<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:33:52 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1233 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</link>
      <description>certfr-2026-avi-1233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BG21634 — Security fixes in langfuse-worker 3.216.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bg21634</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 3.216.0-r1 fixes 29 vulnerabilities: ghsa-frvp-7c67-39w9, ghsa-p63j-vcc4-9vmv, ghsa-55q2-fjhq-7xh7, ghsa-c2j3-45gr-mqc4, CVE-2026-69192...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 3.216.0-r1 fixes 29 vulnerabilities: ghsa-frvp-7c67-39w9, ghsa-p63j-vcc4-9vmv, ghsa-55q2-fjhq-7xh7, ghsa-c2j3-45gr-mqc4, CVE-2026-69192...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bg21634</guid>
    </item>
    <item>
      <title>EUVD-2026-342459</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342459</link>
      <description>EUVD-2026-342459</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342459</guid>
    </item>
    <item>
      <title>fkie_cve-2026-16729</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-16729</link>
      <description>&lt;p&gt;undici&amp;#39;s setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the unparsed array are not sanitized, so attacker-influenced input can inject additional cookie attributes. For example, a domain value containing a semicolon can append attributes such as SameSite, and an unparsed entry can inject attributes such as HttpOnly, without the caller setting them. Applications that pass user-controlled input to these fields, such as multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, or the Secure, HttpOnly, and SameSite attributes forced, stripped, or overridden. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici&amp;#39;s setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the unparsed array are not sanitized, so attacker-influenced input can inject additional cookie attributes. For example, a domain value containing a semicolon can append attributes such as SameSite, and an unparsed entry can inject attributes such as HttpOnly, without the caller setting them. Applications that pass user-controlled input to these fields, such as multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, or the Secure, HttpOnly, and SameSite attributes forced, stripped, or overridden. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-16729</guid>
    </item>
    <item>
      <title>GHSA-v3r7-h72x-cjcm — undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v3r7-h72x-cjcm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The `setCookie` function has two attribute injection paths. `validateCookieDomain` does not reject semicolons (`validateCookiePath` already does at 0x3B), so a `domain` value like `example.com; SameSite=None` lands verbatim as `Domain=example.com; SameSite=None`. The `unparsed` array&amp;#39;s loop only checks each entry contains `=` and does not sanitize values, so an entry like `X-Custom=val; HttpOnly` lands unchanged, injecting `HttpOnly` without the caller setting `cookie.httpOnly = true`.&lt;/p&gt;
&lt;p&gt;Applications that pass user-controlled input to these fields, typically multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, `Secure` or `HttpOnly` forced or stripped, or the intended SameSite tier overridden.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Patched in undici v6.28.0, v7.29.0, and v8.9.0.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;- Sanitize `domain` values against the RFC 1034 letter-digit-hyphen set before passing to `setCookie`.
- Do not pass user-controlled data to the `unparsed` field.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The `setCookie` function has two attribute injection paths. `validateCookieDomain` does not reject semicolons (`validateCookiePath` already does at 0x3B), so a `domain` value like `example.com; SameSite=None` lands verbatim as `Domain=example.com; SameSite=None`. The `unparsed` array&amp;#39;s loop only checks each entry contains `=` and does not sanitize values, so an entry like `X-Custom=val; HttpOnly` lands unchanged, injecting `HttpOnly` without the caller setting `cookie.httpOnly = true`.&lt;/p&gt;
&lt;p&gt;Applications that pass user-controlled input to these fields, typically multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, `Secure` or `HttpOnly` forced or stripped, or the intended SameSite tier overridden.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Patched in undici v6.28.0, v7.29.0, and v8.9.0.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;- Sanitize `domain` values against the RFC 1034 letter-digit-hyphen set before passing to `setCookie`.
- Do not pass user-controlled data to the `unparsed` field.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v3r7-h72x-cjcm</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-16729 — undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-16729</link>
      <description>msrc_CVE-2026-16729</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-16729</guid>
    </item>
    <item>
      <title>RHSA-2026:48273 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:48273</link>
      <description>&lt;p&gt;undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing undici: undici: HTTP header injection via unvalidated blob-like body type property undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length undici: Undici: Cookie attribute injection allows bypassing security protections nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw nodejs: Information disclosure due to improper permission enforcement nodejs: HTTPS Agent TLS session reuse skips hostname verification nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing undici: undici: HTTP header injection via unvalidated blob-like body type property undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length undici: Undici: Cookie attribute injection allows bypassing security protections nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw nodejs: Information disclosure due to improper permission enforcement nodejs: HTTPS Agent TLS session reuse skips hostname verification nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:48273</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:3929-1 — Security update for nodejs20</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:3929-1</link>
      <description>&lt;p&gt;Security update for nodejs20&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs20&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:3929-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-16729</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16729</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;undici&amp;#39;s setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the unparsed array are not sanitized, so attacker-influenced input can inject additional cookie attributes. For example, a domain value containing a semicolon can append attributes such as SameSite, and an unparsed entry can inject attributes such as HttpOnly, without the caller setting them. Applications that pass user-controlled input to these fields, such as multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, or the Secure, HttpOnly, and SameSite attributes forced, stripped, or overridden. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;undici&amp;#39;s setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the unparsed array are not sanitized, so attacker-influenced input can inject additional cookie attributes. For example, a domain value containing a semicolon can append attributes such as SameSite, and an unparsed entry can inject attributes such as HttpOnly, without the caller setting them. Applications that pass user-controlled input to these fields, such as multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, or the Secure, HttpOnly, and SameSite attributes forced, stripped, or overridden. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16729</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
