<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:55:29 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10885</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10885</link>
      <description>bdu:2026-10885</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10885</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0788 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</link>
      <description>certfr-2026-avi-0788</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AG43501 — Security fixes in sqlpad 7.5.7-r2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ag43501</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: sqlpad&lt;/p&gt;
&lt;p&gt;Package sqlpad version 7.5.7-r2 fixes 26 vulnerabilities: ghsa-2v35-w6hq-6mfw, ghsa-f6ww-3ggp-fr8h, ghsa-wh4c-j3r5-mjhp, ghsa-x6wf-f3px-wcqx, ghsa-j759-j44w-7fr8...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: sqlpad&lt;/p&gt;
&lt;p&gt;Package sqlpad version 7.5.7-r2 fixes 26 vulnerabilities: ghsa-2v35-w6hq-6mfw, ghsa-f6ww-3ggp-fr8h, ghsa-wh4c-j3r5-mjhp, ghsa-x6wf-f3px-wcqx, ghsa-j759-j44w-7fr8...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ag43501</guid>
    </item>
    <item>
      <title>EUVD-2026-293113</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-293113</link>
      <description>EUVD-2026-293113</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-293113</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41907</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41907</link>
      <description>&lt;p&gt;uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41907</guid>
    </item>
    <item>
      <title>GHSA-w5hq-g745-h8pq — uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w5hq-g745-h8pq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: uuid&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `v3()`, `v5()`, and `v6()` [API methods](https://github.com/uuidjs/uuid#api-summary) (not `uuid` release versions) accept external output buffers but do not reject out-of-range writes (small `buf` or large `offset`).  
By contrast, `v4()`, `v1()`, and `v7()` API methods explicitly throw `RangeError` on invalid bounds.&lt;/p&gt;
&lt;p&gt;This inconsistency allows **silent partial writes** into caller-provided buffers.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `src/v35.ts` (`v3()`/`v5()` path) writes `buf[offset + i]` without bounds validation.
- `src/v6.ts` writes `buf[offset + i]` without bounds validation.&lt;/p&gt;
&lt;p&gt;### Reproducible PoC&lt;/p&gt;
&lt;p&gt;```bash
cd /home/StrawHat/uuid
npm ci
npm run build&lt;/p&gt;
&lt;p&gt;node --input-type=module -e &amp;#34;
import {v4,v5,v6} from &amp;#39;./dist-node/index.js&amp;#39;;
const ns=&amp;#39;6ba7b810-9dad-11d1-80b4-00c04fd430c8&amp;#39;;
for (const [name,fn] of [
  [&amp;#39;v4()&amp;#39;,()=&amp;gt;v4({},new Uint8Array(8),4)],
  [&amp;#39;v5()&amp;#39;,()=&amp;gt;v5(&amp;#39;x&amp;#39;,ns,new Uint8Array(8),4)],
  [&amp;#39;v6()&amp;#39;,()=&amp;gt;v6({},new Uint8Array(8),4)],
]) {
  try { fn(); console.log(name,&amp;#39;NO_THROW&amp;#39;); }
  catch(e){ console.log(name,&amp;#39;THREW&amp;#39;,e.name); }
}&amp;#34;
```&lt;/p&gt;
&lt;p&gt;Observed:&lt;/p&gt;
&lt;p&gt;- `v4() THREW RangeError`
- `v5() NO_THROW`
- `v6() NO_THROW`&lt;/p&gt;
&lt;p&gt;Example partial overwrite evidence captured during audit:&lt;/p&gt;
&lt;p&gt;```text
same true buf [
  170, 170, 170, 170,
   75, 224, 100,  63
]
v6 [
  187, 187, 187, 187,
   31,  19, 185,  64
]
```&lt;/p&gt;
&lt;p&gt;### Security impact&lt;/p&gt;
&lt;p&gt;- **Primary**: integrity/robustness issue (silent partial output).
- If an application assumes full UUID writes into preallocated buffers, this can produce ma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: uuid&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `v3()`, `v5()`, and `v6()` [API methods](https://github.com/uuidjs/uuid#api-summary) (not `uuid` release versions) accept external output buffers but do not reject out-of-range writes (small `buf` or large `offset`).  
By contrast, `v4()`, `v1()`, and `v7()` API methods explicitly throw `RangeError` on invalid bounds.&lt;/p&gt;
&lt;p&gt;This inconsistency allows **silent partial writes** into caller-provided buffers.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `src/v35.ts` (`v3()`/`v5()` path) writes `buf[offset + i]` without bounds validation.
- `src/v6.ts` writes `buf[offset + i]` without bounds validation.&lt;/p&gt;
&lt;p&gt;### Reproducible PoC&lt;/p&gt;
&lt;p&gt;```bash
cd /home/StrawHat/uuid
npm ci
npm run build&lt;/p&gt;
&lt;p&gt;node --input-type=module -e &amp;#34;
import {v4,v5,v6} from &amp;#39;./dist-node/index.js&amp;#39;;
const ns=&amp;#39;6ba7b810-9dad-11d1-80b4-00c04fd430c8&amp;#39;;
for (const [name,fn] of [
  [&amp;#39;v4()&amp;#39;,()=&amp;gt;v4({},new Uint8Array(8),4)],
  [&amp;#39;v5()&amp;#39;,()=&amp;gt;v5(&amp;#39;x&amp;#39;,ns,new Uint8Array(8),4)],
  [&amp;#39;v6()&amp;#39;,()=&amp;gt;v6({},new Uint8Array(8),4)],
]) {
  try { fn(); console.log(name,&amp;#39;NO_THROW&amp;#39;); }
  catch(e){ console.log(name,&amp;#39;THREW&amp;#39;,e.name); }
}&amp;#34;
```&lt;/p&gt;
&lt;p&gt;Observed:&lt;/p&gt;
&lt;p&gt;- `v4() THREW RangeError`
- `v5() NO_THROW`
- `v6() NO_THROW`&lt;/p&gt;
&lt;p&gt;Example partial overwrite evidence captured during audit:&lt;/p&gt;
&lt;p&gt;```text
same true buf [
  170, 170, 170, 170,
   75, 224, 100,  63
]
v6 [
  187, 187, 187, 187,
   31,  19, 185,  64
]
```&lt;/p&gt;
&lt;p&gt;### Security impact&lt;/p&gt;
&lt;p&gt;- **Primary**: integrity/robustness issue (silent partial output).
- If an application assumes full UUID writes into preallocated buffers, this can produce ma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w5hq-g745-h8pq</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-41907 — uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-41907</link>
      <description>msrc_CVE-2026-41907</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-41907</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>RHSA-2026:56431 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.27 security, enhancement &amp; bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:56431</link>
      <description>&lt;p&gt;golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate js-yaml: js-yaml prototype pollution in merge react-router: React Router unexpected external redirect undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: Undici: HTTP header injection and request smuggling vulnerability undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri: fast-uri: URI authority bypass due to improper delimiter handling undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing postcss-selector-parser: Postcss: Denial of Service via uncontrolled recursion in AST Serialization undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header form-data: form-data: Form field override via CRLF injection undici: undici: Denial…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate js-yaml: js-yaml prototype pollution in merge react-router: React Router unexpected external redirect undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: Undici: HTTP header injection and request smuggling vulnerability undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri: fast-uri: URI authority bypass due to improper delimiter handling undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing postcss-selector-parser: Postcss: Denial of Service via uncontrolled recursion in AST Serialization undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header form-data: form-data: Form field override via CRLF injection undici: undici: Denial…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:56431</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-41907</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41907</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: node-uuid, Ubuntu:16.04:LTS: node-uuid, Ubuntu:18.04:LTS: node-uuid, Ubuntu:20.04:LTS: node-uuid, Ubuntu:22.04:LTS: node-uuid, Ubuntu:24.04:LTS: node-uuid, Ubuntu:25.10: node-uuid, Ubuntu:26.04:LTS: node-uuid&lt;/p&gt;
&lt;p&gt;uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: node-uuid, Ubuntu:16.04:LTS: node-uuid, Ubuntu:18.04:LTS: node-uuid, Ubuntu:20.04:LTS: node-uuid, Ubuntu:22.04:LTS: node-uuid, Ubuntu:24.04:LTS: node-uuid, Ubuntu:25.10: node-uuid, Ubuntu:26.04:LTS: node-uuid&lt;/p&gt;
&lt;p&gt;uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41907</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2112 — IBM App Connect Enterprise: Mehrere Schwachstellen ermöglichen Manipulation von Daten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2112</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2112</guid>
    </item>
  </channel>
</rss>
