<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:40:18 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0773 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0773</link>
      <description>certfr-2026-avi-0773</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0773</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-GE92046 — Security fix for CVE-2026-45149 applied in: npm 11.14.0-r0, pulumi 3.248.0-r0, renovate 44.31.0-r1, renovate 44.32.4-r1…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ge92046</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: npm, CleanStart: pulumi, CleanStart: renovate&lt;/p&gt;
&lt;p&gt;CVE-2026-45149 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: npm, CleanStart: pulumi, CleanStart: renovate&lt;/p&gt;
&lt;p&gt;CVE-2026-45149 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ge92046</guid>
    </item>
    <item>
      <title>EUVD-2026-323516</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323516</link>
      <description>EUVD-2026-323516</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323516</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45149</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45149</link>
      <description>&lt;p&gt;The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate elements before the max limit is applied With max=10, the output is correctly limited to 10 items, but the process still allocates ~505 MB and spends ~800ms building the full intermediate array. This vulnerability is fixed in 5.0.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate elements before the max limit is applied With max=10, the output is correctly limited to 10 items, but the process still allocates ~505 MB and spends ~800ms building the full intermediate array. This vulnerability is fixed in 5.0.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45149</guid>
    </item>
    <item>
      <title>GHSA-jxxr-4gwj-5jf2 — brace-expansion: Large numeric range defeats documented `max` DoS protection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jxxr-4gwj-5jf2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: brace-expansion&lt;/p&gt;
&lt;p&gt;The `max` option was being applied too late:&lt;/p&gt;
&lt;p&gt;When expanding a single large numeric range like `{1..10000000}`, the sequence generation loop generates all 10 million intermediate elements before the `max` limit is applied With `max=10`, the output is correctly limited to 10 items, but the process still allocates `~505 MB` and spends `~800ms` building the full intermediate array.&lt;/p&gt;
&lt;p&gt;### Workaround&lt;/p&gt;
&lt;p&gt;Ensure the string to be expanded doesn&amp;#39;t contain more values than the desired `max` item count.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: brace-expansion&lt;/p&gt;
&lt;p&gt;The `max` option was being applied too late:&lt;/p&gt;
&lt;p&gt;When expanding a single large numeric range like `{1..10000000}`, the sequence generation loop generates all 10 million intermediate elements before the `max` limit is applied With `max=10`, the output is correctly limited to 10 items, but the process still allocates `~505 MB` and spends `~800ms` building the full intermediate array.&lt;/p&gt;
&lt;p&gt;### Workaround&lt;/p&gt;
&lt;p&gt;Ensure the string to be expanded doesn&amp;#39;t contain more values than the desired `max` item count.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jxxr-4gwj-5jf2</guid>
    </item>
    <item>
      <title>RHSA-2026:13874 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13874</link>
      <description>&lt;p&gt;brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13874</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-45149</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45149</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:25.10: node-brace-expansion, Ubuntu:26.04:LTS: node-brace-expansion&lt;/p&gt;
&lt;p&gt;The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate elements before the max limit is applied With max=10, the output is correctly limited to 10 items, but the process still allocates ~505 MB and spends ~800ms building the full intermediate array. This vulnerability is fixed in 5.0.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:25.10: node-brace-expansion, Ubuntu:26.04:LTS: node-brace-expansion&lt;/p&gt;
&lt;p&gt;The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate elements before the max limit is applied With max=10, the output is correctly limited to 10 items, but the process still allocates ~505 MB and spends ~800ms building the full intermediate array. This vulnerability is fixed in 5.0.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45149</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1955 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955</guid>
    </item>
  </channel>
</rss>
