<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:33:25 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-07454</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-07454</link>
      <description>bdu:2025-07454</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-07454</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0724 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0724</link>
      <description>certfr-2025-avi-0724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0724</guid>
    </item>
    <item>
      <title>EUVD-2026-268151</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-268151</link>
      <description>EUVD-2026-268151</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-268151</guid>
    </item>
    <item>
      <title>fkie_cve-2025-6547</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-6547</link>
      <description>&lt;p&gt;Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: &amp;lt;=3.1.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: &amp;lt;=3.1.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-6547</guid>
    </item>
    <item>
      <title>GHSA-v62p-rq8g-8h59 — pbkdf2 silently disregards Uint8Array input, returning static keys</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v62p-rq8g-8h59</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: pbkdf2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;On historic but declared as supported Node.js versions (0.12-2.x), pbkdf2 silently disregards Uint8Array input&lt;/p&gt;
&lt;p&gt;This only affects Node.js &amp;lt;3.0.0, but `pbkdf2` claims to:
 * Support Node.js [&amp;gt;= 0.12](https://github.com/browserify/pbkdf2/blob/v3.1.2/package.json#L62) (and there seems to be ongoing effort in this repo to maintain that)
 * Support `Uint8Array` input (input is typechecked against Uint8Array, and the error message includes e.g. &amp;#34;Password must be a string, a Buffer, a typed array or a DataView&amp;#34;&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The error is in `toBuffer` method&lt;/p&gt;
&lt;p&gt;This vulnerability somehow even made it to tests: https://github.com/browserify/pbkdf2/commit/eb9f97a66ed83836bebc4ff563a1588248708501
There, `resultsOld` (where mismatch `results`) are just invalid output generated from empty password/salt instead of the supplied one&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;On Node.js/io.js &amp;lt; 3.0.0&lt;/p&gt;
&lt;p&gt;```console
&amp;gt; require(&amp;#39;pbkdf2&amp;#39;).pbkdf2Sync(new Uint8Array([1,2,3]), new Uint8Array([1,3,4]), 1024, 32, &amp;#39;sha256&amp;#39;)
&amp;lt;Buffer 21 53 cd 5b a5 f0 15 39 2f 68 e2 40 8b 21 ba ca 0e dc 7b 20 d5 45 a4 8a ea b5 95 9f f0 be bf 66&amp;gt;&lt;/p&gt;
&lt;p&gt;// But that&amp;#39;s just a hash of empty data with empty password:
&amp;gt; require(&amp;#39;pbkdf2&amp;#39;).pbkdf2Sync(&amp;#39;&amp;#39;, &amp;#39;&amp;#39;, 1024, 32, &amp;#39;sha256&amp;#39;)
&amp;lt;Buffer 21 53 cd 5b a5 f0 15 39 2f 68 e2 40 8b 21 ba ca 0e dc 7b 20 d5 45 a4 8a ea b5 95 9f f0 be bf 66&amp;gt;&lt;/p&gt;
&lt;p&gt;// Node.js crypto is fine even on that version:
&amp;gt; require(&amp;#39;crypto&amp;#39;).pbkdf2Sync(new Uint8Array([1,2,3]), new Uint8Array([1,3,4]), 1024, 32, &amp;#39;sha256&amp;#39;)
&amp;lt;Buffer 78 10 cc 84 b7 bb 85…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: pbkdf2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;On historic but declared as supported Node.js versions (0.12-2.x), pbkdf2 silently disregards Uint8Array input&lt;/p&gt;
&lt;p&gt;This only affects Node.js &amp;lt;3.0.0, but `pbkdf2` claims to:
 * Support Node.js [&amp;gt;= 0.12](https://github.com/browserify/pbkdf2/blob/v3.1.2/package.json#L62) (and there seems to be ongoing effort in this repo to maintain that)
 * Support `Uint8Array` input (input is typechecked against Uint8Array, and the error message includes e.g. &amp;#34;Password must be a string, a Buffer, a typed array or a DataView&amp;#34;&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The error is in `toBuffer` method&lt;/p&gt;
&lt;p&gt;This vulnerability somehow even made it to tests: https://github.com/browserify/pbkdf2/commit/eb9f97a66ed83836bebc4ff563a1588248708501
There, `resultsOld` (where mismatch `results`) are just invalid output generated from empty password/salt instead of the supplied one&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;On Node.js/io.js &amp;lt; 3.0.0&lt;/p&gt;
&lt;p&gt;```console
&amp;gt; require(&amp;#39;pbkdf2&amp;#39;).pbkdf2Sync(new Uint8Array([1,2,3]), new Uint8Array([1,3,4]), 1024, 32, &amp;#39;sha256&amp;#39;)
&amp;lt;Buffer 21 53 cd 5b a5 f0 15 39 2f 68 e2 40 8b 21 ba ca 0e dc 7b 20 d5 45 a4 8a ea b5 95 9f f0 be bf 66&amp;gt;&lt;/p&gt;
&lt;p&gt;// But that&amp;#39;s just a hash of empty data with empty password:
&amp;gt; require(&amp;#39;pbkdf2&amp;#39;).pbkdf2Sync(&amp;#39;&amp;#39;, &amp;#39;&amp;#39;, 1024, 32, &amp;#39;sha256&amp;#39;)
&amp;lt;Buffer 21 53 cd 5b a5 f0 15 39 2f 68 e2 40 8b 21 ba ca 0e dc 7b 20 d5 45 a4 8a ea b5 95 9f f0 be bf 66&amp;gt;&lt;/p&gt;
&lt;p&gt;// Node.js crypto is fine even on that version:
&amp;gt; require(&amp;#39;crypto&amp;#39;).pbkdf2Sync(new Uint8Array([1,2,3]), new Uint8Array([1,3,4]), 1024, 32, &amp;#39;sha256&amp;#39;)
&amp;lt;Buffer 78 10 cc 84 b7 bb 85…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v62p-rq8g-8h59</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11126-1 — velociraptor-0.7.0.4.git185.a5708584-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11126-1</link>
      <description>&lt;p&gt;velociraptor-0.7.0.4.git185.a5708584-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;velociraptor-0.7.0.4.git185.a5708584-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11126-1</guid>
    </item>
    <item>
      <title>RHSA-2025:10738 — Red Hat Security Advisory: Kiali 2.4.7 for Red Hat OpenShift Service Mesh 3.0</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:10738</link>
      <description>&lt;p&gt;pbkdf2: pbkdf2 silently returns predictable key material pbkdf2: pbkdf2 silently returns static keys&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pbkdf2: pbkdf2 silently returns predictable key material pbkdf2: pbkdf2 silently returns static keys&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:10738</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2025-6547</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6547</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-pbkdf2, Ubuntu:20.04:LTS: node-pbkdf2, Ubuntu:22.04:LTS: node-pbkdf2, Ubuntu:24.04:LTS: node-pbkdf2, Ubuntu:25.10: node-pbkdf2, Ubuntu:26.04:LTS: node-pbkdf2&lt;/p&gt;
&lt;p&gt;Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: &amp;lt;=3.1.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-pbkdf2, Ubuntu:20.04:LTS: node-pbkdf2, Ubuntu:22.04:LTS: node-pbkdf2, Ubuntu:24.04:LTS: node-pbkdf2, Ubuntu:25.10: node-pbkdf2, Ubuntu:26.04:LTS: node-pbkdf2&lt;/p&gt;
&lt;p&gt;Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: &amp;lt;=3.1.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6547</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1409 — IBM App Connect Enterprise: Mehrere Schwachstellen ermöglichen Manipulation von Daten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1409</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1409</guid>
    </item>
  </channel>
</rss>
