<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:01:51 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0698 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0698</link>
      <description>certfr-2026-avi-0698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0698</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BE61221 — Security fixes for CVE-2025-62718, CVE-2025-69873, CVE-2026-29045, CVE-2026-29085, CVE-2026-29086, CVE-2026-29087, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the opensearch-dashboards-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the opensearch-dashboards-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221</guid>
    </item>
    <item>
      <title>EUVD-2026-366083</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366083</link>
      <description>EUVD-2026-366083</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366083</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42041</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42041</link>
      <description>&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution &amp;#34;Gadget&amp;#34; attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript&amp;#39;s in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () =&amp;gt; true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution &amp;#34;Gadget&amp;#34; attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript&amp;#39;s in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () =&amp;gt; true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42041</guid>
    </item>
    <item>
      <title>GHSA-w9j2-pvgh-6h63 — Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w9j2-pvgh-6h63</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;# Vulnerability Disclosure: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The Axios library is vulnerable to a Prototype Pollution &amp;#34;Gadget&amp;#34; attack that allows any `Object.prototype` pollution to **silently suppress all HTTP error responses** (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling.&lt;/p&gt;
&lt;p&gt;The root cause is that `validateStatus` is the **only** config property using the `mergeDirectKeys` merge strategy, which uses JavaScript&amp;#39;s `in` operator — an operator that inherently traverses the prototype chain. When `Object.prototype.validateStatus` is polluted with `() =&amp;gt; true`, all HTTP status codes are accepted as success.&lt;/p&gt;
&lt;p&gt;**Severity:** High (CVSS 8.2)
**Affected Versions:** All versions (v0.x - v1.x including v1.15.0)
**Vulnerable Component:** `lib/core/mergeConfig.js` (`mergeDirectKeys` strategy) + `lib/core/settle.js`&lt;/p&gt;
&lt;p&gt;## CWE&lt;/p&gt;
&lt;p&gt;- **CWE-1321:** Improperly Controlled Modification of Object Prototype Attributes (&amp;#39;Prototype Pollution&amp;#39;)
- **CWE-287:** Improper Authentication&lt;/p&gt;
&lt;p&gt;## CVSS 3.1&lt;/p&gt;
&lt;p&gt;**Score: 8.2 (High)**&lt;/p&gt;
&lt;p&gt;Vector: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N`&lt;/p&gt;
&lt;p&gt;| Metric | Value | Justification |
|---|---|---|
| Attack Vector | Network | PP is triggered remotely |
| Attack Complexity | Low | Once PP exists, a single property assignment exploits this. Consistent with GHSA-fvcv-3m26-pcqx |
| Privileges Required | None | No au…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;# Vulnerability Disclosure: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The Axios library is vulnerable to a Prototype Pollution &amp;#34;Gadget&amp;#34; attack that allows any `Object.prototype` pollution to **silently suppress all HTTP error responses** (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling.&lt;/p&gt;
&lt;p&gt;The root cause is that `validateStatus` is the **only** config property using the `mergeDirectKeys` merge strategy, which uses JavaScript&amp;#39;s `in` operator — an operator that inherently traverses the prototype chain. When `Object.prototype.validateStatus` is polluted with `() =&amp;gt; true`, all HTTP status codes are accepted as success.&lt;/p&gt;
&lt;p&gt;**Severity:** High (CVSS 8.2)
**Affected Versions:** All versions (v0.x - v1.x including v1.15.0)
**Vulnerable Component:** `lib/core/mergeConfig.js` (`mergeDirectKeys` strategy) + `lib/core/settle.js`&lt;/p&gt;
&lt;p&gt;## CWE&lt;/p&gt;
&lt;p&gt;- **CWE-1321:** Improperly Controlled Modification of Object Prototype Attributes (&amp;#39;Prototype Pollution&amp;#39;)
- **CWE-287:** Improper Authentication&lt;/p&gt;
&lt;p&gt;## CVSS 3.1&lt;/p&gt;
&lt;p&gt;**Score: 8.2 (High)**&lt;/p&gt;
&lt;p&gt;Vector: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N`&lt;/p&gt;
&lt;p&gt;| Metric | Value | Justification |
|---|---|---|
| Attack Vector | Network | PP is triggered remotely |
| Attack Complexity | Low | Once PP exists, a single property assignment exploits this. Consistent with GHSA-fvcv-3m26-pcqx |
| Privileges Required | None | No au…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w9j2-pvgh-6h63</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20919-1 — Security update for agama-web-ui</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20919-1</link>
      <description>&lt;p&gt;Security update for agama-web-ui&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for agama-web-ui&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20919-1</guid>
    </item>
    <item>
      <title>RHSA-2026:14937 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:14937</link>
      <description>&lt;p&gt;axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option axios: Axios: Remote Code Execution via Prototype Pollution escalation follow-redirects: follow-redirects: Information disclosure via cross-domain redirects axios: Axios: HTTP Transport Hijacking via Prototype Pollution axios: Axios: Arbitrary HTTP header injection via prototype pollution axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling axi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option axios: Axios: Remote Code Execution via Prototype Pollution escalation follow-redirects: follow-redirects: Information disclosure via cross-domain redirects axios: Axios: HTTP Transport Hijacking via Prototype Pollution axios: Axios: Arbitrary HTTP header injection via prototype pollution axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling axi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:14937</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-42041</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42041</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:25.10: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution &amp;#34;Gadget&amp;#34; attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript&amp;#39;s in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () =&amp;gt; true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:25.10: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution &amp;#34;Gadget&amp;#34; attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript&amp;#39;s in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () =&amp;gt; true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42041</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1450 — IBM App Connect Enterprise (Axios): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1450</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, wodurch weitere Angriffe möglich werden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, wodurch weitere Angriffe möglich werden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1450</guid>
    </item>
  </channel>
</rss>
