<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:20:41 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0112 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0112</link>
      <description>certfr-2026-avi-0112</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0112</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-FE11294 — Security fix for CVE-2025-65945 applied in: jitsucom-jitsu 2.11.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fe11294</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jitsucom-jitsu&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the jitsucom-jitsu package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jitsucom-jitsu&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the jitsucom-jitsu package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fe11294</guid>
    </item>
    <item>
      <title>EUVD-2026-262671</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262671</link>
      <description>EUVD-2026-262671</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262671</guid>
    </item>
    <item>
      <title>fkie_cve-2025-65945</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-65945</link>
      <description>&lt;p&gt;auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they use the jws.createVerify() function for HMAC algorithms and use user-provided data from the JSON Web Signature protected header or payload in HMAC secret lookup routines, which can allow attackers to bypass signature verification. This issue has been patched in versions 3.2.3 and 4.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they use the jws.createVerify() function for HMAC algorithms and use user-provided data from the JSON Web Signature protected header or payload in HMAC secret lookup routines, which can allow attackers to bypass signature verification. This issue has been patched in versions 3.2.3 and 4.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-65945</guid>
    </item>
    <item>
      <title>GHSA-869p-cjfg-cm3x — auth0/node-jws Improperly Verifies HMAC Signature</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-869p-cjfg-cm3x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jws&lt;/p&gt;
&lt;p&gt;### Overview
An improper signature verification vulnerability exists when using auth0/node-jws with the HS256 algorithm under specific conditions.&lt;/p&gt;
&lt;p&gt;### Am I Affected?
You are affected by this vulnerability if you meet all of the following preconditions:&lt;/p&gt;
&lt;p&gt;1. Application uses the auth0/node-jws implementation of JSON Web Signatures, versions &amp;lt;=3.2.2 || 4.0.0
2. Application uses the jws.createVerify() function for HMAC algorithms
3. Application uses user-provided data from the JSON Web Signature Protected Header or Payload in the HMAC secret lookup routines&lt;/p&gt;
&lt;p&gt;You are NOT affected by this vulnerability if you meet any of the following preconditions:
1. Application uses the jws.verify() interface (note: `auth0/node-jsonwebtoken` users fall into this category and are therefore NOT affected by this vulnerability)
2. Application uses only asymmetric algorithms (e.g. RS256)
3. Application doesn’t use user-provided data from the JSON Web Signature Protected Header or Payload in the HMAC secret lookup routines&lt;/p&gt;
&lt;p&gt;### Fix
Upgrade auth0/node-jws version to version 3.2.3 or 4.0.1&lt;/p&gt;
&lt;p&gt;### Acknowledgement
Okta would like to thank Félix Charette for discovering this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jws&lt;/p&gt;
&lt;p&gt;### Overview
An improper signature verification vulnerability exists when using auth0/node-jws with the HS256 algorithm under specific conditions.&lt;/p&gt;
&lt;p&gt;### Am I Affected?
You are affected by this vulnerability if you meet all of the following preconditions:&lt;/p&gt;
&lt;p&gt;1. Application uses the auth0/node-jws implementation of JSON Web Signatures, versions &amp;lt;=3.2.2 || 4.0.0
2. Application uses the jws.createVerify() function for HMAC algorithms
3. Application uses user-provided data from the JSON Web Signature Protected Header or Payload in the HMAC secret lookup routines&lt;/p&gt;
&lt;p&gt;You are NOT affected by this vulnerability if you meet any of the following preconditions:
1. Application uses the jws.verify() interface (note: `auth0/node-jsonwebtoken` users fall into this category and are therefore NOT affected by this vulnerability)
2. Application uses only asymmetric algorithms (e.g. RS256)
3. Application doesn’t use user-provided data from the JSON Web Signature Protected Header or Payload in the HMAC secret lookup routines&lt;/p&gt;
&lt;p&gt;### Fix
Upgrade auth0/node-jws version to version 3.2.3 or 4.0.1&lt;/p&gt;
&lt;p&gt;### Acknowledgement
Okta would like to thank Félix Charette for discovering this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-869p-cjfg-cm3x</guid>
    </item>
    <item>
      <title>RHSA-2026:0261 — Red Hat Security Advisory: Red Hat Developer Hub 1.7.4 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:0261</link>
      <description>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications qs: qs: Denial of Service via improper input validation in array parsing glob: glob: Command Injection Vulnerability via Malicious Filenames node-jws: auth0/node-jws: Improper signature verification in HS256 algorithm node-forge: node-forge ASN.1 Unbounded Recursion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications qs: qs: Denial of Service via improper input validation in array parsing glob: glob: Command Injection Vulnerability via Malicious Filenames node-jws: auth0/node-jws: Improper signature verification in HS256 algorithm node-forge: node-forge ASN.1 Unbounded Recursion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:0261</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2909 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2909</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen, um Dateien zu manipulieren, um einen Denial of Service Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen, um Dateien zu manipulieren, um einen Denial of Service Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2909</guid>
    </item>
  </channel>
</rss>
