<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:51:11 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-08998</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-08998</link>
      <description>bdu:2026-08998</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-08998</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-GA82552 — Babel is a compiler for writing next generation JavaScript</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ga82552</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. Babel is a compiler for writing next generation JavaScript.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. Babel is a compiler for writing next generation JavaScript.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ga82552</guid>
    </item>
    <item>
      <title>EUVD-2026-322304</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322304</link>
      <description>EUVD-2026-322304</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322304</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44728</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44728</link>
      <description>&lt;p&gt;Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44728</guid>
    </item>
    <item>
      <title>GHSA-fv7c-fp4j-7gwp — @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fv7c-fp4j-7gwp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @babel/plugin-transform-modules-systemjs&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code.&lt;/p&gt;
&lt;p&gt;Known affected plugins are:
- `@babel/plugin-transform-modules-systemjs`
- `@babel/preset-env` when using the [`modules: &amp;#34;systemjs&amp;#34;` option](https://babel.dev/docs/babel-preset-env#modules), as it delegates to `@babel/plugin-transform-modules-systemjs`&lt;/p&gt;
&lt;p&gt;No other plugins under the `@babel` namespace are impacted.&lt;/p&gt;
&lt;p&gt;**Users that only compile trusted code are not impacted.**&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The vulnerability has been fixed in `@babel/plugin-transform-modules-systemjs@7.29.4`.&lt;/p&gt;
&lt;p&gt;Babel also released `@babel/preset-env@7.29.5`, updating its `@babel/plugin-transform-modules-systemjs` dependency, to simplify forcing the update if you are using `@babel/preset-env` directly.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;- Pin `@babel/parser` to v7.11.5. The downgrade will completely disable string module name parsing, but it would also disable other new language features and the build pipeline may fail as a result. Only do so if you are working on a legacy codebase and can not upgrade `@babel/plugin-transform-modules-systemjs` to v7.29.4.
- Do not use the `modules: &amp;#34;systemjs&amp;#34;` option, migrate the codebase to native ES Modules or any other module formats.&lt;/p&gt;
&lt;p&gt;### Credits
Babel thanks Daniel Cervera for reporting the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @babel/plugin-transform-modules-systemjs&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code.&lt;/p&gt;
&lt;p&gt;Known affected plugins are:
- `@babel/plugin-transform-modules-systemjs`
- `@babel/preset-env` when using the [`modules: &amp;#34;systemjs&amp;#34;` option](https://babel.dev/docs/babel-preset-env#modules), as it delegates to `@babel/plugin-transform-modules-systemjs`&lt;/p&gt;
&lt;p&gt;No other plugins under the `@babel` namespace are impacted.&lt;/p&gt;
&lt;p&gt;**Users that only compile trusted code are not impacted.**&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The vulnerability has been fixed in `@babel/plugin-transform-modules-systemjs@7.29.4`.&lt;/p&gt;
&lt;p&gt;Babel also released `@babel/preset-env@7.29.5`, updating its `@babel/plugin-transform-modules-systemjs` dependency, to simplify forcing the update if you are using `@babel/preset-env` directly.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;- Pin `@babel/parser` to v7.11.5. The downgrade will completely disable string module name parsing, but it would also disable other new language features and the build pipeline may fail as a result. Only do so if you are working on a legacy codebase and can not upgrade `@babel/plugin-transform-modules-systemjs` to v7.29.4.
- Do not use the `modules: &amp;#34;systemjs&amp;#34;` option, migrate the codebase to native ES Modules or any other module formats.&lt;/p&gt;
&lt;p&gt;### Credits
Babel thanks Daniel Cervera for reporting the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fv7c-fp4j-7gwp</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-44728</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44728</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-babel7, Ubuntu:24.04:LTS: node-babel7, Ubuntu:25.10: node-babel7, Ubuntu:26.04:LTS: node-babel7&lt;/p&gt;
&lt;p&gt;Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-babel7, Ubuntu:24.04:LTS: node-babel7, Ubuntu:25.10: node-babel7, Ubuntu:26.04:LTS: node-babel7&lt;/p&gt;
&lt;p&gt;Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44728</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3046 — IBM Concert: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</guid>
    </item>
  </channel>
</rss>
