<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:37:29 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</link>
      <description>certfr-2026-avi-0667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</guid>
    </item>
    <item>
      <title>EUVD-2026-275547</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275547</link>
      <description>EUVD-2026-275547</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275547</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31808</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31808</link>
      <description>&lt;p&gt;file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in the ASF (WMV/WMA) file type detection parser. When parsing a crafted input where an ASF sub-header has a size field of zero, the parser enters an infinite loop. The payload value becomes negative (-24), causing tokenizer.ignore(payload) to move the read position backwards, so the same sub-header is read repeatedly forever. Any application that uses file-type to detect the type of untrusted/attacker-controlled input is affected. An attacker can stall the Node.js event loop with a 55-byte payload. Fixed in version 21.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in the ASF (WMV/WMA) file type detection parser. When parsing a crafted input where an ASF sub-header has a size field of zero, the parser enters an infinite loop. The payload value becomes negative (-24), causing tokenizer.ignore(payload) to move the read position backwards, so the same sub-header is read repeatedly forever. Any application that uses file-type to detect the type of untrusted/attacker-controlled input is affected. An attacker can stall the Node.js event loop with a 55-byte payload. Fixed in version 21.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31808</guid>
    </item>
    <item>
      <title>GHSA-5v7r-6r5c-r473 — file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5v7r-6r5c-r473</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: file-type&lt;/p&gt;
&lt;p&gt;### Impact
A denial of service vulnerability exists in the ASF (WMV/WMA) file type detection parser. When parsing a crafted input where an ASF sub-header has a `size` field of zero, the parser enters an infinite loop. The `payload` value becomes negative (-24), causing `tokenizer.ignore(payload)` to move the read position backwards, so the same sub-header is read repeatedly forever.&lt;/p&gt;
&lt;p&gt;Any application that uses `file-type` to detect the type of untrusted/attacker-controlled input is affected. An attacker can stall the Node.js event loop with a 55-byte payload.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in version 21.3.1. Users should upgrade to &amp;gt;= 21.3.1.&lt;/p&gt;
&lt;p&gt;### Workarounds
Validate or limit the size of input buffers before passing them to `file-type`, or run file type detection in a worker thread with a timeout.&lt;/p&gt;
&lt;p&gt;### References
- Fix commit: 319abf871b50ba2fa221b4a7050059f1ae096f4f&lt;/p&gt;
&lt;p&gt;### Reporter&lt;/p&gt;
&lt;p&gt;crnkovic@lokvica.com&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: file-type&lt;/p&gt;
&lt;p&gt;### Impact
A denial of service vulnerability exists in the ASF (WMV/WMA) file type detection parser. When parsing a crafted input where an ASF sub-header has a `size` field of zero, the parser enters an infinite loop. The `payload` value becomes negative (-24), causing `tokenizer.ignore(payload)` to move the read position backwards, so the same sub-header is read repeatedly forever.&lt;/p&gt;
&lt;p&gt;Any application that uses `file-type` to detect the type of untrusted/attacker-controlled input is affected. An attacker can stall the Node.js event loop with a 55-byte payload.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in version 21.3.1. Users should upgrade to &amp;gt;= 21.3.1.&lt;/p&gt;
&lt;p&gt;### Workarounds
Validate or limit the size of input buffers before passing them to `file-type`, or run file type detection in a worker thread with a timeout.&lt;/p&gt;
&lt;p&gt;### References
- Fix commit: 319abf871b50ba2fa221b4a7050059f1ae096f4f&lt;/p&gt;
&lt;p&gt;### Reporter&lt;/p&gt;
&lt;p&gt;crnkovic@lokvica.com&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5v7r-6r5c-r473</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1940 — IBM App Connect Enterprise: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1940</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1940</guid>
    </item>
  </channel>
</rss>
