<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:31:52 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:18480 — Important: linux-sgx security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:18480</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: sgx-common, AlmaLinux:10: sgx-libs, AlmaLinux:10: sgx-mpa, AlmaLinux:10: sgx-pccs, AlmaLinux:10: sgx-pccs-admin, AlmaLinux:10: sgx-pckid-tool, AlmaLinux:10: tdx-qgs&lt;/p&gt;
&lt;p&gt;The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)
  * node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)
  * node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)
  * lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)
  * node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: sgx-common, AlmaLinux:10: sgx-libs, AlmaLinux:10: sgx-mpa, AlmaLinux:10: sgx-pccs, AlmaLinux:10: sgx-pccs-admin, AlmaLinux:10: sgx-pckid-tool, AlmaLinux:10: tdx-qgs&lt;/p&gt;
&lt;p&gt;The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)
  * node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)
  * node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)
  * lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)
  * node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:18480</guid>
    </item>
    <item>
      <title>bdu:2026-00891</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00891</link>
      <description>bdu:2026-00891</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00891</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0112 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0112</link>
      <description>certfr-2026-avi-0112</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0112</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD27625 — Security fixes for CVE-2022-25881, CVE-2022-33987, CVE-2025-25285, CVE-2025-62718, CVE-2025-69873, CVE-2026-21637, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</guid>
    </item>
    <item>
      <title>EUVD-2026-364324</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364324</link>
      <description>EUVD-2026-364324</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364324</guid>
    </item>
    <item>
      <title>fkie_cve-2026-24842</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24842</link>
      <description>&lt;p&gt;node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-24842</guid>
    </item>
    <item>
      <title>GHSA-34x7-hfp2-rc4v — node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-34x7-hfp2-rc4v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tar&lt;/p&gt;
&lt;p&gt;### Summary
node-tar contains a vulnerability where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability exists in `lib/unpack.js`. When extracting a hardlink, two functions handle the linkpath differently:&lt;/p&gt;
&lt;p&gt;**Security check in `[STRIPABSOLUTEPATH]`:**
```javascript
const entryDir = path.posix.dirname(entry.path);
const resolved = path.posix.normalize(path.posix.join(entryDir, linkpath));
if (resolved.startsWith(&amp;#39;../&amp;#39;)) { /* block */ }
```&lt;/p&gt;
&lt;p&gt;**Hardlink creation in `[HARDLINK]`:**
```javascript
const linkpath = path.resolve(this.cwd, entry.linkpath);
fs.linkSync(linkpath, dest);
```&lt;/p&gt;
&lt;p&gt;**Example:** An application extracts a TAR using `tar.extract({ cwd: &amp;#39;/var/app/uploads/&amp;#39; })`. The TAR contains entry `a/b/c/d/x` as a hardlink to `../../../../etc/passwd`.&lt;/p&gt;
&lt;p&gt;- **Security check** resolves the linkpath relative to the entry&amp;#39;s parent directory: `a/b/c/d/ + ../../../../etc/passwd` = `etc/passwd`. No `../` prefix, so it **passes**.&lt;/p&gt;
&lt;p&gt;- **Hardlink creation** resolves the linkpath relative to the extraction directory (`this.cwd`): `/var/app/uploads/ + ../../../../etc/passwd` = `/etc/passwd`. This **escapes** to the system&amp;#39;s `/etc/passwd`.&lt;/p&gt;
&lt;p&gt;The security check and hardlink creation use different starting points (en…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tar&lt;/p&gt;
&lt;p&gt;### Summary
node-tar contains a vulnerability where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability exists in `lib/unpack.js`. When extracting a hardlink, two functions handle the linkpath differently:&lt;/p&gt;
&lt;p&gt;**Security check in `[STRIPABSOLUTEPATH]`:**
```javascript
const entryDir = path.posix.dirname(entry.path);
const resolved = path.posix.normalize(path.posix.join(entryDir, linkpath));
if (resolved.startsWith(&amp;#39;../&amp;#39;)) { /* block */ }
```&lt;/p&gt;
&lt;p&gt;**Hardlink creation in `[HARDLINK]`:**
```javascript
const linkpath = path.resolve(this.cwd, entry.linkpath);
fs.linkSync(linkpath, dest);
```&lt;/p&gt;
&lt;p&gt;**Example:** An application extracts a TAR using `tar.extract({ cwd: &amp;#39;/var/app/uploads/&amp;#39; })`. The TAR contains entry `a/b/c/d/x` as a hardlink to `../../../../etc/passwd`.&lt;/p&gt;
&lt;p&gt;- **Security check** resolves the linkpath relative to the entry&amp;#39;s parent directory: `a/b/c/d/ + ../../../../etc/passwd` = `etc/passwd`. No `../` prefix, so it **passes**.&lt;/p&gt;
&lt;p&gt;- **Hardlink creation** resolves the linkpath relative to the extraction directory (`this.cwd`): `/var/app/uploads/ + ../../../../etc/passwd` = `/etc/passwd`. This **escapes** to the system&amp;#39;s `/etc/passwd`.&lt;/p&gt;
&lt;p&gt;The security check and hardlink creation use different starting points (en…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-34x7-hfp2-rc4v</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10410-1 — pnpm-10.32.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10410-1</link>
      <description>&lt;p&gt;pnpm-10.32.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pnpm-10.32.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10410-1</guid>
    </item>
    <item>
      <title>RHSA-2026:2900 — Red Hat Security Advisory: Network Observability 1.11.0 for OpenShift</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:2900</link>
      <description>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects golang: archive/tar: Unbounded allocation when parsing GNU sparse map github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks node-forge: node-forge ASN.1 Unbounded Recursion urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects golang: archive/tar: Unbounded allocation when parsing GNU sparse map github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks node-forge: node-forge ASN.1 Unbounded Recursion urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:2900</guid>
    </item>
    <item>
      <title>RLSA-2026:18480 — Important: linux-sgx security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:18480</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: linux-sgx&lt;/p&gt;
&lt;p&gt;The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)&lt;/p&gt;
&lt;p&gt;* lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux 10 Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: linux-sgx&lt;/p&gt;
&lt;p&gt;The Intel SGX SDK is a collection of APIs, libraries, documentations and tools that allow software developers to create and debug Intel SGX enabled applications in C/C++.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* qs: qs: Denial of Service via improper input validation in array parsing (CVE-2025-15284)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives (CVE-2026-23745)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition (CVE-2026-23950)&lt;/p&gt;
&lt;p&gt;* lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)&lt;/p&gt;
&lt;p&gt;* node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check (CVE-2026-24842)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux 10 Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:18480</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-24842</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24842</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-tar, Ubuntu:Pro:16.04:LTS: node-tar, Ubuntu:18.04:LTS: node-tar, Ubuntu:Pro:20.04:LTS: node-tar, Ubuntu:22.04:LTS: node-tar, Ubuntu:24.04:LTS: node-tar, Ubuntu:25.10: node-tar, Ubuntu:26.04:LTS: node-tar&lt;/p&gt;
&lt;p&gt;node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-tar, Ubuntu:Pro:16.04:LTS: node-tar, Ubuntu:18.04:LTS: node-tar, Ubuntu:Pro:20.04:LTS: node-tar, Ubuntu:22.04:LTS: node-tar, Ubuntu:24.04:LTS: node-tar, Ubuntu:25.10: node-tar, Ubuntu:26.04:LTS: node-tar&lt;/p&gt;
&lt;p&gt;node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24842</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0770 — Atlassian Jira: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0770</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Daten zu manipulieren und offenzulegen, Cross-Site-Scripting-Angriffe durchzuführen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Daten zu manipulieren und offenzulegen, Cross-Site-Scripting-Angriffe durchzuführen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0770</guid>
    </item>
  </channel>
</rss>
