<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:53:59 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:18480 — Important: linux-sgx security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:18480</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: sgx-common, AlmaLinux:10: sgx-libs, AlmaLinux:10: sgx-mpa, AlmaLinux:10: sgx-pccs, AlmaLinux:10: sgx-pccs-admin, AlmaLinux:10: sgx-pckid-tool, AlmaLinux:10: tdx-qgs&lt;/p&gt;
&lt;p&gt;The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)
  * node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)
  * node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)
  * lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)
  * node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: sgx-common, AlmaLinux:10: sgx-libs, AlmaLinux:10: sgx-mpa, AlmaLinux:10: sgx-pccs, AlmaLinux:10: sgx-pccs-admin, AlmaLinux:10: sgx-pckid-tool, AlmaLinux:10: tdx-qgs&lt;/p&gt;
&lt;p&gt;The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)
  * node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)
  * node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)
  * lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)
  * node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:18480</guid>
    </item>
    <item>
      <title>bdu:2026-00332</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00332</link>
      <description>bdu:2026-00332</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00332</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0065 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0065</link>
      <description>certfr-2026-avi-0065</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0065</guid>
    </item>
    <item>
      <title>EUVD-2026-267888</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267888</link>
      <description>EUVD-2026-267888</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267888</guid>
    </item>
    <item>
      <title>fkie_cve-2025-15284</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-15284</link>
      <description>&lt;p&gt;Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: &amp;lt; 6.14.1.&lt;/p&gt;
&lt;p&gt;Summary&lt;/p&gt;
&lt;p&gt;The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&amp;amp;a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit should apply uniformly across all array notations.&lt;/p&gt;
&lt;p&gt;Note: The default parameterLimit of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays larger than parameterLimit regardless of arrayLimit, because each a[]=valueconsumes one parameter slot. The severity has been reduced accordingly.&lt;/p&gt;
&lt;p&gt;Details&lt;/p&gt;
&lt;p&gt;The arrayLimit option only checked limits for indexed notation (a[0]=1&amp;amp;a[1]=2) but did not enforce it for bracket notation (a[]=1&amp;amp;a[]=2).&lt;/p&gt;
&lt;p&gt;Vulnerable code (lib/parse.js:159-162):&lt;/p&gt;
&lt;p&gt;if (root === &amp;#39;[]&amp;#39; &amp;amp;&amp;amp; options.parseArrays) {
    obj = utils.combine([], leaf);  // No arrayLimit check
}&lt;/p&gt;
&lt;p&gt;Working code (lib/parse.js:175):&lt;/p&gt;
&lt;p&gt;else if (index &amp;lt;= options.arrayLimit) {  // Limit checked here
    obj = [];
    obj[index] = leaf;
}&lt;/p&gt;
&lt;p&gt;The bracket notation handler at line 159 uses utils.combine([], leaf) without validating against options.arrayLimit, while indexed notation at line 175 checks index &amp;lt;= options.arrayLimit before creating arrays.&lt;/p&gt;
&lt;p&gt;PoC&lt;/p&gt;
&lt;p&gt;const qs = require(&amp;#39;qs&amp;#39;);
const result = qs.parse(&amp;#39;a[]=1&amp;amp;a[]=2&amp;amp;a[]=3&amp;amp;a[]=4&amp;amp;a[]=5&amp;amp;a[]=6&amp;#39;, { arrayLimit: 5 });
console.log(result.a.length);  // Output: 6 (should be max 5)&lt;/p&gt;
&lt;p&gt;Note on parameterL…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: &amp;lt; 6.14.1.&lt;/p&gt;
&lt;p&gt;Summary&lt;/p&gt;
&lt;p&gt;The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&amp;amp;a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit should apply uniformly across all array notations.&lt;/p&gt;
&lt;p&gt;Note: The default parameterLimit of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays larger than parameterLimit regardless of arrayLimit, because each a[]=valueconsumes one parameter slot. The severity has been reduced accordingly.&lt;/p&gt;
&lt;p&gt;Details&lt;/p&gt;
&lt;p&gt;The arrayLimit option only checked limits for indexed notation (a[0]=1&amp;amp;a[1]=2) but did not enforce it for bracket notation (a[]=1&amp;amp;a[]=2).&lt;/p&gt;
&lt;p&gt;Vulnerable code (lib/parse.js:159-162):&lt;/p&gt;
&lt;p&gt;if (root === &amp;#39;[]&amp;#39; &amp;amp;&amp;amp; options.parseArrays) {
    obj = utils.combine([], leaf);  // No arrayLimit check
}&lt;/p&gt;
&lt;p&gt;Working code (lib/parse.js:175):&lt;/p&gt;
&lt;p&gt;else if (index &amp;lt;= options.arrayLimit) {  // Limit checked here
    obj = [];
    obj[index] = leaf;
}&lt;/p&gt;
&lt;p&gt;The bracket notation handler at line 159 uses utils.combine([], leaf) without validating against options.arrayLimit, while indexed notation at line 175 checks index &amp;lt;= options.arrayLimit before creating arrays.&lt;/p&gt;
&lt;p&gt;PoC&lt;/p&gt;
&lt;p&gt;const qs = require(&amp;#39;qs&amp;#39;);
const result = qs.parse(&amp;#39;a[]=1&amp;amp;a[]=2&amp;amp;a[]=3&amp;amp;a[]=4&amp;amp;a[]=5&amp;amp;a[]=6&amp;#39;, { arrayLimit: 5 });
console.log(result.a.length);  // Output: 6 (should be max 5)&lt;/p&gt;
&lt;p&gt;Note on parameterL…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-15284</guid>
    </item>
    <item>
      <title>GHSA-6rw7-vpxm-498p — qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6rw7-vpxm-498p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: qs&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `arrayLimit` option in qs did not enforce limits for bracket notation (`a[]=1&amp;amp;a[]=2`), only for indexed notation (`a[0]=1`). This is a consistency bug; `arrayLimit` should apply uniformly across all array notations.&lt;/p&gt;
&lt;p&gt;**Note:** The default `parameterLimit` of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays larger than `parameterLimit` regardless of `arrayLimit`, because each `a[]=value` consumes one parameter slot. The severity has been reduced accordingly.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `arrayLimit` option only checked limits for indexed notation (`a[0]=1&amp;amp;a[1]=2`) but did not enforce it for bracket notation (`a[]=1&amp;amp;a[]=2`).&lt;/p&gt;
&lt;p&gt;**Vulnerable code** (`lib/parse.js:159-162`):
```javascript
if (root === &amp;#39;[]&amp;#39; &amp;amp;&amp;amp; options.parseArrays) {
    obj = utils.combine([], leaf);  // No arrayLimit check
}
```&lt;/p&gt;
&lt;p&gt;**Working code** (`lib/parse.js:175`):
```javascript
else if (index &amp;lt;= options.arrayLimit) {  // Limit checked here
    obj = [];
    obj[index] = leaf;
}
```&lt;/p&gt;
&lt;p&gt;The bracket notation handler at line 159 uses `utils.combine([], leaf)` without validating against `options.arrayLimit`, while indexed notation at line 175 checks `index &amp;lt;= options.arrayLimit` before creating arrays.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```javascript
const qs = require(&amp;#39;qs&amp;#39;);
const result = qs.parse(&amp;#39;a[]=1&amp;amp;a[]=2&amp;amp;a[]=3&amp;amp;a[]=4&amp;amp;a[]=5&amp;amp;a[]=6&amp;#39;, { arrayLimit: 5 });
console.log(result.a.length);  // Output: 6 (should be max 5)
```&lt;/p&gt;
&lt;p&gt;**Note on parameterLimit interaction…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: qs&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `arrayLimit` option in qs did not enforce limits for bracket notation (`a[]=1&amp;amp;a[]=2`), only for indexed notation (`a[0]=1`). This is a consistency bug; `arrayLimit` should apply uniformly across all array notations.&lt;/p&gt;
&lt;p&gt;**Note:** The default `parameterLimit` of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays larger than `parameterLimit` regardless of `arrayLimit`, because each `a[]=value` consumes one parameter slot. The severity has been reduced accordingly.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `arrayLimit` option only checked limits for indexed notation (`a[0]=1&amp;amp;a[1]=2`) but did not enforce it for bracket notation (`a[]=1&amp;amp;a[]=2`).&lt;/p&gt;
&lt;p&gt;**Vulnerable code** (`lib/parse.js:159-162`):
```javascript
if (root === &amp;#39;[]&amp;#39; &amp;amp;&amp;amp; options.parseArrays) {
    obj = utils.combine([], leaf);  // No arrayLimit check
}
```&lt;/p&gt;
&lt;p&gt;**Working code** (`lib/parse.js:175`):
```javascript
else if (index &amp;lt;= options.arrayLimit) {  // Limit checked here
    obj = [];
    obj[index] = leaf;
}
```&lt;/p&gt;
&lt;p&gt;The bracket notation handler at line 159 uses `utils.combine([], leaf)` without validating against `options.arrayLimit`, while indexed notation at line 175 checks `index &amp;lt;= options.arrayLimit` before creating arrays.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```javascript
const qs = require(&amp;#39;qs&amp;#39;);
const result = qs.parse(&amp;#39;a[]=1&amp;amp;a[]=2&amp;amp;a[]=3&amp;amp;a[]=4&amp;amp;a[]=5&amp;amp;a[]=6&amp;#39;, { arrayLimit: 5 });
console.log(result.a.length);  // Output: 6 (should be max 5)
```&lt;/p&gt;
&lt;p&gt;**Note on parameterLimit interaction…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6rw7-vpxm-498p</guid>
    </item>
    <item>
      <title>ICSA-26-071-03 — Siemens SIDIS Prime</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-071-03</link>
      <description>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-071-03</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-15284 — arrayLimit bypass in bracket notation allows DoS via memory exhaustion</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-15284</link>
      <description>msrc_CVE-2025-15284</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-15284</guid>
    </item>
    <item>
      <title>NCSC-2026-0034 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0034</link>
      <description>NCSC-2026-0034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0034</guid>
    </item>
    <item>
      <title>RHSA-2026:0261 — Red Hat Security Advisory: Red Hat Developer Hub 1.7.4 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:0261</link>
      <description>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications qs: qs: Denial of Service via improper input validation in array parsing glob: glob: Command Injection Vulnerability via Malicious Filenames node-jws: auth0/node-jws: Improper signature verification in HS256 algorithm node-forge: node-forge ASN.1 Unbounded Recursion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications qs: qs: Denial of Service via improper input validation in array parsing glob: glob: Command Injection Vulnerability via Malicious Filenames node-jws: auth0/node-jws: Improper signature verification in HS256 algorithm node-forge: node-forge ASN.1 Unbounded Recursion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:0261</guid>
    </item>
    <item>
      <title>RHSA-2026:18480 — Red Hat Security Advisory: linux-sgx security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:18480</link>
      <description>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:18480</guid>
    </item>
    <item>
      <title>RLSA-2026:18480 — Important: linux-sgx security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:18480</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: linux-sgx&lt;/p&gt;
&lt;p&gt;The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)&lt;/p&gt;
&lt;p&gt;* lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux 10 Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: linux-sgx&lt;/p&gt;
&lt;p&gt;The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)&lt;/p&gt;
&lt;p&gt;* lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux 10 Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:18480</guid>
    </item>
    <item>
      <title>SSA-485750 — SSA-485750: Multiple Vulnerabilities in SIDIS Prime Before V4.0.800</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-485750</link>
      <description>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-485750</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-15284</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-15284</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-qs, Ubuntu:16.04:LTS: node-qs, Ubuntu:18.04:LTS: node-qs, Ubuntu:Pro:20.04:LTS: node-qs, Ubuntu:22.04:LTS: node-qs, Ubuntu:24.04:LTS: node-qs, Ubuntu:25.10: node-qs, Ubuntu:26.04:LTS: node-qs&lt;/p&gt;
&lt;p&gt;Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: &amp;lt; 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&amp;amp;a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit should apply uniformly across all array notations. Note: The default parameterLimit of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays larger than parameterLimit regardless of arrayLimit, because each a[]=valueconsumes one parameter slot. The severity has been reduced accordingly. Details The arrayLimit option only checked limits for indexed notation (a[0]=1&amp;amp;a[1]=2) but did not enforce it for bracket notation (a[]=1&amp;amp;a[]=2). Vulnerable code (lib/parse.js:159-162): if (root === &amp;#39;[]&amp;#39; &amp;amp;&amp;amp; options.parseArrays) {     obj = utils.combine([], leaf);  // No arrayLimit check } Working code (lib/parse.js:175): else if (index &amp;lt;= options.arrayLimit) {  // Limit checked here     obj = [];     obj[index] = leaf; } The bracket notation handler at line 159 uses utils.combine([], leaf) without validating against options.arrayLimit, while indexed notation at line 175 checks index &amp;lt;= options.arrayLimit before creating arrays. PoC const qs = require(&amp;#39;qs&amp;#39;); const result = qs.parse(&amp;#39;a[]=1&amp;amp;a[]=2&amp;amp;a[]=3&amp;amp;a[]=4&amp;amp;a[]=5&amp;amp;a[]=6&amp;#39;, { arrayLimit: 5 }); console.log(result.a.length);  // Output: 6 (should be max 5) Note on parameterLimit interaction: The origin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-qs, Ubuntu:16.04:LTS: node-qs, Ubuntu:18.04:LTS: node-qs, Ubuntu:Pro:20.04:LTS: node-qs, Ubuntu:22.04:LTS: node-qs, Ubuntu:24.04:LTS: node-qs, Ubuntu:25.10: node-qs, Ubuntu:26.04:LTS: node-qs&lt;/p&gt;
&lt;p&gt;Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: &amp;lt; 6.14.1. Summary The arrayLimit option in qs did not enforce limits for bracket notation (a[]=1&amp;amp;a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimit should apply uniformly across all array notations. Note: The default parameterLimit of 1000 effectively mitigates the DoS scenario originally described. With default options, bracket notation cannot produce arrays larger than parameterLimit regardless of arrayLimit, because each a[]=valueconsumes one parameter slot. The severity has been reduced accordingly. Details The arrayLimit option only checked limits for indexed notation (a[0]=1&amp;amp;a[1]=2) but did not enforce it for bracket notation (a[]=1&amp;amp;a[]=2). Vulnerable code (lib/parse.js:159-162): if (root === &amp;#39;[]&amp;#39; &amp;amp;&amp;amp; options.parseArrays) {     obj = utils.combine([], leaf);  // No arrayLimit check } Working code (lib/parse.js:175): else if (index &amp;lt;= options.arrayLimit) {  // Limit checked here     obj = [];     obj[index] = leaf; } The bracket notation handler at line 159 uses utils.combine([], leaf) without validating against options.arrayLimit, while indexed notation at line 175 checks index &amp;lt;= options.arrayLimit before creating arrays. PoC const qs = require(&amp;#39;qs&amp;#39;); const result = qs.parse(&amp;#39;a[]=1&amp;amp;a[]=2&amp;amp;a[]=3&amp;amp;a[]=4&amp;amp;a[]=5&amp;amp;a[]=6&amp;#39;, { arrayLimit: 5 }); console.log(result.a.length);  // Output: 6 (should be max 5) Note on parameterLimit interaction: The origin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-15284</guid>
    </item>
    <item>
      <title>VDE-2026-009 — JUMO: Multiple products affected by nodejs vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-009</link>
      <description>&lt;p&gt;A vulnerability in the REST API of the JUMO device allows an attacker to trigger a denial‑of‑service (DoS) condition. Due to an incorrect implementation of the arrayLimit option in the Node.js qs module, limits for incoming request parameters are not properly enforced. As a result, an attacker can send specially crafted requests containing excessively large or deeply nested arrays, causing the web server to become unresponsive. This condition leads to a crash of the web server, followed by an automatic restart of the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the REST API of the JUMO device allows an attacker to trigger a denial‑of‑service (DoS) condition. Due to an incorrect implementation of the arrayLimit option in the Node.js qs module, limits for incoming request parameters are not properly enforced. As a result, an attacker can send specially crafted requests containing excessively large or deeply nested arrays, causing the web server to become unresponsive. This condition leads to a crash of the web server, followed by an automatic restart of the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-009</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0105 — Red Hat Developer Hub: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0105</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Developer Hub ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen und Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Developer Hub ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen und Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0105</guid>
    </item>
  </channel>
</rss>
