<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:41:22 +0000</lastBuildDate>
    <item>
      <title>BREW-webpack-CVE-2025-68458 — webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior</title>
      <link>https://cve.radiocsirt.org/vuln/brew-webpack-cve-2025-68458</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: webpack&lt;/p&gt;
&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies on a raw string prefix check (e.g., uri.startsWith(allowed)), a URL that looks allow-listed can pass validation while the actual network request is sent to a different authority/host after URL parsing. This is a policy/allow-list bypass that enables build-time SSRF behavior (outbound requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion (the fetched response is treated as module source and bundled). This issue has been patched in version 5.104.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: webpack&lt;/p&gt;
&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies on a raw string prefix check (e.g., uri.startsWith(allowed)), a URL that looks allow-listed can pass validation while the actual network request is sent to a different authority/host after URL parsing. This is a policy/allow-list bypass that enables build-time SSRF behavior (outbound requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion (the fetched response is treated as module source and bundled). This issue has been patched in version 5.104.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-webpack-cve-2025-68458</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0500 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</link>
      <description>certfr-2026-avi-0500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-DS59856 — Security fix for CVE-2025-68458 applied in: argo-workflows 3.6.19-r8, argo-workflows 3.7.15-r3, argo-workflows 3.7.17-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ds59856</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;CVE-2025-68458 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;CVE-2025-68458 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ds59856</guid>
    </item>
    <item>
      <title>EUVD-2026-267631</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267631</link>
      <description>EUVD-2026-267631</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267631</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68458</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68458</link>
      <description>&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies on a raw string prefix check (e.g., uri.startsWith(allowed)), a URL that looks allow-listed can pass validation while the actual network request is sent to a different authority/host after URL parsing. This is a policy/allow-list bypass that enables build-time SSRF behavior (outbound requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion (the fetched response is treated as module source and bundled). This issue has been patched in version 5.104.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies on a raw string prefix check (e.g., uri.startsWith(allowed)), a URL that looks allow-listed can pass validation while the actual network request is sent to a different authority/host after URL parsing. This is a policy/allow-list bypass that enables build-time SSRF behavior (outbound requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion (the fetched response is treated as module source and bundled). This issue has been patched in version 5.104.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68458</guid>
    </item>
    <item>
      <title>GHSA-8fgc-7cc6-rx7x — webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8fgc-7cc6-rx7x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: webpack&lt;/p&gt;
&lt;p&gt;### Summary
When `experiments.buildHttp` is enabled, webpack’s HTTP(S) resolver (`HttpUriPlugin`) can be bypassed to fetch resources from **hosts outside `allowedUris`** by using crafted URLs that include **userinfo** (`username:password@host`). If `allowedUris` enforcement relies on a **raw string prefix check** (e.g., `uri.startsWith(allowed)`), a URL that *looks* allow-listed can pass validation while the actual network request is sent to a different authority/host after URL parsing. This is a **policy/allow-list bypass** that enables **build-time SSRF behavior** (outbound requests from the build machine to internal-only endpoints, depending on network access) and **untrusted content inclusion** (the fetched response is treated as module source and bundled). In my reproduction, the internal response was also persisted in the buildHttp cache.&lt;/p&gt;
&lt;p&gt;Reproduced on:
- webpack version: **5.104.0**
- Node version: **v18.19.1**&lt;/p&gt;
&lt;p&gt;### Details
**Root cause (high level):** `allowedUris` validation can be performed on the raw URI string, while the actual request destination is determined later by parsing the URL (e.g., `new URL(uri)`), which interprets the **authority** as the part after `@`.&lt;/p&gt;
&lt;p&gt;Example crafted URL:
- `http://127.0.0.1:9000@127.0.0.1:9100/secret.js`&lt;/p&gt;
&lt;p&gt;If the allow-list is `[&amp;#34;http://127.0.0.1:9000&amp;#34;]`, then:
- Raw string check:  
  `crafted.startsWith(&amp;#34;http://127.0.0.1:9000&amp;#34;)` → **true**
- URL parsing (WHAT `new URL()` will contact):  
  `origin` → `http://127.0.0.1:9100` (hos…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: webpack&lt;/p&gt;
&lt;p&gt;### Summary
When `experiments.buildHttp` is enabled, webpack’s HTTP(S) resolver (`HttpUriPlugin`) can be bypassed to fetch resources from **hosts outside `allowedUris`** by using crafted URLs that include **userinfo** (`username:password@host`). If `allowedUris` enforcement relies on a **raw string prefix check** (e.g., `uri.startsWith(allowed)`), a URL that *looks* allow-listed can pass validation while the actual network request is sent to a different authority/host after URL parsing. This is a **policy/allow-list bypass** that enables **build-time SSRF behavior** (outbound requests from the build machine to internal-only endpoints, depending on network access) and **untrusted content inclusion** (the fetched response is treated as module source and bundled). In my reproduction, the internal response was also persisted in the buildHttp cache.&lt;/p&gt;
&lt;p&gt;Reproduced on:
- webpack version: **5.104.0**
- Node version: **v18.19.1**&lt;/p&gt;
&lt;p&gt;### Details
**Root cause (high level):** `allowedUris` validation can be performed on the raw URI string, while the actual request destination is determined later by parsing the URL (e.g., `new URL(uri)`), which interprets the **authority** as the part after `@`.&lt;/p&gt;
&lt;p&gt;Example crafted URL:
- `http://127.0.0.1:9000@127.0.0.1:9100/secret.js`&lt;/p&gt;
&lt;p&gt;If the allow-list is `[&amp;#34;http://127.0.0.1:9000&amp;#34;]`, then:
- Raw string check:  
  `crafted.startsWith(&amp;#34;http://127.0.0.1:9000&amp;#34;)` → **true**
- URL parsing (WHAT `new URL()` will contact):  
  `origin` → `http://127.0.0.1:9100` (hos…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8fgc-7cc6-rx7x</guid>
    </item>
    <item>
      <title>RHSA-2026:40984 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.20.15 security, enhancement &amp; bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:40984</link>
      <description>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-forge: node-forge ASN.1 Unbounded Recursion webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior ajv: ReDoS via $data reference lodash: lodash: Arbitrary code execution via untrusted input in template imports @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: g…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-forge: node-forge ASN.1 Unbounded Recursion webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior ajv: ReDoS via $data reference lodash: lodash: Arbitrary code execution via untrusted input in template imports @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: g…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:40984</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-68458</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68458</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-webpack, Ubuntu:20.04:LTS: node-webpack, Ubuntu:22.04:LTS: node-webpack, Ubuntu:24.04:LTS: node-webpack, Ubuntu:25.10: node-webpack, Ubuntu:26.04:LTS: node-webpack&lt;/p&gt;
&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies on a raw string prefix check (e.g., uri.startsWith(allowed)), a URL that looks allow-listed can pass validation while the actual network request is sent to a different authority/host after URL parsing. This is a policy/allow-list bypass that enables build-time SSRF behavior (outbound requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion (the fetched response is treated as module source and bundled). This issue has been patched in version 5.104.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-webpack, Ubuntu:20.04:LTS: node-webpack, Ubuntu:22.04:LTS: node-webpack, Ubuntu:24.04:LTS: node-webpack, Ubuntu:25.10: node-webpack, Ubuntu:26.04:LTS: node-webpack&lt;/p&gt;
&lt;p&gt;Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies on a raw string prefix check (e.g., uri.startsWith(allowed)), a URL that looks allow-listed can pass validation while the actual network request is sent to a different authority/host after URL parsing. This is a policy/allow-list bypass that enables build-time SSRF behavior (outbound requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion (the fetched response is treated as module source and bundled). This issue has been patched in version 5.104.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68458</guid>
    </item>
  </channel>
</rss>
