<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:51:14 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0934 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0934</link>
      <description>certfr-2026-avi-0934</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0934</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-UY90963 — Security fix for CVE-2026-44496 applied in: jitsucom-jitsu 2.14.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-uy90963</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jitsucom-jitsu&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the jitsucom-jitsu package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jitsucom-jitsu&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the jitsucom-jitsu package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-uy90963</guid>
    </item>
    <item>
      <title>EUVD-2026-366766</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366766</link>
      <description>EUVD-2026-366766</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366766</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44496</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44496</link>
      <description>&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read document.cookie. This vulnerability is fixed in 0.32.0 and 1.16.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read document.cookie. This vulnerability is fixed in 0.32.0 and 1.16.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44496</guid>
    </item>
    <item>
      <title>GHSA-hfxv-24rg-xrqf — Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hfxv-24rg-xrqf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Axios versions before `0.32.0` on the `0.x` line and before `1.16.0` on the `1.x` line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads `document.cookie`.&lt;/p&gt;
&lt;p&gt;The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read `document.cookie`.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Applications are affected only when attacker-controlled data can reach the XSRF cookie name configuration or a direct/unsafe call to the internal cookie helper.&lt;/p&gt;
&lt;p&gt;This does not expose credentials, modify requests, or affect response integrity. The impact is availability only.&lt;/p&gt;
&lt;p&gt;## Affected Functionality&lt;/p&gt;
&lt;p&gt;Affected code paths:&lt;/p&gt;
&lt;p&gt;- `lib/helpers/cookies.js` `read(name)` in standard browser environments.
- `lib/helpers/resolveConfig.js` in `1.x`, when browser XHR/fetch adapters resolve XSRF config.
- `lib/adapters/xhr.js` in `0.x`, when the XHR adapter reads the configured XSRF cookie.
- Direct use of `axios/unsafe/helpers/cookies.js` in `1.x`, if callers pass attacker-controlled names.&lt;/p&gt;
&lt;p&gt;Unaffected code paths:&lt;/p&gt;
&lt;p&gt;- Default static `xsrfCookieName: &amp;#39;XSRF-TOKEN&amp;#39;` when not attacker-controlled.
- Requests with `xsrfCookieName: null`.
- Node…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Axios versions before `0.32.0` on the `0.x` line and before `1.16.0` on the `1.x` line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads `document.cookie`.&lt;/p&gt;
&lt;p&gt;The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read `document.cookie`.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Applications are affected only when attacker-controlled data can reach the XSRF cookie name configuration or a direct/unsafe call to the internal cookie helper.&lt;/p&gt;
&lt;p&gt;This does not expose credentials, modify requests, or affect response integrity. The impact is availability only.&lt;/p&gt;
&lt;p&gt;## Affected Functionality&lt;/p&gt;
&lt;p&gt;Affected code paths:&lt;/p&gt;
&lt;p&gt;- `lib/helpers/cookies.js` `read(name)` in standard browser environments.
- `lib/helpers/resolveConfig.js` in `1.x`, when browser XHR/fetch adapters resolve XSRF config.
- `lib/adapters/xhr.js` in `0.x`, when the XHR adapter reads the configured XSRF cookie.
- Direct use of `axios/unsafe/helpers/cookies.js` in `1.x`, if callers pass attacker-controlled names.&lt;/p&gt;
&lt;p&gt;Unaffected code paths:&lt;/p&gt;
&lt;p&gt;- Default static `xsrfCookieName: &amp;#39;XSRF-TOKEN&amp;#39;` when not attacker-controlled.
- Requests with `xsrfCookieName: null`.
- Node…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hfxv-24rg-xrqf</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>RHSA-2026:20889 — Red Hat Security Advisory: RHACS 4.10.3 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:20889</link>
      <description>&lt;p&gt;axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation follow-redirects: follow-redirects: Information disclosure via cross-domain redirects axios: Axios: HTTP Transport Hijacking via Prototype Pollution axios: Axios: Arbitrary HTTP header injection via prototype pollution axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling axios: Axios: NO_PROXY bypass via crafted URL axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget axios: Axios: Prototype pollution allows information disclosure and request manipulation axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution axios: Axios: Information disclosure due to prototype pollution vulnerability axios: Axios: Client-side Denial of Service via unesc…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation follow-redirects: follow-redirects: Information disclosure via cross-domain redirects axios: Axios: HTTP Transport Hijacking via Prototype Pollution axios: Axios: Arbitrary HTTP header injection via prototype pollution axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling axios: Axios: NO_PROXY bypass via crafted URL axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget axios: Axios: Prototype pollution allows information disclosure and request manipulation axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution axios: Axios: Information disclosure due to prototype pollution vulnerability axios: Axios: Client-side Denial of Service via unesc…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:20889</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-44496</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44496</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:25.10: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read document.cookie. This vulnerability is fixed in 0.32.0 and 1.16.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:25.10: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read document.cookie. This vulnerability is fixed in 0.32.0 and 1.16.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44496</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1955 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955</guid>
    </item>
  </channel>
</rss>
