<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:28:54 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0724 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0724</link>
      <description>certfr-2025-avi-0724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0724</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-IW41585 — Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP)</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-iw41585</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-iw41585</guid>
    </item>
    <item>
      <title>EUVD-2026-257998</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-257998</link>
      <description>EUVD-2026-257998</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-257998</guid>
    </item>
    <item>
      <title>fkie_cve-2025-7783</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-7783</link>
      <description>&lt;p&gt;Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.&lt;/p&gt;
&lt;p&gt;This issue affects form-data: &amp;lt; 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.&lt;/p&gt;
&lt;p&gt;This issue affects form-data: &amp;lt; 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-7783</guid>
    </item>
    <item>
      <title>GHSA-fjxv-7rqg-78g4 — form-data uses unsafe random function in form-data for choosing boundary</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fjxv-7rqg-78g4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: form-data&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;form-data uses `Math.random()` to select a boundary value for multipart form-encoded data. This can lead to a security issue if an attacker:
1. can observe other values produced by Math.random in the target application, and
2. can control one field of a request made using form-data&lt;/p&gt;
&lt;p&gt;Because the values of Math.random() are pseudo-random and predictable (see: https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f), an attacker who can observe a few sequential values can determine the state of the PRNG and predict future values, includes those used to generate form-data&amp;#39;s boundary value. The allows the attacker to craft a value that contains a boundary value, allowing them to inject additional parameters into the request.&lt;/p&gt;
&lt;p&gt;This is largely the same vulnerability as was [recently found in `undici`](https://hackerone.com/reports/2913312) by [`parrot409`](https://hackerone.com/parrot409?type=user) -- I&amp;#39;m not affiliated with that researcher but want to give credit where credit is due! My PoC is largely based on their work.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The culprit is this line here: https://github.com/form-data/form-data/blob/426ba9ac440f95d1998dac9a5cd8d738043b048f/lib/form_data.js#L347&lt;/p&gt;
&lt;p&gt;An attacker who is able to predict the output of Math.random() can predict this boundary value, and craft a payload that contains the boundary value, followed by another, fully attacker-controlled field. This is roughly equivalent to any sort of improper escaping vulnerability…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: form-data&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;form-data uses `Math.random()` to select a boundary value for multipart form-encoded data. This can lead to a security issue if an attacker:
1. can observe other values produced by Math.random in the target application, and
2. can control one field of a request made using form-data&lt;/p&gt;
&lt;p&gt;Because the values of Math.random() are pseudo-random and predictable (see: https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f), an attacker who can observe a few sequential values can determine the state of the PRNG and predict future values, includes those used to generate form-data&amp;#39;s boundary value. The allows the attacker to craft a value that contains a boundary value, allowing them to inject additional parameters into the request.&lt;/p&gt;
&lt;p&gt;This is largely the same vulnerability as was [recently found in `undici`](https://hackerone.com/reports/2913312) by [`parrot409`](https://hackerone.com/parrot409?type=user) -- I&amp;#39;m not affiliated with that researcher but want to give credit where credit is due! My PoC is largely based on their work.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The culprit is this line here: https://github.com/form-data/form-data/blob/426ba9ac440f95d1998dac9a5cd8d738043b048f/lib/form_data.js#L347&lt;/p&gt;
&lt;p&gt;An attacker who is able to predict the output of Math.random() can predict this boundary value, and craft a payload that contains the boundary value, followed by another, fully attacker-controlled field. This is roughly equivalent to any sort of improper escaping vulnerability…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fjxv-7rqg-78g4</guid>
    </item>
    <item>
      <title>ICSA-26-071-03 — Siemens SIDIS Prime</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-071-03</link>
      <description>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-071-03</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-7783 — Usage of unsafe random function in form-data for choosing boundary</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-7783</link>
      <description>msrc_CVE-2025-7783</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-7783</guid>
    </item>
    <item>
      <title>NCSC-2026-0079 — Kwetsbaarheden verholpen in Siemens producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0079</link>
      <description>NCSC-2026-0079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0079</guid>
    </item>
    <item>
      <title>OESA-2025-2204 — nodejs-form-data security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2204</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: nodejs-form-data&lt;/p&gt;
&lt;p&gt;A module to create readable &amp;amp;amp;quot;multipart/form-data&amp;amp;amp;quot; streams.  Can be used to submit forms and file uploads to other web applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.&lt;/p&gt;
&lt;p&gt;This issue affects form-data: &amp;amp;lt; 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.(CVE-2025-7783)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: nodejs-form-data&lt;/p&gt;
&lt;p&gt;A module to create readable &amp;amp;amp;quot;multipart/form-data&amp;amp;amp;quot; streams.  Can be used to submit forms and file uploads to other web applications.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.&lt;/p&gt;
&lt;p&gt;This issue affects form-data: &amp;amp;lt; 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.(CVE-2025-7783)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2204</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15373-1 — jupyter-jupyterlab-templates-0.5.2-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15373-1</link>
      <description>&lt;p&gt;jupyter-jupyterlab-templates-0.5.2-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jupyter-jupyterlab-templates-0.5.2-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15373-1</guid>
    </item>
    <item>
      <title>RHSA-2025:14886 — Red Hat Security Advisory: Kiali 2.4.8 for Red Hat OpenShift Service Mesh 3.0</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:14886</link>
      <description>&lt;p&gt;form-data: Unsafe random function in form-data&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;form-data: Unsafe random function in form-data&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:14886</guid>
    </item>
    <item>
      <title>SSA-485750 — SSA-485750: Multiple Vulnerabilities in SIDIS Prime Before V4.0.800</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-485750</link>
      <description>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters. An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing. An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key. There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-485750</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:3919-1 — Security update for nodejs18</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:3919-1</link>
      <description>&lt;p&gt;Security update for nodejs18&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs18&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:3919-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-7783</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-7783</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-form-data, Ubuntu:Pro:16.04:LTS: node-form-data, Ubuntu:Pro:18.04:LTS: node-form-data, Ubuntu:Pro:20.04:LTS: node-form-data, Ubuntu:Pro:22.04:LTS: node-form-data, Ubuntu:24.04:LTS: node-form-data&lt;/p&gt;
&lt;p&gt;Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: &amp;lt; 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3. This issue affects form-data: &amp;lt; 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-form-data, Ubuntu:Pro:16.04:LTS: node-form-data, Ubuntu:Pro:18.04:LTS: node-form-data, Ubuntu:Pro:20.04:LTS: node-form-data, Ubuntu:Pro:22.04:LTS: node-form-data, Ubuntu:24.04:LTS: node-form-data&lt;/p&gt;
&lt;p&gt;Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: &amp;lt; 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3. This issue affects form-data: &amp;lt; 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-7783</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1854 — HCL BigFix Komponente: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1854</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix Komponente ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Daten zu manipulieren, um Informationen offenzulegen, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix Komponente ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Daten zu manipulieren, um Informationen offenzulegen, und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1854</guid>
    </item>
  </channel>
</rss>
