<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:32:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09107</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09107</link>
      <description>bdu:2026-09107</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09107</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0788 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</link>
      <description>certfr-2026-avi-0788</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-FR90298 — Security fix for CVE-2026-44289 applied in: azure-functions-node 4.1052.200-r0, jitsucom-jitsu 2.14.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fr90298</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: azure-functions-node, CleanStart: jitsucom-jitsu&lt;/p&gt;
&lt;p&gt;CVE-2026-44289 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: azure-functions-node, CleanStart: jitsucom-jitsu&lt;/p&gt;
&lt;p&gt;CVE-2026-44289 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fr90298</guid>
    </item>
    <item>
      <title>EUVD-2026-361082</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361082</link>
      <description>EUVD-2026-361082</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361082</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44289</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44289</link>
      <description>&lt;p&gt;protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44289</guid>
    </item>
    <item>
      <title>GHSA-685m-2w69-288q — protobuf.js: Denial of service through unbounded protobuf recursion</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-685m-2w69-288q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: protobufjs&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields.&lt;/p&gt;
&lt;p&gt;A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can provide protobuf binary data decoded by an application may be able to crash the process or otherwise cause decoding to fail with a stack overflow.&lt;/p&gt;
&lt;p&gt;This affects applications that decode untrusted protobuf binary input with affected versions.&lt;/p&gt;
&lt;p&gt;## Preconditions&lt;/p&gt;
&lt;p&gt;- The application must decode protobuf binary data influenced by an attacker.
- The crafted input must contain deeply nested protobuf structures, such as nested group tags or nested message fields.
- The affected decoder path must process the crafted input.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Avoid decoding untrusted protobuf binary data with affected versions. If immediate upgrade is not possible, reject excessively nested messages at an outer protocol boundary where feasible, or isolate protobuf decoding in a process that can be safely restarted.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: protobufjs&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields.&lt;/p&gt;
&lt;p&gt;A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can provide protobuf binary data decoded by an application may be able to crash the process or otherwise cause decoding to fail with a stack overflow.&lt;/p&gt;
&lt;p&gt;This affects applications that decode untrusted protobuf binary input with affected versions.&lt;/p&gt;
&lt;p&gt;## Preconditions&lt;/p&gt;
&lt;p&gt;- The application must decode protobuf binary data influenced by an attacker.
- The crafted input must contain deeply nested protobuf structures, such as nested group tags or nested message fields.
- The affected decoder path must process the crafted input.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Avoid decoding untrusted protobuf binary data with affected versions. If immediate upgrade is not possible, reject excessively nested messages at an outer protocol boundary where feasible, or isolate protobuf decoding in a process that can be safely restarted.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-685m-2w69-288q</guid>
    </item>
    <item>
      <title>RHSA-2026:42815 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:42815</link>
      <description>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decoding protobufjs: protobufjs: Denial of Service via crafted schema protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution protobufjs: protobufjs: Data integrity impact due to prototype pollution protobufjs: protobufjs: Denial of Service via crafted JSON descriptors linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution tar: node-tar: Denial of Service via crafted gzip bomb tar: Node-tar: Denial of Service via malformed tar archive header&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decoding protobufjs: protobufjs: Denial of Service via crafted schema protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution protobufjs: protobufjs: Data integrity impact due to prototype pollution protobufjs: protobufjs: Denial of Service via crafted JSON descriptors linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution tar: node-tar: Denial of Service via crafted gzip bomb tar: Node-tar: Denial of Service via malformed tar archive header&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:42815</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2452 — Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, DOMPurify): Mehrere S…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</guid>
    </item>
  </channel>
</rss>
