<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:12:23 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:8467 — Important: nodejs:22 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:8467</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: nodejs, AlmaLinux:9: nodejs-devel, AlmaLinux:9: nodejs-docs, AlmaLinux:9: nodejs-full-i18n, AlmaLinux:9: nodejs-libs, AlmaLinux:9: nodejs-nodemon, AlmaLinux:9: nodejs-packaging, AlmaLinux:9: nodejs-packaging-bundler, AlmaLinux:9: npm, AlmaLinux:9: v8-12.4-devel&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs: Remote Crash via SignTraits::DeriveBits() in Node.js (CVE-2025-23166)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: nodejs, AlmaLinux:9: nodejs-devel, AlmaLinux:9: nodejs-docs, AlmaLinux:9: nodejs-full-i18n, AlmaLinux:9: nodejs-libs, AlmaLinux:9: nodejs-nodemon, AlmaLinux:9: nodejs-packaging, AlmaLinux:9: nodejs-packaging-bundler, AlmaLinux:9: npm, AlmaLinux:9: v8-12.4-devel&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs: Remote Crash via SignTraits::DeriveBits() in Node.js (CVE-2025-23166)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:8467</guid>
    </item>
    <item>
      <title>bdu:2025-10620</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10620</link>
      <description>bdu:2025-10620</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10620</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-23166</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-23166</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: nodejs, Alpaquita:23: openjdk-nik-23-17, Alpaquita:23: openjdk-nik-23-21, Alpaquita:23: openjdk-nik-24-24, Alpaquita:25: openjdk-nik-23-17, Alpaquita:25: openjdk-nik-23-21, Alpaquita:25: openjdk-nik-24-24, Alpaquita:stream: nodejs, Alpaquita:stream: openjdk-nik-23-17, Alpaquita:stream: openjdk-nik-23-21 and 12 more&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: nodejs, Alpaquita:23: openjdk-nik-23-17, Alpaquita:23: openjdk-nik-23-21, Alpaquita:23: openjdk-nik-24-24, Alpaquita:25: openjdk-nik-23-17, Alpaquita:25: openjdk-nik-23-21, Alpaquita:25: openjdk-nik-24-24, Alpaquita:stream: nodejs, Alpaquita:stream: openjdk-nik-23-17, Alpaquita:stream: openjdk-nik-23-21 and 12 more&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-23166</guid>
    </item>
    <item>
      <title>BIT-node-2025-23166</title>
      <link>https://cve.radiocsirt.org/vuln/bit-node-2025-23166</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: node&lt;/p&gt;
&lt;p&gt;The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: node&lt;/p&gt;
&lt;p&gt;The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-node-2025-23166</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0434 — De multiples vulnérabilités ont été découvertes dans Node.js. Elles permettent à un attaquant de provoquer un déni de s…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0434</link>
      <description>certfr-2025-avi-0434</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0434</guid>
    </item>
    <item>
      <title>EUVD-2026-241464</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-241464</link>
      <description>EUVD-2026-241464</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-241464</guid>
    </item>
    <item>
      <title>fkie_cve-2025-23166</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-23166</link>
      <description>&lt;p&gt;The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-23166</guid>
    </item>
    <item>
      <title>GHSA-rrjv-57mm-j6cm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rrjv-57mm-j6cm</link>
      <description>&lt;p&gt;The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rrjv-57mm-j6cm</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-23166 — The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when execut…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-23166</link>
      <description>msrc_CVE-2025-23166</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-23166</guid>
    </item>
    <item>
      <title>OESA-2025-1533 — nodejs security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1533</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: nodejs&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;amp;amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service.&lt;/p&gt;
&lt;p&gt;Impact:
* This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.(CVE-2025-23165)&lt;/p&gt;
&lt;p&gt;The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.(CVE-2025-23166)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: nodejs&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;amp;amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading to a denial of service.&lt;/p&gt;
&lt;p&gt;Impact:
* This vulnerability affects APIs relying on `ReadFileUtf8` on Node.js release lines: v20 and v22.(CVE-2025-23165)&lt;/p&gt;
&lt;p&gt;The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.(CVE-2025-23166)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1533</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15250-1 — corepack22-22.15.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15250-1</link>
      <description>&lt;p&gt;corepack22-22.15.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;corepack22-22.15.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15250-1</guid>
    </item>
    <item>
      <title>RHSA-2025:8493 — Red Hat Security Advisory: nodejs22 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:8493</link>
      <description>&lt;p&gt;nodejs: Memory Leak in Node.js ReadFileUtf8 Binding Leading to DoS nodejs: Remote Crash via SignTraits::DeriveBits() in Node.js&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs: Memory Leak in Node.js ReadFileUtf8 Binding Leading to DoS nodejs: Remote Crash via SignTraits::DeriveBits() in Node.js&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:8493</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01878-1 — Security update for nodejs22</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01878-1</link>
      <description>&lt;p&gt;Security update for nodejs22&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs22&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01878-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-23166</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23166</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: nodejs&lt;/p&gt;
&lt;p&gt;The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: nodejs&lt;/p&gt;
&lt;p&gt;The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23166</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1055 — Node.js: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1055</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um einen Denial of Service Angriff durchzuführen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um einen Denial of Service Angriff durchzuführen oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1055</guid>
    </item>
  </channel>
</rss>
