<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:10:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-357984</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357984</link>
      <description>EUVD-2026-357984</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357984</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42570</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42570</link>
      <description>&lt;p&gt;Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn&amp;#39;t sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption. This issue has been patched in version 5.8.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn&amp;#39;t sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption. This issue has been patched in version 5.8.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42570</guid>
    </item>
    <item>
      <title>GHSA-77vg-94rm-hx3p — Svelte devalue: DoS via sparse array deserialization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-77vg-94rm-hx3p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: devalue&lt;/p&gt;
&lt;p&gt;`devalue.parse` could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: devalue&lt;/p&gt;
&lt;p&gt;`devalue.parse` could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-77vg-94rm-hx3p</guid>
    </item>
    <item>
      <title>RHSA-2026:37272 — Red Hat Security Advisory: RHTAS 1.4.2 - Red Hat Trusted Artifact Signer Release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:37272</link>
      <description>&lt;p&gt;image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images. golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API devalue: devalue: Excessive memory consumption via deserialization of sparse arrays next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js: Next.js: Authorization bypass via crafted query parameters next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js: Next.js: Denial of Service via Image Optimization API Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests next.js: Next.js: Denial of Service via crafted POST requests to server actions next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images. golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API devalue: devalue: Excessive memory consumption via deserialization of sparse arrays next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js: Next.js: Authorization bypass via crafted query parameters next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js: Next.js: Denial of Service via Image Optimization API Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests next.js: Next.js: Denial of Service via crafted POST requests to server actions next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:37272</guid>
    </item>
  </channel>
</rss>
