<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:18:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-380193</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-380193</link>
      <description>EUVD-2026-380193</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-380193</guid>
    </item>
    <item>
      <title>fkie_cve-2026-101909</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-101909</link>
      <description>&lt;p&gt;Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-101909</guid>
    </item>
    <item>
      <title>GHSA-x97p-jq2g-jp4f — Axios: Prototype Pollution Gadget in axios toFormData Options</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x97p-jq2g-jp4f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Axios form serialization reads `visitor`, `maxDepth`, `dots`, `indexes`, `metaTokens`, and `Blob` from an internal options object without own-property guards. When `Object.prototype` has been polluted elsewhere in the same process, those inherited values can change how axios serializes multipart and URL-encoded request bodies.&lt;/p&gt;
&lt;p&gt;Axios does not create the prototype pollution source. This is a read-side gadget: axios turns an existing same-process pollution condition into altered request serialization or request failures.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The impact depends on which property is polluted and which axios serialization path the application uses.&lt;/p&gt;
&lt;p&gt;Polluted `dots`, `indexes`, or `metaTokens` can change field names and cause the receiving service to parse different data than the caller intended. Polluted `maxDepth` can cause nested form submissions to throw `ERR_FORM_DATA_DEPTH_EXCEEDED`, producing request-level or service-level denial of service for affected workflows. Polluted `visitor` can execute as the serializer visitor if an attacker can place a function on `Object.prototype`, but that condition generally implies a stronger same-process code-execution or malicious-dependency primitive and should be described carefully.&lt;/p&gt;
&lt;p&gt;## Affected Functionality&lt;/p&gt;
&lt;p&gt;Affected:&lt;/p&gt;
&lt;p&gt;- `axios.toFormData()`.
- `transformRequest` paths that serialize plain objects to `multipart/form-data`.
- URL-encoded form serialization paths that rely on the same helper.
- `formSerializer` option defaults when t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Axios form serialization reads `visitor`, `maxDepth`, `dots`, `indexes`, `metaTokens`, and `Blob` from an internal options object without own-property guards. When `Object.prototype` has been polluted elsewhere in the same process, those inherited values can change how axios serializes multipart and URL-encoded request bodies.&lt;/p&gt;
&lt;p&gt;Axios does not create the prototype pollution source. This is a read-side gadget: axios turns an existing same-process pollution condition into altered request serialization or request failures.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The impact depends on which property is polluted and which axios serialization path the application uses.&lt;/p&gt;
&lt;p&gt;Polluted `dots`, `indexes`, or `metaTokens` can change field names and cause the receiving service to parse different data than the caller intended. Polluted `maxDepth` can cause nested form submissions to throw `ERR_FORM_DATA_DEPTH_EXCEEDED`, producing request-level or service-level denial of service for affected workflows. Polluted `visitor` can execute as the serializer visitor if an attacker can place a function on `Object.prototype`, but that condition generally implies a stronger same-process code-execution or malicious-dependency primitive and should be described carefully.&lt;/p&gt;
&lt;p&gt;## Affected Functionality&lt;/p&gt;
&lt;p&gt;Affected:&lt;/p&gt;
&lt;p&gt;- `axios.toFormData()`.
- `transformRequest` paths that serialize plain objects to `multipart/form-data`.
- URL-encoded form serialization paths that rely on the same helper.
- `formSerializer` option defaults when t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x97p-jq2g-jp4f</guid>
    </item>
    <item>
      <title>RHSA-2026:74869 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:74869</link>
      <description>&lt;p&gt;hono: hono/jsx: Cross-Site Scripting via Unescaped Strings axios: axios: Security control bypass via unapplied HTTP/2 proxy and DNS settings axios: Axios: Outbound HTTP header injection via prototype pollution in fetch adapter axios: Axios: Denial of Service via unhandled error in HTTP/2 session initialization axios: axios: Unintended HTTP method override via prototype pollution gadget axios: Axios: Denial of Service via malformed data URLs axios: Axios: HTTP header injection via inherited prototype properties axios: axios: Request socket hijacking via inherited createConnection property axios: axios: Denial of Service via crafted redirect hostname axios: Axios: Server-Side Request Forgery via bypassed redirect restrictions in fetch adapter axios: Axios: Outbound HTTP request manipulation via fetch adapter prototype pollution axios: axios: Denial of Service via prototype pollution gadget in form serialization&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hono: hono/jsx: Cross-Site Scripting via Unescaped Strings axios: axios: Security control bypass via unapplied HTTP/2 proxy and DNS settings axios: Axios: Outbound HTTP header injection via prototype pollution in fetch adapter axios: Axios: Denial of Service via unhandled error in HTTP/2 session initialization axios: axios: Unintended HTTP method override via prototype pollution gadget axios: Axios: Denial of Service via malformed data URLs axios: Axios: HTTP header injection via inherited prototype properties axios: axios: Request socket hijacking via inherited createConnection property axios: axios: Denial of Service via crafted redirect hostname axios: Axios: Server-Side Request Forgery via bypassed redirect restrictions in fetch adapter axios: Axios: Outbound HTTP request manipulation via fetch adapter prototype pollution axios: axios: Denial of Service via prototype pollution gadget in form serialization&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:74869</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-101909</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-101909</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-101909</guid>
    </item>
  </channel>
</rss>
