<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:51:43 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-WA26037 — Security fix for CVE-2026-16221 applied in: argo-workflows 3.6.19-r8</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-wa26037</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-wa26037</guid>
    </item>
    <item>
      <title>EUVD-2026-338871</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338871</link>
      <description>EUVD-2026-338871</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338871</guid>
    </item>
    <item>
      <title>fkie_cve-2026-16221</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-16221</link>
      <description>&lt;p&gt;Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node&amp;#39;s native WHATWG URL parser, used by fetch, undici, and Node&amp;#39;s http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use fast-uri to enforce host-based policy such as allowlists, denylists, loopback or SSRF filtering, redirect validation, or outbound proxy routing before passing the same URL into Node&amp;#39;s URL or fetch consumers can be steered to an unintended destination, including cloud metadata endpoints, loopback, or internal hosts.&lt;/p&gt;
&lt;p&gt;Patches: upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3.&lt;/p&gt;
&lt;p&gt;Workarounds: none.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node&amp;#39;s native WHATWG URL parser, used by fetch, undici, and Node&amp;#39;s http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use fast-uri to enforce host-based policy such as allowlists, denylists, loopback or SSRF filtering, redirect validation, or outbound proxy routing before passing the same URL into Node&amp;#39;s URL or fetch consumers can be steered to an unintended destination, including cloud metadata endpoints, loopback, or internal hosts.&lt;/p&gt;
&lt;p&gt;Patches: upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3.&lt;/p&gt;
&lt;p&gt;Workarounds: none.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-16221</guid>
    </item>
    <item>
      <title>GHSA-v2hh-gcrm-f6hx — fast-uri vulnerable to host confusion via literal backslash authority delimiter</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v2hh-gcrm-f6hx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-uri&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;`fast-uri` v4.1.0 and earlier do not treat a literal backslash (U+005C) as an authority delimiter. Node&amp;#39;s native WHATWG `URL` (used by `fetch()`, `undici`, and Node&amp;#39;s `http`/`https` clients) normalizes `\` to `/` for special schemes (`http`, `https`, `ws`, `wss`, `ftp`, `file`), so the two parsers extract different hosts from the same input string.&lt;/p&gt;
&lt;p&gt;For example, `http://evil.com\@allowed.com` is treated by `fast-uri` as host `allowed.com` with userinfo `evil.com\`, while Node&amp;#39;s WHATWG URL parser and `fetch()` see host `evil.com` with path `/@allowed.com`.&lt;/p&gt;
&lt;p&gt;Applications that use `fast-uri` to enforce host-based policy (allowlists, denylists, loopback/SSRF filtering, redirect validation, outbound proxy routing) before passing the same URL into Node&amp;#39;s URL or `fetch()` consumers see a policy/use desync and can be steered to an unintended destination, including cloud metadata endpoints, loopback, or internal hosts.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Upgrade to `fast-uri` v4.1.1, v3.1.4, or v2.4.3.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None. Upgrade to the patched version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-uri&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;`fast-uri` v4.1.0 and earlier do not treat a literal backslash (U+005C) as an authority delimiter. Node&amp;#39;s native WHATWG `URL` (used by `fetch()`, `undici`, and Node&amp;#39;s `http`/`https` clients) normalizes `\` to `/` for special schemes (`http`, `https`, `ws`, `wss`, `ftp`, `file`), so the two parsers extract different hosts from the same input string.&lt;/p&gt;
&lt;p&gt;For example, `http://evil.com\@allowed.com` is treated by `fast-uri` as host `allowed.com` with userinfo `evil.com\`, while Node&amp;#39;s WHATWG URL parser and `fetch()` see host `evil.com` with path `/@allowed.com`.&lt;/p&gt;
&lt;p&gt;Applications that use `fast-uri` to enforce host-based policy (allowlists, denylists, loopback/SSRF filtering, redirect validation, outbound proxy routing) before passing the same URL into Node&amp;#39;s URL or `fetch()` consumers see a policy/use desync and can be steered to an unintended destination, including cloud metadata endpoints, loopback, or internal hosts.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Upgrade to `fast-uri` v4.1.1, v3.1.4, or v2.4.3.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None. Upgrade to the patched version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v2hh-gcrm-f6hx</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>RHSA-2026:54517 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:54517</link>
      <description>&lt;p&gt;fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling DOMPurify: DOMPurify: Cross-Site Scripting via unsanitized DOM elements from different realms DOMPurify: DOMPurify: Cross-site scripting due to state leakage in sanitization. dompurify: DOMPurify: URI validation bypass leads to cross-site scripting dompurify: DOMPurify: Cross-Site Scripting (XSS) via prototype pollution in USE_PROFILES mode dompurify: DOMPurify: Cross-Site Scripting vulnerability allows arbitrary code execution browserslist: Browserslist: Prototype pollution leading to denial of service browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling DOMPurify: DOMPurify: Cross-Site Scripting via unsanitized DOM elements from different realms DOMPurify: DOMPurify: Cross-site scripting due to state leakage in sanitization. dompurify: DOMPurify: URI validation bypass leads to cross-site scripting dompurify: DOMPurify: Cross-Site Scripting (XSS) via prototype pollution in USE_PROFILES mode dompurify: DOMPurify: Cross-Site Scripting vulnerability allows arbitrary code execution browserslist: Browserslist: Prototype pollution leading to denial of service browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:54517</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-16221</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16221</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-ajv, Ubuntu:20.04:LTS: node-ajv, Ubuntu:22.04:LTS: node-ajv, Ubuntu:24.04:LTS: node-ajv, Ubuntu:26.04:LTS: node-ajv&lt;/p&gt;
&lt;p&gt;Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node&amp;#39;s native WHATWG URL parser, used by fetch, undici, and Node&amp;#39;s http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use fast-uri to enforce host-based policy such as allowlists, denylists, loopback or SSRF filtering, redirect validation, or outbound proxy routing before passing the same URL into Node&amp;#39;s URL or fetch consumers can be steered to an unintended destination, including cloud metadata endpoints, loopback, or internal hosts. Patches: upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3. Workarounds: none.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-ajv, Ubuntu:20.04:LTS: node-ajv, Ubuntu:22.04:LTS: node-ajv, Ubuntu:24.04:LTS: node-ajv, Ubuntu:26.04:LTS: node-ajv&lt;/p&gt;
&lt;p&gt;Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node&amp;#39;s native WHATWG URL parser, used by fetch, undici, and Node&amp;#39;s http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use fast-uri to enforce host-based policy such as allowlists, denylists, loopback or SSRF filtering, redirect validation, or outbound proxy routing before passing the same URL into Node&amp;#39;s URL or fetch consumers can be steered to an unintended destination, including cloud metadata endpoints, loopback, or internal hosts. Patches: upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3. Workarounds: none.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16221</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2923 — Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2923</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2923</guid>
    </item>
  </channel>
</rss>
