<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:30:05 +0000</lastBuildDate>
    <item>
      <title>BREW-webpack-CVE-2025-68157 — webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects</title>
      <link>https://cve.radiocsirt.org/vuln/brew-webpack-cve-2025-68157</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: webpack&lt;/p&gt;
&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to a trusted allow-list can be redirected to HTTP(S) URLs outside the allow-list. This is a policy/allow-list bypass that enables build-time SSRF behavior (requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion in build outputs (redirected content is treated as module source and bundled). This issue has been patched in version 5.104.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: webpack&lt;/p&gt;
&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to a trusted allow-list can be redirected to HTTP(S) URLs outside the allow-list. This is a policy/allow-list bypass that enables build-time SSRF behavior (requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion in build outputs (redirected content is treated as module source and bundled). This issue has been patched in version 5.104.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-webpack-cve-2025-68157</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0500 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</link>
      <description>certfr-2026-avi-0500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-EU00318 — Security fixes in argo-workflows 3.7.17-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-eu00318</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Package argo-workflows version 3.7.17-r1 fixes 16 vulnerabilities: ghsa-3ppc-4f35-3m26, ghsa-7r86-cg39-jmmj, ghsa-23c5-xmqv-rm74, ghsa-xv26-6w52-cph6, ghsa-q3j6-qgpj-74h6...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Package argo-workflows version 3.7.17-r1 fixes 16 vulnerabilities: ghsa-3ppc-4f35-3m26, ghsa-7r86-cg39-jmmj, ghsa-23c5-xmqv-rm74, ghsa-xv26-6w52-cph6, ghsa-q3j6-qgpj-74h6...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-eu00318</guid>
    </item>
    <item>
      <title>EUVD-2026-267611</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267611</link>
      <description>EUVD-2026-267611</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267611</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68157</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68157</link>
      <description>&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to a trusted allow-list can be redirected to HTTP(S) URLs outside the allow-list. This is a policy/allow-list bypass that enables build-time SSRF behavior (requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion in build outputs (redirected content is treated as module source and bundled). This issue has been patched in version 5.104.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to a trusted allow-list can be redirected to HTTP(S) URLs outside the allow-list. This is a policy/allow-list bypass that enables build-time SSRF behavior (requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion in build outputs (redirected content is treated as module source and bundled). This issue has been patched in version 5.104.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68157</guid>
    </item>
    <item>
      <title>GHSA-38r7-794h-5758 — webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-38r7-794h-5758</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: webpack&lt;/p&gt;
&lt;p&gt;### Summary
When `experiments.buildHttp` is enabled, webpack’s HTTP(S) resolver (`HttpUriPlugin`) enforces `allowedUris` only for the **initial** URL, but **does not re-validate `allowedUris` after following HTTP 30x redirects**. As a result, an import that appears restricted to a trusted allow-list can be redirected to **HTTP(S) URLs outside the allow-list**. This is a **policy/allow-list bypass** that enables **build-time SSRF behavior** (requests from the build machine to internal-only endpoints, depending on network access) and **untrusted content inclusion in build outputs** (redirected content is treated as module source and bundled). In my reproduction, the internal response is also persisted in the buildHttp cache.&lt;/p&gt;
&lt;p&gt;### Details
In the HTTP scheme resolver, the allow-list check (`allowedUris`) is performed when metadata/info is created for the original request (via `getInfo()`), but the content-fetch path follows redirects by resolving the `Location` URL without re-checking whether the redirected URL is within `allowedUris`.&lt;/p&gt;
&lt;p&gt;Practical consequence: if an “allowed” host/path can return a 302 (or has an open redirect), it can point to an external URL or an internal-only URL (SSRF). The redirected response is consumed as module content, bundled, and can be cached. If the redirect target is attacker-controlled, this can potentially result in attacker-controlled JavaScript being bundled and later executed when the resulting bundle runs.&lt;/p&gt;
&lt;p&gt;**Figure 1 (evidence screenshot):**…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: webpack&lt;/p&gt;
&lt;p&gt;### Summary
When `experiments.buildHttp` is enabled, webpack’s HTTP(S) resolver (`HttpUriPlugin`) enforces `allowedUris` only for the **initial** URL, but **does not re-validate `allowedUris` after following HTTP 30x redirects**. As a result, an import that appears restricted to a trusted allow-list can be redirected to **HTTP(S) URLs outside the allow-list**. This is a **policy/allow-list bypass** that enables **build-time SSRF behavior** (requests from the build machine to internal-only endpoints, depending on network access) and **untrusted content inclusion in build outputs** (redirected content is treated as module source and bundled). In my reproduction, the internal response is also persisted in the buildHttp cache.&lt;/p&gt;
&lt;p&gt;### Details
In the HTTP scheme resolver, the allow-list check (`allowedUris`) is performed when metadata/info is created for the original request (via `getInfo()`), but the content-fetch path follows redirects by resolving the `Location` URL without re-checking whether the redirected URL is within `allowedUris`.&lt;/p&gt;
&lt;p&gt;Practical consequence: if an “allowed” host/path can return a 302 (or has an open redirect), it can point to an external URL or an internal-only URL (SSRF). The redirected response is consumed as module content, bundled, and can be cached. If the redirect target is attacker-controlled, this can potentially result in attacker-controlled JavaScript being bundled and later executed when the resulting bundle runs.&lt;/p&gt;
&lt;p&gt;**Figure 1 (evidence screenshot):**…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-38r7-794h-5758</guid>
    </item>
    <item>
      <title>RHSA-2026:40984 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.20.15 security, enhancement &amp; bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:40984</link>
      <description>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-forge: node-forge ASN.1 Unbounded Recursion webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior ajv: ReDoS via $data reference lodash: lodash: Arbitrary code execution via untrusted input in template imports @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: g…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-forge: node-forge ASN.1 Unbounded Recursion webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior ajv: ReDoS via $data reference lodash: lodash: Arbitrary code execution via untrusted input in template imports @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: g…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:40984</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-68157</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68157</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-webpack, Ubuntu:20.04:LTS: node-webpack, Ubuntu:22.04:LTS: node-webpack, Ubuntu:24.04:LTS: node-webpack, Ubuntu:25.10: node-webpack, Ubuntu:26.04:LTS: node-webpack&lt;/p&gt;
&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to a trusted allow-list can be redirected to HTTP(S) URLs outside the allow-list. This is a policy/allow-list bypass that enables build-time SSRF behavior (requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion in build outputs (redirected content is treated as module source and bundled). This issue has been patched in version 5.104.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-webpack, Ubuntu:20.04:LTS: node-webpack, Ubuntu:22.04:LTS: node-webpack, Ubuntu:24.04:LTS: node-webpack, Ubuntu:25.10: node-webpack, Ubuntu:26.04:LTS: node-webpack&lt;/p&gt;
&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to a trusted allow-list can be redirected to HTTP(S) URLs outside the allow-list. This is a policy/allow-list bypass that enables build-time SSRF behavior (requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion in build outputs (redirected content is treated as module source and bundled). This issue has been patched in version 5.104.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68157</guid>
    </item>
  </channel>
</rss>
