<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:33:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10877</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10877</link>
      <description>bdu:2026-10877</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10877</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0112 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0112</link>
      <description>certfr-2026-avi-0112</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0112</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-GV78775 — Security fix for CVE-2025-64718 applied in: argo-workflows 3.6.19-r7, argo-workflows 3.7.15-r3</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-gv78775</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;CVE-2025-64718 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;CVE-2025-64718 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-gv78775</guid>
    </item>
    <item>
      <title>EUVD-2026-266981</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266981</link>
      <description>EUVD-2026-266981</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266981</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64718</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64718</link>
      <description>&lt;p&gt;js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it&amp;#39;s possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it&amp;#39;s possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64718</guid>
    </item>
    <item>
      <title>GHSA-mh29-5h37-fv8m — js-yaml has prototype pollution in merge (&lt;&lt;)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mh29-5h37-fv8m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: js-yaml&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In js-yaml 4.1.0, 4.0.0, and 3.14.1 and below, it&amp;#39;s possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Problem is patched in js-yaml 4.1.1 and 3.14.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;You can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: js-yaml&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In js-yaml 4.1.0, 4.0.0, and 3.14.1 and below, it&amp;#39;s possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Problem is patched in js-yaml 4.1.1 and 3.14.2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;You can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mh29-5h37-fv8m</guid>
    </item>
    <item>
      <title>ICSA-26-071-03 — Siemens SIDIS Prime</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-071-03</link>
      <description>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-071-03</guid>
    </item>
    <item>
      <title>NCSC-2026-0022 — Kwetsbaarheden verholpen in Oracle Communications producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0022</link>
      <description>NCSC-2026-0022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0022</guid>
    </item>
    <item>
      <title>OESA-2026-1166 — nodejs-js-yaml security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1166</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: nodejs-js-yaml&lt;/p&gt;
&lt;p&gt;This is an implementation of YAML (YAML Ain&amp;amp;amp;apos;t Markup Language), a human friendly data serialization language. It started as PyYAML port, and was completely rewritten from scratch.  Now it&amp;amp;amp;apos;s very fast, and supports the 1.2 spec.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;js-yaml is a JavaScript YAML parser and dumper. In js-yaml 4.1.0 and below, it&amp;amp;apos;s possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (__proto__). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1. Users can protect against this kind of attack on the server by using node --disable-proto=delete or deno (in Deno, pollution protection is on by default).(CVE-2025-64718)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: nodejs-js-yaml&lt;/p&gt;
&lt;p&gt;This is an implementation of YAML (YAML Ain&amp;amp;amp;apos;t Markup Language), a human friendly data serialization language. It started as PyYAML port, and was completely rewritten from scratch.  Now it&amp;amp;amp;apos;s very fast, and supports the 1.2 spec.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;js-yaml is a JavaScript YAML parser and dumper. In js-yaml 4.1.0 and below, it&amp;amp;apos;s possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (__proto__). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1. Users can protect against this kind of attack on the server by using node --disable-proto=delete or deno (in Deno, pollution protection is on by default).(CVE-2025-64718)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1166</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10036-1 — cockpit-repos-4.6-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10036-1</link>
      <description>&lt;p&gt;cockpit-repos-4.6-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cockpit-repos-4.6-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10036-1</guid>
    </item>
    <item>
      <title>RHSA-2026:15979 — Red Hat Security Advisory: Red Hat Ceph Storage</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:15979</link>
      <description>&lt;p&gt;nodemailer: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate js-yaml: js-yaml prototype pollution in merge glob: glob: Command Injection Vulnerability via Malicious Filenames github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodemailer: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate js-yaml: js-yaml prototype pollution in merge glob: glob: Command Injection Vulnerability via Malicious Filenames github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:15979</guid>
    </item>
    <item>
      <title>SSA-485750 — SSA-485750: Multiple Vulnerabilities in SIDIS Prime Before V4.0.800</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-485750</link>
      <description>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-485750</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:20170-1 — Security update for cockpit-subscriptions</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:20170-1</link>
      <description>&lt;p&gt;Security update for cockpit-subscriptions&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for cockpit-subscriptions&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:20170-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-64718</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-64718</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-js-yaml, Ubuntu:20.04:LTS: node-js-yaml, Ubuntu:22.04:LTS: node-js-yaml, Ubuntu:24.04:LTS: node-js-yaml, Ubuntu:25.10: node-js-yaml, Ubuntu:26.04:LTS: node-js-yaml&lt;/p&gt;
&lt;p&gt;js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it&amp;#39;s possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-js-yaml, Ubuntu:20.04:LTS: node-js-yaml, Ubuntu:22.04:LTS: node-js-yaml, Ubuntu:24.04:LTS: node-js-yaml, Ubuntu:25.10: node-js-yaml, Ubuntu:26.04:LTS: node-js-yaml&lt;/p&gt;
&lt;p&gt;js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it&amp;#39;s possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-64718</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2853 — HCL Commerce: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2853</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL Commerce ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Daten zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL Commerce ausnutzen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, um Daten zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2853</guid>
    </item>
  </channel>
</rss>
