<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:08:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09444</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09444</link>
      <description>bdu:2026-09444</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09444</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0281 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0281</link>
      <description>certfr-2026-avi-0281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0281</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CB77162 — Security fixes for CVE-2026-2391, CVE-2026-26960, CVE-2026-29786, CVE-2026-31802, CVE-2026-4867, ghsa-34x7-hfp2-rc4v, g…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cb77162</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: thingsboard-tb-web-ui&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the thingsboard-tb-web-ui package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: thingsboard-tb-web-ui&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the thingsboard-tb-web-ui package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cb77162</guid>
    </item>
    <item>
      <title>EUVD-2026-268210</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-268210</link>
      <description>EUVD-2026-268210</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-268210</guid>
    </item>
    <item>
      <title>fkie_cve-2026-2391</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2391</link>
      <description>&lt;p&gt;### Summary
The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).&lt;/p&gt;
&lt;p&gt;### Details
When the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?param=a,b,c` becomes `[&amp;#39;a&amp;#39;, &amp;#39;b&amp;#39;, &amp;#39;c&amp;#39;]`). However, the limit check for `arrayLimit` (default: 20) and the optional throwOnLimitExceeded occur after the comma-handling logic in `parseArrayValue`, enabling a bypass. This permits creation of arbitrarily large arrays from a single parameter, leading to excessive memory allocation.&lt;/p&gt;
&lt;p&gt;**Vulnerable code** (lib/parse.js: lines ~40-50):
```js
if (val &amp;amp;&amp;amp; typeof val === &amp;#39;string&amp;#39; &amp;amp;&amp;amp; options.comma &amp;amp;&amp;amp; val.indexOf(&amp;#39;,&amp;#39;) &amp;gt; -1) {
    return val.split(&amp;#39;,&amp;#39;);
}&lt;/p&gt;
&lt;p&gt;if (options.throwOnLimitExceeded &amp;amp;&amp;amp; currentArrayLength &amp;gt;= options.arrayLimit) {
    throw new RangeError(&amp;#39;Array limit exceeded. Only &amp;#39; + options.arrayLimit + &amp;#39; element&amp;#39; + (options.arrayLimit === 1 ? &amp;#39;&amp;#39; : &amp;#39;s&amp;#39;) + &amp;#39; allowed in an array.&amp;#39;);
}&lt;/p&gt;
&lt;p&gt;return val;
```
The `split(&amp;#39;,&amp;#39;)` returns the array immediately, skipping the subsequent limit check. Downstream merging via `utils.combine` does not prevent allocation, even if it marks overflows for sparse arrays.This discrepancy allows attackers to send a single…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;### Summary
The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).&lt;/p&gt;
&lt;p&gt;### Details
When the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?param=a,b,c` becomes `[&amp;#39;a&amp;#39;, &amp;#39;b&amp;#39;, &amp;#39;c&amp;#39;]`). However, the limit check for `arrayLimit` (default: 20) and the optional throwOnLimitExceeded occur after the comma-handling logic in `parseArrayValue`, enabling a bypass. This permits creation of arbitrarily large arrays from a single parameter, leading to excessive memory allocation.&lt;/p&gt;
&lt;p&gt;**Vulnerable code** (lib/parse.js: lines ~40-50):
```js
if (val &amp;amp;&amp;amp; typeof val === &amp;#39;string&amp;#39; &amp;amp;&amp;amp; options.comma &amp;amp;&amp;amp; val.indexOf(&amp;#39;,&amp;#39;) &amp;gt; -1) {
    return val.split(&amp;#39;,&amp;#39;);
}&lt;/p&gt;
&lt;p&gt;if (options.throwOnLimitExceeded &amp;amp;&amp;amp; currentArrayLength &amp;gt;= options.arrayLimit) {
    throw new RangeError(&amp;#39;Array limit exceeded. Only &amp;#39; + options.arrayLimit + &amp;#39; element&amp;#39; + (options.arrayLimit === 1 ? &amp;#39;&amp;#39; : &amp;#39;s&amp;#39;) + &amp;#39; allowed in an array.&amp;#39;);
}&lt;/p&gt;
&lt;p&gt;return val;
```
The `split(&amp;#39;,&amp;#39;)` returns the array immediately, skipping the subsequent limit check. Downstream merging via `utils.combine` does not prevent allocation, even if it marks overflows for sparse arrays.This discrepancy allows attackers to send a single…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-2391</guid>
    </item>
    <item>
      <title>GHSA-w7fw-mjwx-w883 — qs's arrayLimit bypass in comma parsing allows denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w7fw-mjwx-w883</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: qs&lt;/p&gt;
&lt;p&gt;### Summary
The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).&lt;/p&gt;
&lt;p&gt;### Details
When the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?param=a,b,c` becomes `[&amp;#39;a&amp;#39;, &amp;#39;b&amp;#39;, &amp;#39;c&amp;#39;]`). However, the limit check for `arrayLimit` (default: 20) and the optional throwOnLimitExceeded occur after the comma-handling logic in `parseArrayValue`, enabling a bypass. This permits creation of arbitrarily large arrays from a single parameter, leading to excessive memory allocation.&lt;/p&gt;
&lt;p&gt;**Vulnerable code** (lib/parse.js: lines ~40-50):
```js
if (val &amp;amp;&amp;amp; typeof val === &amp;#39;string&amp;#39; &amp;amp;&amp;amp; options.comma &amp;amp;&amp;amp; val.indexOf(&amp;#39;,&amp;#39;) &amp;gt; -1) {
    return val.split(&amp;#39;,&amp;#39;);
}&lt;/p&gt;
&lt;p&gt;if (options.throwOnLimitExceeded &amp;amp;&amp;amp; currentArrayLength &amp;gt;= options.arrayLimit) {
    throw new RangeError(&amp;#39;Array limit exceeded. Only &amp;#39; + options.arrayLimit + &amp;#39; element&amp;#39; + (options.arrayLimit === 1 ? &amp;#39;&amp;#39; : &amp;#39;s&amp;#39;) + &amp;#39; allowed in an array.&amp;#39;);
}&lt;/p&gt;
&lt;p&gt;return val;
```
The `split(&amp;#39;,&amp;#39;)` returns the array immediately, skipping the subsequent limit check. Downstream merging via `utils.combine` does not prevent allocation, even if it marks overflows for sparse arrays.This discrepancy allows attackers to send a single…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: qs&lt;/p&gt;
&lt;p&gt;### Summary
The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284).&lt;/p&gt;
&lt;p&gt;### Details
When the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?param=a,b,c` becomes `[&amp;#39;a&amp;#39;, &amp;#39;b&amp;#39;, &amp;#39;c&amp;#39;]`). However, the limit check for `arrayLimit` (default: 20) and the optional throwOnLimitExceeded occur after the comma-handling logic in `parseArrayValue`, enabling a bypass. This permits creation of arbitrarily large arrays from a single parameter, leading to excessive memory allocation.&lt;/p&gt;
&lt;p&gt;**Vulnerable code** (lib/parse.js: lines ~40-50):
```js
if (val &amp;amp;&amp;amp; typeof val === &amp;#39;string&amp;#39; &amp;amp;&amp;amp; options.comma &amp;amp;&amp;amp; val.indexOf(&amp;#39;,&amp;#39;) &amp;gt; -1) {
    return val.split(&amp;#39;,&amp;#39;);
}&lt;/p&gt;
&lt;p&gt;if (options.throwOnLimitExceeded &amp;amp;&amp;amp; currentArrayLength &amp;gt;= options.arrayLimit) {
    throw new RangeError(&amp;#39;Array limit exceeded. Only &amp;#39; + options.arrayLimit + &amp;#39; element&amp;#39; + (options.arrayLimit === 1 ? &amp;#39;&amp;#39; : &amp;#39;s&amp;#39;) + &amp;#39; allowed in an array.&amp;#39;);
}&lt;/p&gt;
&lt;p&gt;return val;
```
The `split(&amp;#39;,&amp;#39;)` returns the array immediately, skipping the subsequent limit check. Downstream merging via `utils.combine` does not prevent allocation, even if it marks overflows for sparse arrays.This discrepancy allows attackers to send a single…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w7fw-mjwx-w883</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-2391</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2391</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-qs, Ubuntu:16.04:LTS: node-qs, Ubuntu:18.04:LTS: node-qs, Ubuntu:Pro:20.04:LTS: node-qs, Ubuntu:22.04:LTS: node-qs, Ubuntu:24.04:LTS: node-qs, Ubuntu:25.10: node-qs, Ubuntu:26.04:LTS: node-qs&lt;/p&gt;
&lt;p&gt;### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284). ### Details When the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?param=a,b,c` becomes `[&amp;#39;a&amp;#39;, &amp;#39;b&amp;#39;, &amp;#39;c&amp;#39;]`). However, the limit check for `arrayLimit` (default: 20) and the optional throwOnLimitExceeded occur after the comma-handling logic in `parseArrayValue`, enabling a bypass. This permits creation of arbitrarily large arrays from a single parameter, leading to excessive memory allocation. **Vulnerable code** (lib/parse.js: lines ~40-50): ```js if (val &amp;amp;&amp;amp; typeof val === &amp;#39;string&amp;#39; &amp;amp;&amp;amp; options.comma &amp;amp;&amp;amp; val.indexOf(&amp;#39;,&amp;#39;) &amp;gt; -1) {     return val.split(&amp;#39;,&amp;#39;); } if (options.throwOnLimitExceeded &amp;amp;&amp;amp; currentArrayLength &amp;gt;= options.arrayLimit) {     throw new RangeError(&amp;#39;Array limit exceeded. Only &amp;#39; + options.arrayLimit + &amp;#39; element&amp;#39; + (options.arrayLimit === 1 ? &amp;#39;&amp;#39; : &amp;#39;s&amp;#39;) + &amp;#39; allowed in an array.&amp;#39;); } return val; ``` The `split(&amp;#39;,&amp;#39;)` returns the array immediately, skipping the subsequent limit check. Downstream merging via `utils.combine` does not prevent allocation, even if it marks overflows for sparse arrays.This discrepancy allows attackers to send a single par…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-qs, Ubuntu:16.04:LTS: node-qs, Ubuntu:18.04:LTS: node-qs, Ubuntu:Pro:20.04:LTS: node-qs, Ubuntu:22.04:LTS: node-qs, Ubuntu:24.04:LTS: node-qs, Ubuntu:25.10: node-qs, Ubuntu:26.04:LTS: node-qs&lt;/p&gt;
&lt;p&gt;### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6rw7-vpxm-498p (CVE-2025-15284). ### Details When the `comma` option is set to `true` (not the default, but configurable in applications), qs allows parsing comma-separated strings as arrays (e.g., `?param=a,b,c` becomes `[&amp;#39;a&amp;#39;, &amp;#39;b&amp;#39;, &amp;#39;c&amp;#39;]`). However, the limit check for `arrayLimit` (default: 20) and the optional throwOnLimitExceeded occur after the comma-handling logic in `parseArrayValue`, enabling a bypass. This permits creation of arbitrarily large arrays from a single parameter, leading to excessive memory allocation. **Vulnerable code** (lib/parse.js: lines ~40-50): ```js if (val &amp;amp;&amp;amp; typeof val === &amp;#39;string&amp;#39; &amp;amp;&amp;amp; options.comma &amp;amp;&amp;amp; val.indexOf(&amp;#39;,&amp;#39;) &amp;gt; -1) {     return val.split(&amp;#39;,&amp;#39;); } if (options.throwOnLimitExceeded &amp;amp;&amp;amp; currentArrayLength &amp;gt;= options.arrayLimit) {     throw new RangeError(&amp;#39;Array limit exceeded. Only &amp;#39; + options.arrayLimit + &amp;#39; element&amp;#39; + (options.arrayLimit === 1 ? &amp;#39;&amp;#39; : &amp;#39;s&amp;#39;) + &amp;#39; allowed in an array.&amp;#39;); } return val; ``` The `split(&amp;#39;,&amp;#39;)` returns the array immediately, skipping the subsequent limit check. Downstream merging via `utils.combine` does not prevent allocation, even if it marks overflows for sparse arrays.This discrepancy allows attackers to send a single par…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2391</guid>
    </item>
    <item>
      <title>VDE-2026-064 — METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.3</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-064</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been discovered in LabX Standard v21.3.22. Most of the vulnerabilities are fixed in LabX Standard v21.4.23. The Vulnerabilities CVE-2025-69419, CVE-2026-0915, CVE-2025-15467 and CVE-2025-58187 are not yet fixed. The fix will be available in the upcoming releases.&lt;/p&gt;
&lt;p&gt;Notice: LabX Standard was formerly known as LabX Cloud Local.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been discovered in LabX Standard v21.3.22. Most of the vulnerabilities are fixed in LabX Standard v21.4.23. The Vulnerabilities CVE-2025-69419, CVE-2026-0915, CVE-2025-15467 and CVE-2025-58187 are not yet fixed. The fix will be available in the upcoming releases.&lt;/p&gt;
&lt;p&gt;Notice: LabX Standard was formerly known as LabX Cloud Local.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-064</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2933 — Splunk SOAR: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</guid>
    </item>
  </channel>
</rss>
