<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:13:37 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:7350 — Important: nodejs:24 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:7350</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: nodejs, AlmaLinux:9: nodejs-devel, AlmaLinux:9: nodejs-docs, AlmaLinux:9: nodejs-full-i18n, AlmaLinux:9: nodejs-libs, AlmaLinux:9: nodejs-nodemon, AlmaLinux:9: nodejs-packaging, AlmaLinux:9: nodejs-packaging-bundler, AlmaLinux:9: npm, AlmaLinux:9: v8-13.6-devel&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs: Nodejs denial of service (CVE-2026-21637)
  * brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion (CVE-2026-25547)
  * minimatch: minimatch: Denial of Service via specially crafted glob patterns (CVE-2026-26996)
  * undici: Undici: Denial of Service due to uncontrolled resource consumption (CVE-2026-2581)
  * undici: Undici: HTTP header injection and request smuggling vulnerability (CVE-2026-1527)
  * undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression (CVE-2026-1526)
  * undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter (CVE-2026-2229)
  * undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers (CVE-2026-1525)
  * undici: undici: Denial of Service via crafted WebSocket frame with large length (CVE-2026-1528)
  * nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)
  * Node.js: Node.js: Denial of Service via malformed Internationalized Domain Name processing (CVE-2026-21712)
  * Node.js: Node.js: Denial of Service due to crafted HTTP `__proto__` header (CVE-2026-21710)
  * Node.js: Node.js: Information disclosure due to `fs.realpathSync.native()` bypassing filesyste…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: nodejs, AlmaLinux:9: nodejs-devel, AlmaLinux:9: nodejs-docs, AlmaLinux:9: nodejs-full-i18n, AlmaLinux:9: nodejs-libs, AlmaLinux:9: nodejs-nodemon, AlmaLinux:9: nodejs-packaging, AlmaLinux:9: nodejs-packaging-bundler, AlmaLinux:9: npm, AlmaLinux:9: v8-13.6-devel&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs: Nodejs denial of service (CVE-2026-21637)
  * brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion (CVE-2026-25547)
  * minimatch: minimatch: Denial of Service via specially crafted glob patterns (CVE-2026-26996)
  * undici: Undici: Denial of Service due to uncontrolled resource consumption (CVE-2026-2581)
  * undici: Undici: HTTP header injection and request smuggling vulnerability (CVE-2026-1527)
  * undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression (CVE-2026-1526)
  * undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter (CVE-2026-2229)
  * undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers (CVE-2026-1525)
  * undici: undici: Denial of Service via crafted WebSocket frame with large length (CVE-2026-1528)
  * nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)
  * Node.js: Node.js: Denial of Service via malformed Internationalized Domain Name processing (CVE-2026-21712)
  * Node.js: Node.js: Denial of Service due to crafted HTTP `__proto__` header (CVE-2026-21710)
  * Node.js: Node.js: Information disclosure due to `fs.realpathSync.native()` bypassing filesyste…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:7350</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-2581</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-2581</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: nodejs, BellSoft Hardened Containers:stream: nodejs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: nodejs, BellSoft Hardened Containers:stream: nodejs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-2581</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</link>
      <description>certfr-2026-avi-0667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CE10526 — Security fixes for CVE-2025-64756, CVE-2025-69873, CVE-2026-1525, CVE-2026-1526, CVE-2026-1527, CVE-2026-1528, CVE-2026…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: renovate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: renovate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</guid>
    </item>
    <item>
      <title>EUVD-2026-275993</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275993</link>
      <description>EUVD-2026-275993</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275993</guid>
    </item>
    <item>
      <title>fkie_cve-2026-2581</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2581</link>
      <description>&lt;p&gt;This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS).&lt;/p&gt;
&lt;p&gt;In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted upstream endpoint can exploit this with large/chunked responses and concurrent identical requests, causing high memory usage and potential OOM process termination.&lt;/p&gt;
&lt;p&gt;Impacted users are applications that use Undici’s deduplication interceptor against endpoints that may produce large or long-lived response bodies.&lt;/p&gt;
&lt;p&gt;PatchesThe issue has been patched by changing deduplication behavior to stream response chunks to downstream handlers as they arrive (instead of full-body accumulation), and by preventing late deduplication when body streaming has already started.&lt;/p&gt;
&lt;p&gt;Users should upgrade to the first official Undici (and Node.js, where applicable) releases that include this patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS).&lt;/p&gt;
&lt;p&gt;In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted upstream endpoint can exploit this with large/chunked responses and concurrent identical requests, causing high memory usage and potential OOM process termination.&lt;/p&gt;
&lt;p&gt;Impacted users are applications that use Undici’s deduplication interceptor against endpoints that may produce large or long-lived response bodies.&lt;/p&gt;
&lt;p&gt;PatchesThe issue has been patched by changing deduplication behavior to stream response chunks to downstream handlers as they arrive (instead of full-body accumulation), and by preventing late deduplication when body streaming has already started.&lt;/p&gt;
&lt;p&gt;Users should upgrade to the first official Undici (and Node.js, where applicable) releases that include this patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-2581</guid>
    </item>
    <item>
      <title>GHSA-phc3-fgpg-7m6h — Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-phc3-fgpg-7m6h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;## Impact
This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS).&lt;/p&gt;
&lt;p&gt;In vulnerable Undici versions, when `interceptors.deduplicate()` is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted upstream endpoint can exploit this with large/chunked responses and concurrent identical requests, causing high memory usage and potential OOM process termination.&lt;/p&gt;
&lt;p&gt;Impacted users are applications that use Undici’s deduplication interceptor against endpoints that may produce large or long-lived response bodies.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The issue has been patched by changing deduplication behavior to stream response chunks to downstream handlers as they arrive (instead of full-body accumulation), and by preventing late deduplication when body streaming has already started.&lt;/p&gt;
&lt;p&gt;Users should upgrade to the first official Undici (and Node.js, where applicable) releases that include this patch.&lt;/p&gt;
&lt;p&gt;## Workarounds
If upgrading immediately is not possible:&lt;/p&gt;
&lt;p&gt;- Disable `interceptors.deduplicate()` for affected clients/routes.
- Use `skipHeaderNames` with a marker header to force high-risk requests to bypass deduplication.
- Avoid concurrent identical requests to untrusted endpoints that may return very large/chunked bodies.
- Apply upstream/proxy response-size and timeout limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;## Impact
This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS).&lt;/p&gt;
&lt;p&gt;In vulnerable Undici versions, when `interceptors.deduplicate()` is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted upstream endpoint can exploit this with large/chunked responses and concurrent identical requests, causing high memory usage and potential OOM process termination.&lt;/p&gt;
&lt;p&gt;Impacted users are applications that use Undici’s deduplication interceptor against endpoints that may produce large or long-lived response bodies.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The issue has been patched by changing deduplication behavior to stream response chunks to downstream handlers as they arrive (instead of full-body accumulation), and by preventing late deduplication when body streaming has already started.&lt;/p&gt;
&lt;p&gt;Users should upgrade to the first official Undici (and Node.js, where applicable) releases that include this patch.&lt;/p&gt;
&lt;p&gt;## Workarounds
If upgrading immediately is not possible:&lt;/p&gt;
&lt;p&gt;- Disable `interceptors.deduplicate()` for affected clients/routes.
- Use `skipHeaderNames` with a marker header to force high-risk requests to bypass deduplication.
- Avoid concurrent identical requests to untrusted endpoints that may return very large/chunked bodies.
- Apply upstream/proxy response-size and timeout limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-phc3-fgpg-7m6h</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11121-1 — corepack24-24.17.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11121-1</link>
      <description>&lt;p&gt;corepack24-24.17.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;corepack24-24.17.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11121-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22565-1 — Security update for nodejs24</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22565-1</link>
      <description>&lt;p&gt;Security update for nodejs24&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs24&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22565-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-2581</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2581</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted upstream endpoint can exploit this with large/chunked responses and concurrent identical requests, causing high memory usage and potential OOM process termination. Impacted users are applications that use Undici’s deduplication interceptor against endpoints that may produce large or long-lived response bodies. PatchesThe issue has been patched by changing deduplication behavior to stream response chunks to downstream handlers as they arrive (instead of full-body accumulation), and by preventing late deduplication when body streaming has already started. Users should upgrade to the first official Undici (and Node.js, where applicable) releases that include this patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted upstream endpoint can exploit this with large/chunked responses and concurrent identical requests, causing high memory usage and potential OOM process termination. Impacted users are applications that use Undici’s deduplication interceptor against endpoints that may produce large or long-lived response bodies. PatchesThe issue has been patched by changing deduplication behavior to stream response chunks to downstream handlers as they arrive (instead of full-body accumulation), and by preventing late deduplication when body streaming has already started. Users should upgrade to the first official Undici (and Node.js, where applicable) releases that include this patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2581</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0933 — IBM App Connect Enterprise (Hono und Undici): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0933</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0933</guid>
    </item>
  </channel>
</rss>
