<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:33:53 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10886</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10886</link>
      <description>bdu:2026-10886</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10886</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0500 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</link>
      <description>certfr-2026-avi-0500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-QW40696 — Security fixes in mongosh 2.8.2-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-qw40696</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Package mongosh version 2.8.2-r0 fixes 23 vulnerabilities: ghsa-2w6w-674q-4c4q, ghsa-3mfm-83xf-c92r, ghsa-xhpv-hc6g-r9c6, ghsa-9cx6-37pm-9jff, ghsa-xjpj-3mr7-gcpf...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Package mongosh version 2.8.2-r0 fixes 23 vulnerabilities: ghsa-2w6w-674q-4c4q, ghsa-3mfm-83xf-c92r, ghsa-xhpv-hc6g-r9c6, ghsa-9cx6-37pm-9jff, ghsa-xjpj-3mr7-gcpf...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-qw40696</guid>
    </item>
    <item>
      <title>EUVD-2026-277969</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277969</link>
      <description>EUVD-2026-277969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277969</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33532</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33532</link>
      <description>&lt;p&gt;`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack overflow. The node resolution/composition phase uses recursive function calls without a depth bound. An attacker who can supply YAML for parsing can trigger a `RangeError: Maximum call stack size exceeded` with a small payload (~2–10 KB). The `RangeError` is not a `YAMLParseError`, so applications that only catch YAML-specific errors will encounter an unexpected exception type. Depending on the host application&amp;#39;s exception handling, this can fail requests or terminate the Node.js process. Flow sequences allow deep nesting with minimal bytes (2 bytes per level: one `[` and one `]`). On the default Node.js stack, approximately 1,000–5,000 levels of nesting (2–10 KB input) exhaust the call stack. The exact threshold is environment-dependent (Node.js version, stack size, call stack depth at invocation). Note: the library&amp;#39;s `Parser` (CST phase) uses a stack-based iterative approach and is not affected. Only the compose/resolve phase uses actual call-stack recursion. All three public parsing APIs are affected: `YAML.parse()`, `YAML.parseDocument()`, and `YAML.parseAllDocuments()`. Versions 1.10.3 and 2.8.3 contain a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack overflow. The node resolution/composition phase uses recursive function calls without a depth bound. An attacker who can supply YAML for parsing can trigger a `RangeError: Maximum call stack size exceeded` with a small payload (~2–10 KB). The `RangeError` is not a `YAMLParseError`, so applications that only catch YAML-specific errors will encounter an unexpected exception type. Depending on the host application&amp;#39;s exception handling, this can fail requests or terminate the Node.js process. Flow sequences allow deep nesting with minimal bytes (2 bytes per level: one `[` and one `]`). On the default Node.js stack, approximately 1,000–5,000 levels of nesting (2–10 KB input) exhaust the call stack. The exact threshold is environment-dependent (Node.js version, stack size, call stack depth at invocation). Note: the library&amp;#39;s `Parser` (CST phase) uses a stack-based iterative approach and is not affected. Only the compose/resolve phase uses actual call-stack recursion. All three public parsing APIs are affected: `YAML.parse()`, `YAML.parseDocument()`, and `YAML.parseAllDocuments()`. Versions 1.10.3 and 2.8.3 contain a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33532</guid>
    </item>
    <item>
      <title>GHSA-48c2-rrv3-qjmp — yaml is vulnerable to Stack Overflow via deeply nested YAML collections</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-48c2-rrv3-qjmp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: yaml&lt;/p&gt;
&lt;p&gt;Parsing a YAML document with `yaml` may throw a RangeError due to a stack overflow.&lt;/p&gt;
&lt;p&gt;The node resolution/composition phase uses recursive function calls without a depth bound. An attacker who can supply YAML for parsing can trigger a `RangeError: Maximum call stack size exceeded` with a small payload (~2–10 KB). The `RangeError` is not a `YAMLParseError`, so applications that only catch YAML-specific errors will encounter an unexpected exception type. Depending on the host application&amp;#39;s exception handling, this can fail requests or terminate the Node.js process.&lt;/p&gt;
&lt;p&gt;Flow sequences allow deep nesting with minimal bytes (2 bytes per level: one `[` and one `]`). On the default Node.js stack, approximately 1,000–5,000 levels of nesting (2–10 KB input) exhaust the call stack. The exact threshold is environment-dependent (Node.js version, stack size, call stack depth at invocation).&lt;/p&gt;
&lt;p&gt;Note: the library&amp;#39;s `Parser` (CST phase) uses a stack-based iterative approach and is not affected. Only the compose/resolve phase uses actual call-stack recursion.&lt;/p&gt;
&lt;p&gt;All three public parsing APIs are affected: `YAML.parse()`, `YAML.parseDocument()`, and `YAML.parseAllDocuments()`.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```javascript
const YAML = require(&amp;#39;yaml&amp;#39;);&lt;/p&gt;
&lt;p&gt;// ~10 KB payload: 5000 levels of nested flow sequences
const payload = &amp;#39;[&amp;#39;.repeat(5000) + &amp;#39;1&amp;#39; + &amp;#39;]&amp;#39;.repeat(5000);&lt;/p&gt;
&lt;p&gt;try {
  YAML.parse(payload);
} catch (e) {
  console.log(e.constructor.name); // RangeError (NOT YAMLParseError)
  console.log(e.message);          // Maximum…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: yaml&lt;/p&gt;
&lt;p&gt;Parsing a YAML document with `yaml` may throw a RangeError due to a stack overflow.&lt;/p&gt;
&lt;p&gt;The node resolution/composition phase uses recursive function calls without a depth bound. An attacker who can supply YAML for parsing can trigger a `RangeError: Maximum call stack size exceeded` with a small payload (~2–10 KB). The `RangeError` is not a `YAMLParseError`, so applications that only catch YAML-specific errors will encounter an unexpected exception type. Depending on the host application&amp;#39;s exception handling, this can fail requests or terminate the Node.js process.&lt;/p&gt;
&lt;p&gt;Flow sequences allow deep nesting with minimal bytes (2 bytes per level: one `[` and one `]`). On the default Node.js stack, approximately 1,000–5,000 levels of nesting (2–10 KB input) exhaust the call stack. The exact threshold is environment-dependent (Node.js version, stack size, call stack depth at invocation).&lt;/p&gt;
&lt;p&gt;Note: the library&amp;#39;s `Parser` (CST phase) uses a stack-based iterative approach and is not affected. Only the compose/resolve phase uses actual call-stack recursion.&lt;/p&gt;
&lt;p&gt;All three public parsing APIs are affected: `YAML.parse()`, `YAML.parseDocument()`, and `YAML.parseAllDocuments()`.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```javascript
const YAML = require(&amp;#39;yaml&amp;#39;);&lt;/p&gt;
&lt;p&gt;// ~10 KB payload: 5000 levels of nested flow sequences
const payload = &amp;#39;[&amp;#39;.repeat(5000) + &amp;#39;1&amp;#39; + &amp;#39;]&amp;#39;.repeat(5000);&lt;/p&gt;
&lt;p&gt;try {
  YAML.parse(payload);
} catch (e) {
  console.log(e.constructor.name); // RangeError (NOT YAMLParseError)
  console.log(e.message);          // Maximum…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-48c2-rrv3-qjmp</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11053-1 — alloy-1.17.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11053-1</link>
      <description>&lt;p&gt;alloy-1.17.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;alloy-1.17.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11053-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22575-1 — Security update for alloy</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22575-1</link>
      <description>&lt;p&gt;Security update for alloy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for alloy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22575-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-33532</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33532</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-yaml, Ubuntu:24.04:LTS: node-yaml, Ubuntu:25.10: node-yaml, Ubuntu:26.04:LTS: node-yaml&lt;/p&gt;
&lt;p&gt;`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack overflow. The node resolution/composition phase uses recursive function calls without a depth bound. An attacker who can supply YAML for parsing can trigger a `RangeError: Maximum call stack size exceeded` with a small payload (~2–10 KB). The `RangeError` is not a `YAMLParseError`, so applications that only catch YAML-specific errors will encounter an unexpected exception type. Depending on the host application&amp;#39;s exception handling, this can fail requests or terminate the Node.js process. Flow sequences allow deep nesting with minimal bytes (2 bytes per level: one `[` and one `]`). On the default Node.js stack, approximately 1,000–5,000 levels of nesting (2–10 KB input) exhaust the call stack. The exact threshold is environment-dependent (Node.js version, stack size, call stack depth at invocation). Note: the library&amp;#39;s `Parser` (CST phase) uses a stack-based iterative approach and is not affected. Only the compose/resolve phase uses actual call-stack recursion. All three public parsing APIs are affected: `YAML.parse()`, `YAML.parseDocument()`, and `YAML.parseAllDocuments()`. Versions 1.10.3 and 2.8.3 contain a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-yaml, Ubuntu:24.04:LTS: node-yaml, Ubuntu:25.10: node-yaml, Ubuntu:26.04:LTS: node-yaml&lt;/p&gt;
&lt;p&gt;`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack overflow. The node resolution/composition phase uses recursive function calls without a depth bound. An attacker who can supply YAML for parsing can trigger a `RangeError: Maximum call stack size exceeded` with a small payload (~2–10 KB). The `RangeError` is not a `YAMLParseError`, so applications that only catch YAML-specific errors will encounter an unexpected exception type. Depending on the host application&amp;#39;s exception handling, this can fail requests or terminate the Node.js process. Flow sequences allow deep nesting with minimal bytes (2 bytes per level: one `[` and one `]`). On the default Node.js stack, approximately 1,000–5,000 levels of nesting (2–10 KB input) exhaust the call stack. The exact threshold is environment-dependent (Node.js version, stack size, call stack depth at invocation). Note: the library&amp;#39;s `Parser` (CST phase) uses a stack-based iterative approach and is not affected. Only the compose/resolve phase uses actual call-stack recursion. All three public parsing APIs are affected: `YAML.parse()`, `YAML.parseDocument()`, and `YAML.parseAllDocuments()`. Versions 1.10.3 and 2.8.3 contain a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33532</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1407 — IBM App Connect Enterprise Certified Container: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</guid>
    </item>
  </channel>
</rss>
