<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:18:57 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1233 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</link>
      <description>certfr-2026-avi-1233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BG21634 — Security fixes in langfuse-worker 3.216.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bg21634</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 3.216.0-r1 fixes 29 vulnerabilities: ghsa-frvp-7c67-39w9, ghsa-p63j-vcc4-9vmv, ghsa-55q2-fjhq-7xh7, ghsa-c2j3-45gr-mqc4, CVE-2026-69192...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 3.216.0-r1 fixes 29 vulnerabilities: ghsa-frvp-7c67-39w9, ghsa-p63j-vcc4-9vmv, ghsa-55q2-fjhq-7xh7, ghsa-c2j3-45gr-mqc4, CVE-2026-69192...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bg21634</guid>
    </item>
    <item>
      <title>EUVD-2026-342443</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342443</link>
      <description>EUVD-2026-342443</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342443</guid>
    </item>
    <item>
      <title>fkie_cve-2026-13697</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-13697</link>
      <description>&lt;p&gt;undici&amp;#39;s cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the same cache key, disclosing private response bodies and headers including Set-Cookie. Separately, a Cache-Control header that combines an unqualified private directive with a qualified one triggers an uncaught TypeError in the cache-control parser, which rejects the request and, depending on the consumer&amp;#39;s error handling, can terminate the process. Both issues affect applications using the cache interceptor in shared mode, including the default configuration. The issues are fixed in undici 7.29.0 and 8.9.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici&amp;#39;s cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the same cache key, disclosing private response bodies and headers including Set-Cookie. Separately, a Cache-Control header that combines an unqualified private directive with a qualified one triggers an uncaught TypeError in the cache-control parser, which rejects the request and, depending on the consumer&amp;#39;s error handling, can terminate the process. Both issues affect applications using the cache interceptor in shared mode, including the default configuration. The issues are fixed in undici 7.29.0 and 8.9.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-13697</guid>
    </item>
    <item>
      <title>GHSA-4cwx-7wf7-3272 — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4cwx-7wf7-3272</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Two issues in undici&amp;#39;s cache interceptor, both fixed by the same patch on `lib/util/cache.js`:&lt;/p&gt;
&lt;p&gt;1. **Shared-cache disclosure:** Responses with malformed qualified `Cache-Control: private` directives such as `private=&amp;#34;&amp;#34;` or `private=&amp;#34;,&amp;#34;` can be incorrectly stored in the default shared cache, then served to a later caller with the same cache key.
2. **Parse-time crash:** Mixed unqualified-and-qualified `private` directives in the same header (such as `public, max-age=60, private, private=&amp;#34;hdr&amp;#34;`) cause an uncaught `TypeError` in the cache-control parser, terminating the request.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;#### Shared-cache disclosure&lt;/p&gt;
&lt;p&gt;Applications using `interceptors.cache()` in shared mode may cache a user-specific response and serve it to a later caller with the same cache key. This can disclose private response bodies and headers, including `Set-Cookie`.&lt;/p&gt;
&lt;p&gt;Required conditions:&lt;/p&gt;
&lt;p&gt;- the cache interceptor is enabled in shared mode, including the default configuration;
- an upstream returns a malformed directive such as `Cache-Control: public, max-age=300, private=&amp;#34;&amp;#34;`;
- another request later matches the same cache key, without a separating `Vary` header.&lt;/p&gt;
&lt;p&gt;#### Parse-time crash&lt;/p&gt;
&lt;p&gt;Applications using `interceptors.cache()` against an upstream that returns a `Cache-Control` header combining unqualified `private` with qualified `private=&amp;#34;...&amp;#34;` see an uncaught `TypeError: output.private.concat is not a function` during response handling. The request rejects; depending on the consumer&amp;#39;s e…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Two issues in undici&amp;#39;s cache interceptor, both fixed by the same patch on `lib/util/cache.js`:&lt;/p&gt;
&lt;p&gt;1. **Shared-cache disclosure:** Responses with malformed qualified `Cache-Control: private` directives such as `private=&amp;#34;&amp;#34;` or `private=&amp;#34;,&amp;#34;` can be incorrectly stored in the default shared cache, then served to a later caller with the same cache key.
2. **Parse-time crash:** Mixed unqualified-and-qualified `private` directives in the same header (such as `public, max-age=60, private, private=&amp;#34;hdr&amp;#34;`) cause an uncaught `TypeError` in the cache-control parser, terminating the request.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;#### Shared-cache disclosure&lt;/p&gt;
&lt;p&gt;Applications using `interceptors.cache()` in shared mode may cache a user-specific response and serve it to a later caller with the same cache key. This can disclose private response bodies and headers, including `Set-Cookie`.&lt;/p&gt;
&lt;p&gt;Required conditions:&lt;/p&gt;
&lt;p&gt;- the cache interceptor is enabled in shared mode, including the default configuration;
- an upstream returns a malformed directive such as `Cache-Control: public, max-age=300, private=&amp;#34;&amp;#34;`;
- another request later matches the same cache key, without a separating `Vary` header.&lt;/p&gt;
&lt;p&gt;#### Parse-time crash&lt;/p&gt;
&lt;p&gt;Applications using `interceptors.cache()` against an upstream that returns a `Cache-Control` header combining unqualified `private` with qualified `private=&amp;#34;...&amp;#34;` see an uncaught `TypeError: output.private.concat is not a function` during response handling. The request rejects; depending on the consumer&amp;#39;s e…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4cwx-7wf7-3272</guid>
    </item>
    <item>
      <title>RHSA-2026:48273 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:48273</link>
      <description>&lt;p&gt;undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing undici: undici: HTTP header injection via unvalidated blob-like body type property undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length undici: Undici: Cookie attribute injection allows bypassing security protections nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw nodejs: Information disclosure due to improper permission enforcement nodejs: HTTPS Agent TLS session reuse skips hostname verification nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing undici: undici: HTTP header injection via unvalidated blob-like body type property undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length undici: Undici: Cookie attribute injection allows bypassing security protections nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw nodejs: Information disclosure due to improper permission enforcement nodejs: HTTPS Agent TLS session reuse skips hostname verification nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:48273</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-13697</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-13697</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;undici&amp;#39;s cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the same cache key, disclosing private response bodies and headers including Set-Cookie. Separately, a Cache-Control header that combines an unqualified private directive with a qualified one triggers an uncaught TypeError in the cache-control parser, which rejects the request and, depending on the consumer&amp;#39;s error handling, can terminate the process. Both issues affect applications using the cache interceptor in shared mode, including the default configuration. The issues are fixed in undici 7.29.0 and 8.9.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;undici&amp;#39;s cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the same cache key, disclosing private response bodies and headers including Set-Cookie. Separately, a Cache-Control header that combines an unqualified private directive with a qualified one triggers an uncaught TypeError in the cache-control parser, which rejects the request and, depending on the consumer&amp;#39;s error handling, can terminate the process. Both issues affect applications using the cache interceptor in shared mode, including the default configuration. The issues are fixed in undici 7.29.0 and 8.9.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-13697</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3621 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3621</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Daten zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Daten zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3621</guid>
    </item>
  </channel>
</rss>
