<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:23:18 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0901 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</link>
      <description>certfr-2026-avi-0901</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-ED19767 — Security fixes in opensearch-dashboards-fips 3.6.0-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ed19767</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Package opensearch-dashboards-fips version 3.6.0-r4 fixes 7 vulnerabilities: ghsa-cmwh-pvxp-8882, CVE-2026-12143, CVE-2026-46625, CVE-2026-53550, CVE-2026-53655...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Package opensearch-dashboards-fips version 3.6.0-r4 fixes 7 vulnerabilities: ghsa-cmwh-pvxp-8882, CVE-2026-12143, CVE-2026-46625, CVE-2026-53550, CVE-2026-53655...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ed19767</guid>
    </item>
    <item>
      <title>EUVD-2026-366753</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366753</link>
      <description>EUVD-2026-366753</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366753</guid>
    </item>
    <item>
      <title>fkie_cve-2026-12143</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-12143</link>
      <description>&lt;p&gt;form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (&amp;#34;) characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `&amp;#34;` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (&amp;#34;) characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `&amp;#34;` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-12143</guid>
    </item>
    <item>
      <title>GHSA-hmw2-7cc7-3qxx — form-data: CRLF injection in form-data via unescaped multipart field names and filenames</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hmw2-7cc7-3qxx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: form-data&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`form-data` builds `multipart/form-data` request bodies. Through v4.0.5, the `field` name passed to `FormData#append` and the `filename` option are concatenated directly into the `Content-Disposition` header with no escaping of CR (`\r`), LF (`\n`), or `&amp;#34;`. An application that uses **untrusted input as a field name or filename** therefore lets an attacker terminate the header line and either inject additional headers or smuggle whole additional multipart parts into the request the application forwards to a backend.&lt;/p&gt;
&lt;p&gt;This is CWE-93 (CRLF injection). It is a divergence from how browsers and the WHATWG HTML spec serialize form-data (they escape these characters), so the fix is to match that behavior. Severity is **conditional**: it depends on the consuming application passing attacker-controlled data as a field name or filename. Applications that only use fixed/trusted field names are not affected.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;In `lib/form_data.js`, `_multiPartHeader` builds the part header as:&lt;/p&gt;
&lt;p&gt;```javascript
&amp;#39;Content-Disposition&amp;#39;: [&amp;#39;form-data&amp;#39;, &amp;#39;name=&amp;#34;&amp;#39; + field + &amp;#39;&amp;#34;&amp;#39;].concat(contentDisposition || [])
```&lt;/p&gt;
&lt;p&gt;and `_getContentDisposition` builds `filename=&amp;#34;&amp;#39; + filename + &amp;#39;&amp;#34;&amp;#39;`. Neither escapes control characters, so a `\r\n` in `field`/`filename` ends the header line. The same applies to `&amp;#34;`, which can break out of the quoted parameter.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```javascript
const FormData = require(&amp;#39;form-data&amp;#39;);
const form = new FormData();
form.append(&amp;#39;email&amp;#34;\r\nX-Injected: true\r\nfake…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: form-data&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`form-data` builds `multipart/form-data` request bodies. Through v4.0.5, the `field` name passed to `FormData#append` and the `filename` option are concatenated directly into the `Content-Disposition` header with no escaping of CR (`\r`), LF (`\n`), or `&amp;#34;`. An application that uses **untrusted input as a field name or filename** therefore lets an attacker terminate the header line and either inject additional headers or smuggle whole additional multipart parts into the request the application forwards to a backend.&lt;/p&gt;
&lt;p&gt;This is CWE-93 (CRLF injection). It is a divergence from how browsers and the WHATWG HTML spec serialize form-data (they escape these characters), so the fix is to match that behavior. Severity is **conditional**: it depends on the consuming application passing attacker-controlled data as a field name or filename. Applications that only use fixed/trusted field names are not affected.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;In `lib/form_data.js`, `_multiPartHeader` builds the part header as:&lt;/p&gt;
&lt;p&gt;```javascript
&amp;#39;Content-Disposition&amp;#39;: [&amp;#39;form-data&amp;#39;, &amp;#39;name=&amp;#34;&amp;#39; + field + &amp;#39;&amp;#34;&amp;#39;].concat(contentDisposition || [])
```&lt;/p&gt;
&lt;p&gt;and `_getContentDisposition` builds `filename=&amp;#34;&amp;#39; + filename + &amp;#39;&amp;#34;&amp;#39;`. Neither escapes control characters, so a `\r\n` in `field`/`filename` ends the header line. The same applies to `&amp;#34;`, which can break out of the quoted parameter.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```javascript
const FormData = require(&amp;#39;form-data&amp;#39;);
const form = new FormData();
form.append(&amp;#39;email&amp;#34;\r\nX-Injected: true\r\nfake…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hmw2-7cc7-3qxx</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-12143 — form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-12143</link>
      <description>msrc_CVE-2026-12143</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-12143</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21448-1 — Security update for agama-web-ui</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21448-1</link>
      <description>&lt;p&gt;Security update for agama-web-ui&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for agama-web-ui&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21448-1</guid>
    </item>
    <item>
      <title>RHSA-2026:33155 — Red Hat Security Advisory: Kiali 1.73.33 for Red Hat OpenShift Service Mesh 2.6</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:33155</link>
      <description>&lt;p&gt;form-data: form-data: Form field override via CRLF injection golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution axios: Axios: Information disclosure due to prototype pollution vulnerability axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;form-data: form-data: Form field override via CRLF injection golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution axios: Axios: Information disclosure due to prototype pollution vulnerability axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:33155</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-12143</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12143</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-form-data, Ubuntu:Pro:16.04:LTS: node-form-data, Ubuntu:Pro:18.04:LTS: node-form-data, Ubuntu:Pro:20.04:LTS: node-form-data, Ubuntu:Pro:22.04:LTS: node-form-data, Ubuntu:24.04:LTS: node-form-data, Ubuntu:25.10: node-form-data, Ubuntu:26.04:LTS: node-form-data&lt;/p&gt;
&lt;p&gt;form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (&amp;#34;) characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `&amp;#34;` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-form-data, Ubuntu:Pro:16.04:LTS: node-form-data, Ubuntu:Pro:18.04:LTS: node-form-data, Ubuntu:Pro:20.04:LTS: node-form-data, Ubuntu:Pro:22.04:LTS: node-form-data, Ubuntu:24.04:LTS: node-form-data, Ubuntu:25.10: node-form-data, Ubuntu:26.04:LTS: node-form-data&lt;/p&gt;
&lt;p&gt;form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (&amp;#34;) characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `&amp;#34;` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12143</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2460 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2460</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2460</guid>
    </item>
  </channel>
</rss>
