<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:09:45 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-SJ56797 — Security fix for CVE-2026-32887 applied in: jitsucom-jitsu 2.11.0-r3</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-sj56797</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jitsucom-jitsu&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the jitsucom-jitsu package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jitsucom-jitsu&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the jitsucom-jitsu package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-sj56797</guid>
    </item>
    <item>
      <title>EUVD-2026-277346</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277346</link>
      <description>EUVD-2026-277346</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277346</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32887</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32887</link>
      <description>&lt;p&gt;Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript applications. Prior to version 3.20.0, when using `RpcServer.toWebHandler` (or `HttpApp.toWebHandlerRuntime`) inside a Next.js App Router route handler, any Node.js `AsyncLocalStorage`-dependent API called from within an Effect fiber can read another concurrent request&amp;#39;s context — or no context at all. Under production traffic, `auth()` from `@clerk/nextjs/server` returns a different user&amp;#39;s session. Version 3.20.0 contains a fix for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript applications. Prior to version 3.20.0, when using `RpcServer.toWebHandler` (or `HttpApp.toWebHandlerRuntime`) inside a Next.js App Router route handler, any Node.js `AsyncLocalStorage`-dependent API called from within an Effect fiber can read another concurrent request&amp;#39;s context — or no context at all. Under production traffic, `auth()` from `@clerk/nextjs/server` returns a different user&amp;#39;s session. Version 3.20.0 contains a fix for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32887</guid>
    </item>
    <item>
      <title>GHSA-38f7-945m-qr2g — Effect `AsyncLocalStorage` context lost/contaminated inside Effect fibers under concurrent load with RPC</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-38f7-945m-qr2g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: effect&lt;/p&gt;
&lt;p&gt;## Versions&lt;/p&gt;
&lt;p&gt;- `effect`: 3.19.15
- `@effect/rpc`: 0.72.1
- `@effect/platform`: 0.94.2
- Node.js: v22.20.0
- Vercel runtime with Fluid compute
- Next.js: 16 (App Router)
- `@clerk/nextjs`: 6.x&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;Effect&amp;#39;s `MixedScheduler` batches fiber continuations and drains them inside a **single** microtask or timer callback. The `AsyncLocalStorage` context active during that callback belongs to whichever request first triggered the scheduler&amp;#39;s drain cycle — **not** the request that owns the fiber being resumed.&lt;/p&gt;
&lt;p&gt;### Detailed mechanism&lt;/p&gt;
&lt;p&gt;#### 1. Scheduler batching (`effect/src/Scheduler.ts`, `MixedScheduler`)&lt;/p&gt;
&lt;p&gt;```typescript
// MixedScheduler.starve() — called once when first task is scheduled
private starve(depth = 0) {
  if (depth &amp;gt;= this.maxNextTickBeforeTimer) {
    setTimeout(() =&amp;gt; this.starveInternal(0), 0)       // timer queue
  } else {
    Promise.resolve(void 0).then(() =&amp;gt; this.starveInternal(depth + 1)) // microtask queue
  }
}&lt;/p&gt;
&lt;p&gt;// MixedScheduler.starveInternal() — drains ALL accumulated tasks in one call
private starveInternal(depth: number) {
  const tasks = this.tasks.buckets
  this.tasks.buckets = []
  for (const [_, toRun] of tasks) {
    for (let i = 0; i &amp;lt; toRun.length; i++) {
      toRun[i]()  // ← Every fiber continuation runs in the SAME ALS context
    }
  }
  // ...
}
```&lt;/p&gt;
&lt;p&gt;`scheduleTask` only calls `starve()` when `running` is `false`. Subsequent tasks accumulate in `this.tasks` until `starveInternal` drains them all. The `Promise.then()` (or `setTimeout`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: effect&lt;/p&gt;
&lt;p&gt;## Versions&lt;/p&gt;
&lt;p&gt;- `effect`: 3.19.15
- `@effect/rpc`: 0.72.1
- `@effect/platform`: 0.94.2
- Node.js: v22.20.0
- Vercel runtime with Fluid compute
- Next.js: 16 (App Router)
- `@clerk/nextjs`: 6.x&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;Effect&amp;#39;s `MixedScheduler` batches fiber continuations and drains them inside a **single** microtask or timer callback. The `AsyncLocalStorage` context active during that callback belongs to whichever request first triggered the scheduler&amp;#39;s drain cycle — **not** the request that owns the fiber being resumed.&lt;/p&gt;
&lt;p&gt;### Detailed mechanism&lt;/p&gt;
&lt;p&gt;#### 1. Scheduler batching (`effect/src/Scheduler.ts`, `MixedScheduler`)&lt;/p&gt;
&lt;p&gt;```typescript
// MixedScheduler.starve() — called once when first task is scheduled
private starve(depth = 0) {
  if (depth &amp;gt;= this.maxNextTickBeforeTimer) {
    setTimeout(() =&amp;gt; this.starveInternal(0), 0)       // timer queue
  } else {
    Promise.resolve(void 0).then(() =&amp;gt; this.starveInternal(depth + 1)) // microtask queue
  }
}&lt;/p&gt;
&lt;p&gt;// MixedScheduler.starveInternal() — drains ALL accumulated tasks in one call
private starveInternal(depth: number) {
  const tasks = this.tasks.buckets
  this.tasks.buckets = []
  for (const [_, toRun] of tasks) {
    for (let i = 0; i &amp;lt; toRun.length; i++) {
      toRun[i]()  // ← Every fiber continuation runs in the SAME ALS context
    }
  }
  // ...
}
```&lt;/p&gt;
&lt;p&gt;`scheduleTask` only calls `starve()` when `running` is `false`. Subsequent tasks accumulate in `this.tasks` until `starveInternal` drains them all. The `Promise.then()` (or `setTimeout`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-38f7-945m-qr2g</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3046 — IBM Concert: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</guid>
    </item>
  </channel>
</rss>
