing many colons, Nodemailer enters infinite recursion, eventually throwing Maximum call stack size exceeded and causing the process to terminate immediately. Due to the structure of this…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nodemailer, Maven: org.webjars.npm:nodemailer&lt;/p&gt;
&lt;p&gt;### Summary
A DoS can occur that immediately halts the system due to the use of an unsafe function.&lt;/p&gt;
&lt;p&gt;### Details
According to **RFC 5322**, nested group structures (a group inside another group) are not allowed. Therefore, in lib/addressparser/index.js, the email address parser performs flattening when nested groups appear, since such input is likely to be abnormal. (If the address is valid, it is added as-is.) In other words, the parser flattens all nested groups and inserts them into the final group list.
However, the code implemented for this flattening process can be exploited by malicious input and triggers DoS&lt;/p&gt;
&lt;p&gt;RFC 5322 uses a colon (:) to define a group, and commas (,) are used to separate members within a group.
At the following location in lib/addressparser/index.js:&lt;/p&gt;
&lt;p&gt;https://github.com/nodemailer/nodemailer/blob/master/lib/addressparser/index.js#L90&lt;/p&gt;
&lt;p&gt;there is code that performs this flattening. The issue occurs when the email address parser attempts to process the following kind of malicious address header:&lt;/p&gt;
&lt;p&gt;```g0: g1: g2: g3: ... gN: victim@example.com;```&lt;/p&gt;
&lt;p&gt;Because no recursion depth limit is enforced, the parser repeatedly invokes itself in the pattern
`addressparser → _handleAddress → addressparser → ...`
for each nested group. As a result, when an attacker sends a header containing many colons, Nodemailer enters infinite recursion, eventually throwing Maximum call stack size exceeded and causing the process to terminate immediately. Due to the structure of this…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rcmh-qjqh-p98v</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-14874</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14874</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-nodemailer, Ubuntu:22.04:LTS: node-nodemailer, Ubuntu:24.04:LTS: node-nodemailer, Ubuntu:25.10: node-nodemailer, Ubuntu:26.04:LTS: node-nodemailer&lt;/p&gt;
&lt;p&gt;A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-nodemailer, Ubuntu:22.04:LTS: node-nodemailer, Ubuntu:24.04:LTS: node-nodemailer, Ubuntu:25.10: node-nodemailer, Ubuntu:26.04:LTS: node-nodemailer&lt;/p&gt;
&lt;p&gt;A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14874</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0759 — IBM Planning Analytics: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0759</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Planning Analytics ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Planning Analytics ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0759</guid>
    </item>
  </channel>
</rss>
