<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 03:01:28 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:54371 — Important: nodejs:24 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:54371</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-libs, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: nodejs-packaging-bundler, AlmaLinux:8: npm, AlmaLinux:8: v8-13.6-devel&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data (CVE-2026-11822)
  * sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 (CVE-2026-11824)
  * brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
  * ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification (CVE-2026-54272)
  * brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)
  * ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-libs, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: nodejs-packaging-bundler, AlmaLinux:8: npm, AlmaLinux:8: v8-13.6-devel&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data (CVE-2026-11822)
  * sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 (CVE-2026-11824)
  * brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
  * ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification (CVE-2026-54272)
  * brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)
  * ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:54371</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BH94852 — Security fixes in langfuse-worker 3.224.1-r2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bh94852</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 3.224.1-r2 fixes 4 vulnerabilities: CVE-2026-14257, CVE-2026-69152, ghsa-r28c-9q8g-f849, CVE-2026-69153&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 3.224.1-r2 fixes 4 vulnerabilities: CVE-2026-14257, CVE-2026-69152, ghsa-r28c-9q8g-f849, CVE-2026-69153&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bh94852</guid>
    </item>
    <item>
      <title>EUVD-2026-339982</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339982</link>
      <description>EUVD-2026-339982</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339982</guid>
    </item>
    <item>
      <title>fkie_cve-2026-14257</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-14257</link>
      <description>&lt;p&gt;brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input (&amp;#39;{a,b}&amp;#39;.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input (&amp;#39;{a,b}&amp;#39;.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-14257</guid>
    </item>
    <item>
      <title>GHSA-mh99-v99m-4gvg — brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mh99-v99m-4gvg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: brace-expansion&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`expand()` bounds the *number* of results it produces (the `max` option,
`100_000` by default) but not their *length*. By chaining many brace groups,
an attacker keeps the result count under `max` while making every result grow
with the number of groups. Building `max` long results — plus the intermediate
arrays combined at each brace group — exhausts memory and crashes the Node
process with an **uncatchable** out-of-memory error. `try/catch` around
`expand()` does not help: the fatal error terminates the process.&lt;/p&gt;
&lt;p&gt;A ~7.5 KB input (`&amp;#39;{a,b}&amp;#39;.repeat(1500)`) is enough to crash a default Node
process.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;For `N` chained brace groups such as `&amp;#39;{a,b}&amp;#39;.repeat(N)`:&lt;/p&gt;
&lt;p&gt;- the result count is `2^N`, immediately capped at `max` (`100_000`), so the
  `max` protection appears to hold, but
- each result is `N` characters long, so the total output size is
  `max × N` characters, which grows without bound in `N`.&lt;/p&gt;
&lt;p&gt;`expand_` combines each brace set with the fully-expanded tail:&lt;/p&gt;
&lt;p&gt;```js
const post = m.post.length ? expand_(m.post, max, false) : [&amp;#39;&amp;#39;]
...
for (let j = 0; j &amp;lt; N.length; j++) {
  for (let k = 0; k &amp;lt; post.length &amp;amp;&amp;amp; expansions.length &amp;lt; max; k++) {
    const expansion = pre + N[j] + post[k]   // grows one group longer per level
    ...
    expansions.push(expansion)
  }
}
```&lt;/p&gt;
&lt;p&gt;The loop guard `expansions.length &amp;lt; max` limits how many strings are built, but
nothing limits how long they get. Each recursion level materializes another
array of up to `max` strings, one…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: brace-expansion&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`expand()` bounds the *number* of results it produces (the `max` option,
`100_000` by default) but not their *length*. By chaining many brace groups,
an attacker keeps the result count under `max` while making every result grow
with the number of groups. Building `max` long results — plus the intermediate
arrays combined at each brace group — exhausts memory and crashes the Node
process with an **uncatchable** out-of-memory error. `try/catch` around
`expand()` does not help: the fatal error terminates the process.&lt;/p&gt;
&lt;p&gt;A ~7.5 KB input (`&amp;#39;{a,b}&amp;#39;.repeat(1500)`) is enough to crash a default Node
process.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;For `N` chained brace groups such as `&amp;#39;{a,b}&amp;#39;.repeat(N)`:&lt;/p&gt;
&lt;p&gt;- the result count is `2^N`, immediately capped at `max` (`100_000`), so the
  `max` protection appears to hold, but
- each result is `N` characters long, so the total output size is
  `max × N` characters, which grows without bound in `N`.&lt;/p&gt;
&lt;p&gt;`expand_` combines each brace set with the fully-expanded tail:&lt;/p&gt;
&lt;p&gt;```js
const post = m.post.length ? expand_(m.post, max, false) : [&amp;#39;&amp;#39;]
...
for (let j = 0; j &amp;lt; N.length; j++) {
  for (let k = 0; k &amp;lt; post.length &amp;amp;&amp;amp; expansions.length &amp;lt; max; k++) {
    const expansion = pre + N[j] + post[k]   // grows one group longer per level
    ...
    expansions.push(expansion)
  }
}
```&lt;/p&gt;
&lt;p&gt;The loop guard `expansions.length &amp;lt; max` limits how many strings are built, but
nothing limits how long they get. Each recursion level materializes another
array of up to `max` strings, one…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mh99-v99m-4gvg</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-14257 — brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-14257</link>
      <description>msrc_CVE-2026-14257</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-14257</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>RHSA-2026:45360 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:45360</link>
      <description>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:45360</guid>
    </item>
    <item>
      <title>RHSA-2026:54371 — Red Hat Security Advisory: nodejs:24 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:54371</link>
      <description>&lt;p&gt;sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:54371</guid>
    </item>
    <item>
      <title>RLSA-2026:54371 — Important: nodejs:24 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:54371</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: nodejs, Rocky Linux:8: nodejs-nodemon, Rocky Linux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data (CVE-2026-11822)&lt;/p&gt;
&lt;p&gt;* sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 (CVE-2026-11824)&lt;/p&gt;
&lt;p&gt;* brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification (CVE-2026-54272)&lt;/p&gt;
&lt;p&gt;* brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: nodejs, Rocky Linux:8: nodejs-nodemon, Rocky Linux:8: nodejs-packaging&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data (CVE-2026-11822)&lt;/p&gt;
&lt;p&gt;* sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 (CVE-2026-11824)&lt;/p&gt;
&lt;p&gt;* brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification (CVE-2026-54272)&lt;/p&gt;
&lt;p&gt;* brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:54371</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-14257</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-14257</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:26.04:LTS: node-brace-expansion&lt;/p&gt;
&lt;p&gt;brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input (&amp;#39;{a,b}&amp;#39;.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:26.04:LTS: node-brace-expansion&lt;/p&gt;
&lt;p&gt;brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input (&amp;#39;{a,b}&amp;#39;.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-14257</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2816 — Red Hat Enterprise Linux (nodejs:24): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2816</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um SSRF-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren, möglicherweise beliebigen Code auszuführen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um SSRF-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten offenzulegen oder zu manipulieren, möglicherweise beliebigen Code auszuführen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2816</guid>
    </item>
  </channel>
</rss>
