<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:39:33 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-11376</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-11376</link>
      <description>bdu:2026-11376</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-11376</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0523 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0523</link>
      <description>certfr-2026-avi-0523</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0523</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CE10526 — Security fixes for CVE-2025-64756, CVE-2025-69873, CVE-2026-1525, CVE-2026-1526, CVE-2026-1527, CVE-2026-1528, CVE-2026…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: renovate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: renovate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</guid>
    </item>
    <item>
      <title>EUVD-2026-274222</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274222</link>
      <description>EUVD-2026-274222</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274222</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27601</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27601</link>
      <description>&lt;p&gt;Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be used to create a recursive datastructure, for example using JSON.parse, with no enforced depth limit. The datastructure thus created must be passed to _.flatten or _.isEqual. In the case of _.flatten, the vulnerability can only be exploited if it is possible for a remote client to prepare a datastructure that consists of arrays at all levels AND if no finite depth limit is passed as the second argument to _.flatten. In the case of _.isEqual, the vulnerability can only be exploited if there exists a code path in which two distinct datastructures that were submitted by the same remote client are compared using _.isEqual. For example, if a client submits data that are stored in a database, and the same client can later submit another datastructure that is then compared to the data that were saved in the database previously, OR if a client submits a single request, but its data are parsed twice, creating two non-identical but equivalent datastructures that are then compared. Exceptions originating from the call to _.flatten or _.isEqual, as a result of a stack overflow, are not being caught. This vulnerability is fixed in 1.13.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be used to create a recursive datastructure, for example using JSON.parse, with no enforced depth limit. The datastructure thus created must be passed to _.flatten or _.isEqual. In the case of _.flatten, the vulnerability can only be exploited if it is possible for a remote client to prepare a datastructure that consists of arrays at all levels AND if no finite depth limit is passed as the second argument to _.flatten. In the case of _.isEqual, the vulnerability can only be exploited if there exists a code path in which two distinct datastructures that were submitted by the same remote client are compared using _.isEqual. For example, if a client submits data that are stored in a database, and the same client can later submit another datastructure that is then compared to the data that were saved in the database previously, OR if a client submits a single request, but its data are parsed twice, creating two non-identical but equivalent datastructures that are then compared. Exceptions originating from the call to _.flatten or _.isEqual, as a result of a stack overflow, are not being caught. This vulnerability is fixed in 1.13.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27601</guid>
    </item>
    <item>
      <title>GHSA-qpx9-hpmf-5gmw — Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qpx9-hpmf-5gmw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: underscore&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In simple words, some programs that use `_.flatten` or `_.isEqual` could be made to crash. Someone who wants to do harm may be able to do this on purpose. This can only be done if the program has special properties. It only works in Underscore versions up to 1.13.7. A more detailed explanation follows.&lt;/p&gt;
&lt;p&gt;In affected versions of Underscore, the `_.flatten` and `_.isEqual` functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow.&lt;/p&gt;
&lt;p&gt;A proof of concept (PoC) for this type of attack with `_.isEqual`:&lt;/p&gt;
&lt;p&gt;```js
const _ = require(&amp;#39;underscore&amp;#39;);&lt;/p&gt;
&lt;p&gt;// build JSON string for nested object ~4500 levels deep
// (for this to be an attack, the JSON would have to come from
// a request or other untrusted input)
let json = &amp;#39;&amp;#39;;
for (let i = 0; i &amp;lt; 4500; i++) json += &amp;#39;{&amp;#34;n&amp;#34;:&amp;#39;;
json += &amp;#39;&amp;#34;x&amp;#34;&amp;#39;;
for (let i = 0; i &amp;lt; 4500; i++) json += &amp;#39;}&amp;#39;;&lt;/p&gt;
&lt;p&gt;// construct two distinct objects with equal shape from the above JSON
const a = JSON.parse(json);
const b = JSON.parse(json);&lt;/p&gt;
&lt;p&gt;_.isEqual(a, b); // RangeError: Maximum call stack size exceeded
```&lt;/p&gt;
&lt;p&gt;A proof of concept (PoC) for this type of attack with `_.flatten`:&lt;/p&gt;
&lt;p&gt;```js
const _ = require(&amp;#39;underscore&amp;#39;);&lt;/p&gt;
&lt;p&gt;// build nested array ~4500 levels deep
// (like with _.isEqual, this nested array would have to be sourced
// from an untrusted external source for it to be an attack)
let nested = [];
for (let i = 0; i &amp;lt; 4500; i++) nested…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: underscore&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In simple words, some programs that use `_.flatten` or `_.isEqual` could be made to crash. Someone who wants to do harm may be able to do this on purpose. This can only be done if the program has special properties. It only works in Underscore versions up to 1.13.7. A more detailed explanation follows.&lt;/p&gt;
&lt;p&gt;In affected versions of Underscore, the `_.flatten` and `_.isEqual` functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow.&lt;/p&gt;
&lt;p&gt;A proof of concept (PoC) for this type of attack with `_.isEqual`:&lt;/p&gt;
&lt;p&gt;```js
const _ = require(&amp;#39;underscore&amp;#39;);&lt;/p&gt;
&lt;p&gt;// build JSON string for nested object ~4500 levels deep
// (for this to be an attack, the JSON would have to come from
// a request or other untrusted input)
let json = &amp;#39;&amp;#39;;
for (let i = 0; i &amp;lt; 4500; i++) json += &amp;#39;{&amp;#34;n&amp;#34;:&amp;#39;;
json += &amp;#39;&amp;#34;x&amp;#34;&amp;#39;;
for (let i = 0; i &amp;lt; 4500; i++) json += &amp;#39;}&amp;#39;;&lt;/p&gt;
&lt;p&gt;// construct two distinct objects with equal shape from the above JSON
const a = JSON.parse(json);
const b = JSON.parse(json);&lt;/p&gt;
&lt;p&gt;_.isEqual(a, b); // RangeError: Maximum call stack size exceeded
```&lt;/p&gt;
&lt;p&gt;A proof of concept (PoC) for this type of attack with `_.flatten`:&lt;/p&gt;
&lt;p&gt;```js
const _ = require(&amp;#39;underscore&amp;#39;);&lt;/p&gt;
&lt;p&gt;// build nested array ~4500 levels deep
// (like with _.isEqual, this nested array would have to be sourced
// from an untrusted external source for it to be an attack)
let nested = [];
for (let i = 0; i &amp;lt; 4500; i++) nested…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qpx9-hpmf-5gmw</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-27601 — Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-27601</link>
      <description>msrc_CVE-2026-27601</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-27601</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>OESA-2026-1578 — nodejs-underscore security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1578</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: nodejs-underscore&lt;/p&gt;
&lt;p&gt;Underscore.js is a utility-belt library for JavaScript that provides support for the usual functional suspects (each, map, reduce, filter...) without extending any core JavaScript objects.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Underscore.js is a utility-belt library for JavaScript. Prior to version 1.13.8, the `_.flatten` and `_.isEqual` functions use recursion without a depth limit. Under very specific conditions, an attacker could exploit this to cause a Denial of Service (DoS) attack by triggering a stack overflow. Exploitation requires all of the following: untrusted input must be used to create a deeply recursive data structure (e.g., via `JSON.parse` with no enforced depth limit), and this structure must be passed to `_.flatten` or `_.isEqual`. For `_.flatten`, the attacker must be able to prepare a data structure consisting solely of arrays at all levels, and no finite depth limit must be passed as the second argument to `_.flatten`. For `_.isEqual`, there must exist a code path where two distinct but structurally equivalent data structures, submitted by the same remote client, are compared using `_.isEqual`. Additionally, exceptions resulting from the stack overflow must not be caught. This vulnerability is fixed in version 1.13.8.(CVE-2026-27601)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: nodejs-underscore&lt;/p&gt;
&lt;p&gt;Underscore.js is a utility-belt library for JavaScript that provides support for the usual functional suspects (each, map, reduce, filter...) without extending any core JavaScript objects.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Underscore.js is a utility-belt library for JavaScript. Prior to version 1.13.8, the `_.flatten` and `_.isEqual` functions use recursion without a depth limit. Under very specific conditions, an attacker could exploit this to cause a Denial of Service (DoS) attack by triggering a stack overflow. Exploitation requires all of the following: untrusted input must be used to create a deeply recursive data structure (e.g., via `JSON.parse` with no enforced depth limit), and this structure must be passed to `_.flatten` or `_.isEqual`. For `_.flatten`, the attacker must be able to prepare a data structure consisting solely of arrays at all levels, and no finite depth limit must be passed as the second argument to `_.flatten`. For `_.isEqual`, there must exist a code path where two distinct but structurally equivalent data structures, submitted by the same remote client, are compared using `_.isEqual`. Additionally, exceptions resulting from the stack overflow must not be caught. This vulnerability is fixed in version 1.13.8.(CVE-2026-27601)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1578</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10424-1 — jupyter-bqplot-jupyterlab-0.5.46-14.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10424-1</link>
      <description>&lt;p&gt;jupyter-bqplot-jupyterlab-0.5.46-14.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jupyter-bqplot-jupyterlab-0.5.46-14.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10424-1</guid>
    </item>
    <item>
      <title>RHSA-2026:13826 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.4 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13826</link>
      <description>&lt;p&gt;axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization python-markdown: denial of service via malformed HTML-like sequences undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter rhdh: GraphQL Injection Leading to Platform-Wide Denial of Service (DoS) in RH Developer Hub Orchestrator Plugin lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Underscore.js: Underscore.js: Denial of Service via recursive data structures in flatten and isEqual functions minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution svgo: SVGO: Denial of Service via XML entity expansion backstage/plugin-techdocs-node: TechDocs Mkdocs configuration key enables arbitrary code execution flatted: flatted: Unbounded recursion DoS in parse() revive phase crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building golang: internal/syscall/unix: Root.Chmod can follow symlinks out…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization python-markdown: denial of service via malformed HTML-like sequences undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter rhdh: GraphQL Injection Leading to Platform-Wide Denial of Service (DoS) in RH Developer Hub Orchestrator Plugin lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Underscore.js: Underscore.js: Denial of Service via recursive data structures in flatten and isEqual functions minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution svgo: SVGO: Denial of Service via XML entity expansion backstage/plugin-techdocs-node: TechDocs Mkdocs configuration key enables arbitrary code execution flatted: flatted: Unbounded recursion DoS in parse() revive phase crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building golang: internal/syscall/unix: Root.Chmod can follow symlinks out…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13826</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-27601</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27601</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: ruby-rails-assets-underscore, Ubuntu:20.04:LTS: ruby-rails-assets-underscore, Ubuntu:22.04:LTS: ruby-rails-assets-underscore, Ubuntu:24.04:LTS: ruby-rails-assets-underscore&lt;/p&gt;
&lt;p&gt;Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be used to create a recursive datastructure, for example using JSON.parse, with no enforced depth limit. The datastructure thus created must be passed to _.flatten or _.isEqual. In the case of _.flatten, the vulnerability can only be exploited if it is possible for a remote client to prepare a datastructure that consists of arrays at all levels AND if no finite depth limit is passed as the second argument to _.flatten. In the case of _.isEqual, the vulnerability can only be exploited if there exists a code path in which two distinct datastructures that were submitted by the same remote client are compared using _.isEqual. For example, if a client submits data that are stored in a database, and the same client can later submit another datastructure that is then compared to the data that were saved in the database previously, OR if a client submits a single request, but its data are parsed twice, creating two non-identical but equivalent datastructures that are then compared. Exceptions originating from the call to _.flatten or _.isEqual, as a result of a stack overflow, are not being caught. This vulnerability is fixed in 1.13.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: ruby-rails-assets-underscore, Ubuntu:20.04:LTS: ruby-rails-assets-underscore, Ubuntu:22.04:LTS: ruby-rails-assets-underscore, Ubuntu:24.04:LTS: ruby-rails-assets-underscore&lt;/p&gt;
&lt;p&gt;Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untrusted input must be used to create a recursive datastructure, for example using JSON.parse, with no enforced depth limit. The datastructure thus created must be passed to _.flatten or _.isEqual. In the case of _.flatten, the vulnerability can only be exploited if it is possible for a remote client to prepare a datastructure that consists of arrays at all levels AND if no finite depth limit is passed as the second argument to _.flatten. In the case of _.isEqual, the vulnerability can only be exploited if there exists a code path in which two distinct datastructures that were submitted by the same remote client are compared using _.isEqual. For example, if a client submits data that are stored in a database, and the same client can later submit another datastructure that is then compared to the data that were saved in the database previously, OR if a client submits a single request, but its data are parsed twice, creating two non-identical but equivalent datastructures that are then compared. Exceptions originating from the call to _.flatten or _.isEqual, as a result of a stack overflow, are not being caught. This vulnerability is fixed in 1.13.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27601</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1220 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1220</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1220</guid>
    </item>
  </channel>
</rss>
