<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:39:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-01715</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01715</link>
      <description>bdu:2026-01715</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01715</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0651 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0651</link>
      <description>certfr-2025-avi-0651</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0651</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-IZ17087 — Security fix for CVE-2025-5889 applied in: argo-workflows 3.6.19-r7</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-iz17087</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-iz17087</guid>
    </item>
    <item>
      <title>EUVD-2026-243757</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-243757</link>
      <description>EUVD-2026-243757</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-243757</guid>
    </item>
    <item>
      <title>fkie_cve-2025-5889</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-5889</link>
      <description>&lt;p&gt;A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to upgrade the affected component.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to upgrade the affected component.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-5889</guid>
    </item>
    <item>
      <title>GHSA-v6h2-p8h4-qcjw — brace-expansion Regular Expression Denial of Service vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v6h2-p8h4-qcjw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: brace-expansion&lt;/p&gt;
&lt;p&gt;A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is `a5b98a4f30d7813266b221435e1eaaf25a1b0ac5`. It is recommended to upgrade the affected component.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: brace-expansion&lt;/p&gt;
&lt;p&gt;A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is `a5b98a4f30d7813266b221435e1eaaf25a1b0ac5`. It is recommended to upgrade the affected component.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v6h2-p8h4-qcjw</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-5889 — juliangruber brace-expansion index.js expand redos</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-5889</link>
      <description>msrc_CVE-2025-5889</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-5889</guid>
    </item>
    <item>
      <title>OESA-2025-1645 — nodejs-brace-expansion security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1645</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: nodejs-brace-expansion, openEuler:22.03-LTS-SP4: nodejs-brace-expansion, openEuler:24.03-LTS: nodejs-brace-expansion, openEuler:24.03-LTS-SP1: nodejs-brace-expansion, openEuler:20.03-LTS-SP4: nodejs-brace-expansion&lt;/p&gt;
&lt;p&gt;Brace expansion as known from sh/bash&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to upgrade the affected component.(CVE-2025-5889)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: nodejs-brace-expansion, openEuler:22.03-LTS-SP4: nodejs-brace-expansion, openEuler:24.03-LTS: nodejs-brace-expansion, openEuler:24.03-LTS-SP1: nodejs-brace-expansion, openEuler:20.03-LTS-SP4: nodejs-brace-expansion&lt;/p&gt;
&lt;p&gt;Brace expansion as known from sh/bash&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to upgrade the affected component.(CVE-2025-5889)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1645</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15269-1 — jupyter-bqplot-jupyterlab-0.5.44-10.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15269-1</link>
      <description>&lt;p&gt;jupyter-bqplot-jupyterlab-0.5.44-10.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jupyter-bqplot-jupyterlab-0.5.44-10.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15269-1</guid>
    </item>
    <item>
      <title>RHSA-2025:21368 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18 security, enhancement &amp; bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:21368</link>
      <description>&lt;p&gt;follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor follow-redirects: Exposure of Sensitive Information via Authorization Header leak brace-expansion: juliangruber brace-expansion index.js expand redos operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd undici: Undici Uses Insufficiently Random Values&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor follow-redirects: Exposure of Sensitive Information via Authorization Header leak brace-expansion: juliangruber brace-expansion index.js expand redos operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd undici: Undici Uses Insufficiently Random Values&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:21368</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-5889</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5889</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:25.10: node-brace-expansion&lt;/p&gt;
&lt;p&gt;A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to upgrade the affected component.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:25.10: node-brace-expansion&lt;/p&gt;
&lt;p&gt;A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.1.12, 2.0.2, 3.0.1 and 4.0.1 is able to address this issue. The name of the patch is a5b98a4f30d7813266b221435e1eaaf25a1b0ac5. It is recommended to upgrade the affected component.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5889</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2072 — IBM App Connect Enterprise: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2072</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2072</guid>
    </item>
  </channel>
</rss>
