<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:05:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09397</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09397</link>
      <description>bdu:2026-09397</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09397</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0698 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0698</link>
      <description>certfr-2026-avi-0698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0698</guid>
    </item>
    <item>
      <title>EUVD-2026-276996</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276996</link>
      <description>EUVD-2026-276996</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276996</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33151</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33151</link>
      <description>&lt;p&gt;Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33151</guid>
    </item>
    <item>
      <title>GHSA-677m-j7p3-52f9 — socket.io allows an unbounded number of binary attachments</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-677m-j7p3-52f9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: socket.io-parser&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;| Version range    | Used by                                    | Fixed version |
|------------------|--------------------------------------------|---------------|
| `&amp;gt;=4.0.0 &amp;lt;4.2.6` | `socket.io@4.x` and `socket.io-client@4.x` | `4.2.6`       |
| `&amp;gt;=3.4.0 &amp;lt;3.4.4` | `socket.io@2.x`                            | `3.4.4`       |
| `&amp;lt;3.3.5`         | `socket.io-client@2.x`                     | `3.3.5`       |&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;There is no known workaround except upgrading to a safe version.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;- Open a discussion [here](https://github.com/socketio/socket.io/discussions)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: socket.io-parser&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;| Version range    | Used by                                    | Fixed version |
|------------------|--------------------------------------------|---------------|
| `&amp;gt;=4.0.0 &amp;lt;4.2.6` | `socket.io@4.x` and `socket.io-client@4.x` | `4.2.6`       |
| `&amp;gt;=3.4.0 &amp;lt;3.4.4` | `socket.io@2.x`                            | `3.4.4`       |
| `&amp;lt;3.3.5`         | `socket.io-client@2.x`                     | `3.3.5`       |&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;There is no known workaround except upgrading to a safe version.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;- Open a discussion [here](https://github.com/socketio/socket.io/discussions)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-677m-j7p3-52f9</guid>
    </item>
    <item>
      <title>SCA-2026-0008 — Vulnerability Affecting SICK Sentio Creator Extension “Software Deployment Manager”</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0008</link>
      <description>&lt;p&gt;Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0008</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-33151</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33151</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-socket.io-parser, Ubuntu:20.04:LTS: node-socket.io-parser, Ubuntu:22.04:LTS: node-socket.io-parser, Ubuntu:24.04:LTS: node-socket.io-parser, Ubuntu:25.10: node-socket.io-parser, Ubuntu:26.04:LTS: node-socket.io-parser&lt;/p&gt;
&lt;p&gt;Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-socket.io-parser, Ubuntu:20.04:LTS: node-socket.io-parser, Ubuntu:22.04:LTS: node-socket.io-parser, Ubuntu:24.04:LTS: node-socket.io-parser, Ubuntu:25.10: node-socket.io-parser, Ubuntu:26.04:LTS: node-socket.io-parser&lt;/p&gt;
&lt;p&gt;Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33151</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1407 — IBM App Connect Enterprise Certified Container: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</guid>
    </item>
  </channel>
</rss>
