<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:41:07 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0372 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0372</link>
      <description>certfr-2026-avi-0372</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0372</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-YP71485 — Immutable</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-yp71485</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. Immutable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. Immutable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-yp71485</guid>
    </item>
    <item>
      <title>EUVD-2026-366106</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366106</link>
      <description>EUVD-2026-366106</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366106</guid>
    </item>
    <item>
      <title>fkie_cve-2026-29063</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29063</link>
      <description>&lt;p&gt;Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-29063</guid>
    </item>
    <item>
      <title>GHSA-wf6x-7x77-mvgw — Immutable is vulnerable to Prototype Pollution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wf6x-7x77-mvgw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: immutable&lt;/p&gt;
&lt;p&gt;## Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;A Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs.&lt;/p&gt;
&lt;p&gt;## Affected APIs&lt;/p&gt;
&lt;p&gt;| API                                     | Notes                                                       |
| --------------------------------------- | ----------------------------------------------------------- |
| `mergeDeep(target, source)`              | Iterates source keys via `ObjectSeq`, assigns `merged[key]` |
| `mergeDeepWith(merger, target, source)`  | Same code path                                              |
| `merge(target, source)`                    | Shallow variant, same assignment logic                      |
| `Map.toJS()`                              | `object[k] = v` in `toObject()` with no `__proto__` guard   |
| `Map.toObject()`                            | Same `toObject()` implementation                            |
| `Map.mergeDeep(source)`                  | When source is converted to plain object                    |&lt;/p&gt;
&lt;p&gt;## Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;| major version | patched version |
| --- | --- |
| 3.x | 3.8.3 |
| 4.x | 4.3.7 |
| 5.x | 5.1.5 |&lt;/p&gt;
&lt;p&gt;## Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;- [Validate user input](https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Prototype_pollution#validate_user_input)
- [Node.js fl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: immutable&lt;/p&gt;
&lt;p&gt;## Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;A Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs.&lt;/p&gt;
&lt;p&gt;## Affected APIs&lt;/p&gt;
&lt;p&gt;| API                                     | Notes                                                       |
| --------------------------------------- | ----------------------------------------------------------- |
| `mergeDeep(target, source)`              | Iterates source keys via `ObjectSeq`, assigns `merged[key]` |
| `mergeDeepWith(merger, target, source)`  | Same code path                                              |
| `merge(target, source)`                    | Shallow variant, same assignment logic                      |
| `Map.toJS()`                              | `object[k] = v` in `toObject()` with no `__proto__` guard   |
| `Map.toObject()`                            | Same `toObject()` implementation                            |
| `Map.mergeDeep(source)`                  | When source is converted to plain object                    |&lt;/p&gt;
&lt;p&gt;## Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;| major version | patched version |
| --- | --- |
| 3.x | 3.8.3 |
| 4.x | 4.3.7 |
| 5.x | 5.1.5 |&lt;/p&gt;
&lt;p&gt;## Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;- [Validate user input](https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Prototype_pollution#validate_user_input)
- [Node.js fl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wf6x-7x77-mvgw</guid>
    </item>
    <item>
      <title>RHSA-2026:11070 — Red Hat Security Advisory: RHACS 4.8.11 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:11070</link>
      <description>&lt;p&gt;immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:11070</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-29063</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29063</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-immutable, Ubuntu:22.04:LTS: node-immutable, Ubuntu:24.04:LTS: node-immutable, Ubuntu:25.10: node-immutable, Ubuntu:26.04:LTS: node-immutable&lt;/p&gt;
&lt;p&gt;Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-immutable, Ubuntu:22.04:LTS: node-immutable, Ubuntu:24.04:LTS: node-immutable, Ubuntu:25.10: node-immutable, Ubuntu:26.04:LTS: node-immutable&lt;/p&gt;
&lt;p&gt;Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-29063</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0845 — IBM WebSphere Application Server Liberty: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0845</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM WebSphere Application Server Liberty ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen und Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM WebSphere Application Server Liberty ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen und Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0845</guid>
    </item>
  </channel>
</rss>
