<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:43:58 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:47057 — Important: nodejs:24 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:47057</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: nodejs, AlmaLinux:9: nodejs-devel, AlmaLinux:9: nodejs-docs, AlmaLinux:9: nodejs-full-i18n, AlmaLinux:9: nodejs-libs, AlmaLinux:9: nodejs-nodemon, AlmaLinux:9: nodejs-packaging, AlmaLinux:9: nodejs-packaging-bundler, AlmaLinux:9: npm, AlmaLinux:9: v8-13.6-devel&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
  * tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
  * tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: nodejs, AlmaLinux:9: nodejs-devel, AlmaLinux:9: nodejs-docs, AlmaLinux:9: nodejs-full-i18n, AlmaLinux:9: nodejs-libs, AlmaLinux:9: nodejs-nodemon, AlmaLinux:9: nodejs-packaging, AlmaLinux:9: nodejs-packaging-bundler, AlmaLinux:9: npm, AlmaLinux:9: v8-13.6-devel&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
  * tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
  * tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:47057</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</link>
      <description>certfr-2026-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CB11602 — Security fixes in npm 11.18.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cb11602</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: npm&lt;/p&gt;
&lt;p&gt;Package npm version 11.18.0-r0 fixes 1 vulnerabilities: CVE-2026-13149&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: npm&lt;/p&gt;
&lt;p&gt;Package npm version 11.18.0-r0 fixes 1 vulnerabilities: CVE-2026-13149&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cb11602</guid>
    </item>
    <item>
      <title>EUVD-2026-333805</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333805</link>
      <description>EUVD-2026-333805</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333805</guid>
    </item>
    <item>
      <title>fkie_cve-2026-13149</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-13149</link>
      <description>&lt;p&gt;brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding &amp;#39;{}&amp;#39; brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding &amp;#39;{}&amp;#39; brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-13149</guid>
    </item>
    <item>
      <title>GHSA-3jxr-9vmj-r5cp — brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3jxr-9vmj-r5cp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: brace-expansion&lt;/p&gt;
&lt;p&gt;### Summary
brace-expansion&amp;#39;s expand() exhibits exponential-time - O(2ⁿ) - behavior in the number of consecutive non-expanding {} groups. A short, all-ASCII input (~90 bytes/30 groups) blocks the calling thread for minutes; a slightly longer input hangs it effectively indefinitely. Because the dominant consumers run on Node&amp;#39;s single-threaded event loop, one small input can fully stall a worker/process.&lt;/p&gt;
&lt;p&gt;In `expand_`, `post` is computed unconditionally at the top of the function, before the early-return branches that don&amp;#39;t use it:
```js
const post = m.post.length ? expand_(m.post, max, false) : [&amp;#39;&amp;#39;];   // always recurses
  ...
if (!isSequence &amp;amp;&amp;amp; !isOptions) {
  if (m.post.match(/,(?!,).*\}/)) {
    str = m.pre + &amp;#39;{&amp;#39; + m.body + escClose + m.post;
    return expand_(str, max, true); // restart — `post` discarded
  }
  return [str];
}
```&lt;/p&gt;
&lt;p&gt;For input like a{},{},…, the first {} is non-expanding, so control reaches the {a},b} rewrite branch - but `expand_` has already recursed into post over the entire remaining tail, only to throw the result away.
Each level therefore spawns two recursive expansions over essentially the same remaining work: `T(n) = 2·T(n−1) ⇒ O(2ⁿ)`.&lt;/p&gt;
&lt;p&gt;The max option does not mitigate this: max only bounds the output-building loops; neither the post recursion nor the rewrite recursion consults it.
  
Measured on 5.0.6:&lt;/p&gt;
&lt;p&gt;| groups (n) | input bytes | time |
|---|---|---|
| 20 | 60 | 130 ms |
| 24 | 72 | 1.9 s |
| 26 | 78 | 7.8 s |
| 30 (PoC) | 90 | ~2 min |&lt;/p&gt;
&lt;p&gt;### Pro…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: brace-expansion&lt;/p&gt;
&lt;p&gt;### Summary
brace-expansion&amp;#39;s expand() exhibits exponential-time - O(2ⁿ) - behavior in the number of consecutive non-expanding {} groups. A short, all-ASCII input (~90 bytes/30 groups) blocks the calling thread for minutes; a slightly longer input hangs it effectively indefinitely. Because the dominant consumers run on Node&amp;#39;s single-threaded event loop, one small input can fully stall a worker/process.&lt;/p&gt;
&lt;p&gt;In `expand_`, `post` is computed unconditionally at the top of the function, before the early-return branches that don&amp;#39;t use it:
```js
const post = m.post.length ? expand_(m.post, max, false) : [&amp;#39;&amp;#39;];   // always recurses
  ...
if (!isSequence &amp;amp;&amp;amp; !isOptions) {
  if (m.post.match(/,(?!,).*\}/)) {
    str = m.pre + &amp;#39;{&amp;#39; + m.body + escClose + m.post;
    return expand_(str, max, true); // restart — `post` discarded
  }
  return [str];
}
```&lt;/p&gt;
&lt;p&gt;For input like a{},{},…, the first {} is non-expanding, so control reaches the {a},b} rewrite branch - but `expand_` has already recursed into post over the entire remaining tail, only to throw the result away.
Each level therefore spawns two recursive expansions over essentially the same remaining work: `T(n) = 2·T(n−1) ⇒ O(2ⁿ)`.&lt;/p&gt;
&lt;p&gt;The max option does not mitigate this: max only bounds the output-building loops; neither the post recursion nor the rewrite recursion consults it.
  
Measured on 5.0.6:&lt;/p&gt;
&lt;p&gt;| groups (n) | input bytes | time |
|---|---|---|
| 20 | 60 | 130 ms |
| 24 | 72 | 1.9 s |
| 26 | 78 | 7.8 s |
| 30 (PoC) | 90 | ~2 min |&lt;/p&gt;
&lt;p&gt;### Pro…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3jxr-9vmj-r5cp</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11220-1 — python313-pytest-html-4.2.0-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11220-1</link>
      <description>&lt;p&gt;python313-pytest-html-4.2.0-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-pytest-html-4.2.0-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11220-1</guid>
    </item>
    <item>
      <title>RHSA-2026:33866 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:33866</link>
      <description>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling nodejs: Node.js: Certification validation bypass in TLS host verification nodejs: Node.js: Unauthorized file metadata modification nodejs: Node.js: Local server can be started without network permission via Permission API flaw js-yaml: js-yaml: Denial of Service via crafted YAML merge keys js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling nodejs: Node.js: Certification validation bypass in TLS host verification nodejs: Node.js: Unauthorized file metadata modification nodejs: Node.js: Local server can be started without network permission via Permission API flaw js-yaml: js-yaml: Denial of Service via crafted YAML merge keys js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:33866</guid>
    </item>
    <item>
      <title>RLSA-2026:47057 — Important: nodejs:24 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:47057</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: nodejs, Rocky Linux:9: nodejs-nodemon, Rocky Linux:9: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)&lt;/p&gt;
&lt;p&gt;* tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)&lt;/p&gt;
&lt;p&gt;* tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: nodejs, Rocky Linux:9: nodejs-nodemon, Rocky Linux:9: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)&lt;/p&gt;
&lt;p&gt;* tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)&lt;/p&gt;
&lt;p&gt;* tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:47057</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:3713-1 — Security update for Multi-Linux Manager Client Tools - Monitoring stack</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:3713-1</link>
      <description>&lt;p&gt;Security update for Multi-Linux Manager Client Tools - Monitoring stack&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for Multi-Linux Manager Client Tools - Monitoring stack&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:3713-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-13149</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-13149</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:25.10: node-brace-expansion, Ubuntu:26.04:LTS: node-brace-expansion&lt;/p&gt;
&lt;p&gt;brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding &amp;#39;{}&amp;#39; brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:25.10: node-brace-expansion, Ubuntu:26.04:LTS: node-brace-expansion&lt;/p&gt;
&lt;p&gt;brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding &amp;#39;{}&amp;#39; brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-13149</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2452 — Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, DOMPurify): Mehrere S…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</guid>
    </item>
  </channel>
</rss>
