<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:36:19 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0773 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0773</link>
      <description>certfr-2026-avi-0773</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0773</guid>
    </item>
    <item>
      <title>EUVD-2026-324318</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-324318</link>
      <description>EUVD-2026-324318</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-324318</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42342</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42342</link>
      <description>&lt;p&gt;React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework Mode applications as well as Remix applications. This does not impact applications using Declarative Mode (`&amp;lt;BrowserRouter&amp;gt;`) or Data Mode (`createBrowserRouter/&amp;lt;RouterProvider&amp;gt;`). This is patched in react-router version 7.15.0 and @remix-run/server-runtime version 2.17.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework Mode applications as well as Remix applications. This does not impact applications using Declarative Mode (`&amp;lt;BrowserRouter&amp;gt;`) or Data Mode (`createBrowserRouter/&amp;lt;RouterProvider&amp;gt;`). This is patched in react-router version 7.15.0 and @remix-run/server-runtime version 2.17.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42342</guid>
    </item>
    <item>
      <title>GHSA-8x6r-g9mw-2r78 — React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8x6r-g9mw-2r78</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: react-router, npm: @remix-run/server-runtime&lt;/p&gt;
&lt;p&gt;There exists a potential DOS attack vector in React Router Framework Mode applications (as well as Remix v2.10.0 - 2.17.4).  Certain requests can be crafted to consume disproportionate resources on the server, resulting in response time degredation and/or service unavailability for end users.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; This does not impact your React Router application if you are using [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`&amp;lt;BrowserRouter&amp;gt;`) or [Data Mode](https://reactrouter.com/start/modes#data) (`createBrowserRouter`/`&amp;lt;RouterProvider&amp;gt;`).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: react-router, npm: @remix-run/server-runtime&lt;/p&gt;
&lt;p&gt;There exists a potential DOS attack vector in React Router Framework Mode applications (as well as Remix v2.10.0 - 2.17.4).  Certain requests can be crafted to consume disproportionate resources on the server, resulting in response time degredation and/or service unavailability for end users.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; This does not impact your React Router application if you are using [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`&amp;lt;BrowserRouter&amp;gt;`) or [Data Mode](https://reactrouter.com/start/modes#data) (`createBrowserRouter`/`&amp;lt;RouterProvider&amp;gt;`).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8x6r-g9mw-2r78</guid>
    </item>
    <item>
      <title>RHSA-2026:41951 — Red Hat Security Advisory: Red Hat Data Grid 8.6.2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:41951</link>
      <description>&lt;p&gt;fast-uri: fast-uri: URI authority bypass due to improper delimiter handling webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration form-data: form-data: Form field override via CRLF injection react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode axios: Axios: Prototype pollution allows information disclosure and request manipulation react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 he…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-uri: fast-uri: URI authority bypass due to improper delimiter handling webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration form-data: form-data: Form field override via CRLF injection react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode axios: Axios: Prototype pollution allows information disclosure and request manipulation react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 he…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:41951</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1955 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955</guid>
    </item>
  </channel>
</rss>
