<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:53:26 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0479 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0479</link>
      <description>certfr-2026-avi-0479</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0479</guid>
    </item>
    <item>
      <title>EUVD-2026-261915</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261915</link>
      <description>EUVD-2026-261915</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261915</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66020</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66020</link>
      <description>&lt;p&gt;Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. A short, maliciously crafted string (e.g., &amp;lt;100 characters) can cause the regex engine to consume excessive CPU time (minutes), leading to a Denial of Service (DoS) for the application. This issue has been patched in version 1.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. A short, maliciously crafted string (e.g., &amp;lt;100 characters) can cause the regex engine to consume excessive CPU time (minutes), leading to a Denial of Service (DoS) for the application. This issue has been patched in version 1.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66020</guid>
    </item>
    <item>
      <title>GHSA-vqpr-j7v3-hqw9 — Valibot has a ReDoS vulnerability in `EMOJI_REGEX`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vqpr-j7v3-hqw9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: valibot&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `EMOJI_REGEX` used in the `emoji` action is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. A short, maliciously crafted string (e.g., &amp;lt;100 characters) can cause the regex engine to consume excessive CPU time (minutes), leading to a Denial of Service (DoS) for the application.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The ReDoS vulnerability stems from &amp;#34;catastrophic backtracking&amp;#34; in the `EMOJI_REGEX`. This is caused by ambiguity in the regex pattern due to overlapping character classes.&lt;/p&gt;
&lt;p&gt;Specifically, the class `\p{Emoji_Presentation}` overlaps with more specific classes used in the same alternation, such as `[\u{1F1E6}-\u{1F1FF}]` (regional indicator symbols used for flags) and `\p{Emoji_Modifier_Base}`.&lt;/p&gt;
&lt;p&gt;When the regex engine attempts to match a string that almost matches but ultimately fails (like the one in the PoC), this ambiguity forces it to explore an exponential number of possible paths. The matching time increases exponentially with the length of the crafted input, rather than linearly.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The following code demonstrates the vulnerability.&lt;/p&gt;
&lt;p&gt;```javascript
import * as v from &amp;#39;valibot&amp;#39;;&lt;/p&gt;
&lt;p&gt;const schema = v.object({
  x: v.pipe(v.string(), v.emoji()),
});&lt;/p&gt;
&lt;p&gt;const attackString = &amp;#39;\u{1F1E6}&amp;#39;.repeat(49) + &amp;#39;0&amp;#39;;&lt;/p&gt;
&lt;p&gt;console.log(`Input length: ${attackString.length}`);
console.log(&amp;#39;Starting parse... (This will take a long time)&amp;#39;);&lt;/p&gt;
&lt;p&gt;// On my machine, a length of 99 takes approximately 2 minutes.
console.time();
try {
  v.parse(schema, {x: attackString });
} catch (…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: valibot&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `EMOJI_REGEX` used in the `emoji` action is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. A short, maliciously crafted string (e.g., &amp;lt;100 characters) can cause the regex engine to consume excessive CPU time (minutes), leading to a Denial of Service (DoS) for the application.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The ReDoS vulnerability stems from &amp;#34;catastrophic backtracking&amp;#34; in the `EMOJI_REGEX`. This is caused by ambiguity in the regex pattern due to overlapping character classes.&lt;/p&gt;
&lt;p&gt;Specifically, the class `\p{Emoji_Presentation}` overlaps with more specific classes used in the same alternation, such as `[\u{1F1E6}-\u{1F1FF}]` (regional indicator symbols used for flags) and `\p{Emoji_Modifier_Base}`.&lt;/p&gt;
&lt;p&gt;When the regex engine attempts to match a string that almost matches but ultimately fails (like the one in the PoC), this ambiguity forces it to explore an exponential number of possible paths. The matching time increases exponentially with the length of the crafted input, rather than linearly.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The following code demonstrates the vulnerability.&lt;/p&gt;
&lt;p&gt;```javascript
import * as v from &amp;#39;valibot&amp;#39;;&lt;/p&gt;
&lt;p&gt;const schema = v.object({
  x: v.pipe(v.string(), v.emoji()),
});&lt;/p&gt;
&lt;p&gt;const attackString = &amp;#39;\u{1F1E6}&amp;#39;.repeat(49) + &amp;#39;0&amp;#39;;&lt;/p&gt;
&lt;p&gt;console.log(`Input length: ${attackString.length}`);
console.log(&amp;#39;Starting parse... (This will take a long time)&amp;#39;);&lt;/p&gt;
&lt;p&gt;// On my machine, a length of 99 takes approximately 2 minutes.
console.time();
try {
  v.parse(schema, {x: attackString });
} catch (…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vqpr-j7v3-hqw9</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1229 — Atlassian Bamboo, Bitbucket, Confluence, Jira: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1229</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1229</guid>
    </item>
  </channel>
</rss>
