<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:04:32 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09331</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09331</link>
      <description>bdu:2026-09331</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09331</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0773 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0773</link>
      <description>certfr-2026-avi-0773</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0773</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-OF42288 — Security fix for CVE-2026-45736 applied in: argo-workflows 3.6.19-r8, argo-workflows 3.7.15-r3</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-of42288</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;CVE-2026-45736 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;CVE-2026-45736 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-of42288</guid>
    </item>
    <item>
      <title>EUVD-2026-366764</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366764</link>
      <description>EUVD-2026-366764</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366764</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45736</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45736</link>
      <description>&lt;p&gt;ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45736</guid>
    </item>
    <item>
      <title>GHSA-58qx-3vcg-4xpx — ws: Uninitialized memory disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-58qx-3vcg-4xpx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ws&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The `websocket.close()` implementation is vulnerable to uninitialized memory disclosure when a `TypedArray` is passed as the reason argument.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```js
import { deepStrictEqual } from &amp;#39;node:assert&amp;#39;;
import { WebSocket, WebSocketServer } from &amp;#39;ws&amp;#39;;&lt;/p&gt;
&lt;p&gt;const wss = new WebSocketServer(
  { port: 0, skipUTF8Validation: true },
  function () {
    const { port } = wss.address();
    const ws = new WebSocket(`ws://localhost:${port}`, {
      skipUTF8Validation: true
    });&lt;/p&gt;
&lt;p&gt;ws.on(&amp;#39;close&amp;#39;, function (code, reason) {
      deepStrictEqual(reason, Buffer.alloc(80));
    });
  }
);&lt;/p&gt;
&lt;p&gt;wss.on(&amp;#39;connection&amp;#39;, function (ws) {
  ws.close(1000, new Float32Array(20));
});
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The vulnerability was fixed in ws@8.20.1 (https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086).&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Credit for the private and responsible disclosure of this issue goes to [Nikita Skovoroda](https://github.com/ChALkeR).&lt;/p&gt;
&lt;p&gt;### Remarks&lt;/p&gt;
&lt;p&gt;Although the calculated CVSS severity is medium, the actual severity is believed to be low, as the flaw is only exploitable through misuse that is unlikely in practice.&lt;/p&gt;
&lt;p&gt;### Resources&lt;/p&gt;
&lt;p&gt;- https://github.com/advisories/GHSA-58qx-3vcg-4xpx
- https://www.cve.org/CVERecord?id=CVE-2026-45736&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ws&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The `websocket.close()` implementation is vulnerable to uninitialized memory disclosure when a `TypedArray` is passed as the reason argument.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```js
import { deepStrictEqual } from &amp;#39;node:assert&amp;#39;;
import { WebSocket, WebSocketServer } from &amp;#39;ws&amp;#39;;&lt;/p&gt;
&lt;p&gt;const wss = new WebSocketServer(
  { port: 0, skipUTF8Validation: true },
  function () {
    const { port } = wss.address();
    const ws = new WebSocket(`ws://localhost:${port}`, {
      skipUTF8Validation: true
    });&lt;/p&gt;
&lt;p&gt;ws.on(&amp;#39;close&amp;#39;, function (code, reason) {
      deepStrictEqual(reason, Buffer.alloc(80));
    });
  }
);&lt;/p&gt;
&lt;p&gt;wss.on(&amp;#39;connection&amp;#39;, function (ws) {
  ws.close(1000, new Float32Array(20));
});
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The vulnerability was fixed in ws@8.20.1 (https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086).&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Credit for the private and responsible disclosure of this issue goes to [Nikita Skovoroda](https://github.com/ChALkeR).&lt;/p&gt;
&lt;p&gt;### Remarks&lt;/p&gt;
&lt;p&gt;Although the calculated CVSS severity is medium, the actual severity is believed to be low, as the flaw is only exploitable through misuse that is unlikely in practice.&lt;/p&gt;
&lt;p&gt;### Resources&lt;/p&gt;
&lt;p&gt;- https://github.com/advisories/GHSA-58qx-3vcg-4xpx
- https://www.cve.org/CVERecord?id=CVE-2026-45736&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-58qx-3vcg-4xpx</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-45736 — ws: Uninitialized memory disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-45736</link>
      <description>msrc_CVE-2026-45736</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-45736</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11705-1 — kimi-code-0.41.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11705-1</link>
      <description>&lt;p&gt;kimi-code-0.41.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kimi-code-0.41.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11705-1</guid>
    </item>
    <item>
      <title>RHSA-2026:26638 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:26638</link>
      <description>&lt;p&gt;dotnet: .NET: Local file tampering via link following vulnerability dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass dotnet: .NET Framework: Denial of Service via improper input validation dotnet: .NET: Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local tampering via improper link resolution dotnet: .NET Framework: Denial of Service via network-based buffer overflow dotnet: .NET: Security feature bypass due to incorrect authorization dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM .NET: .NET: Network Spoofing Vulnerability ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation dotnet: .NET Core: Denial of Service via type confusion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: .NET: Local file tampering via link following vulnerability dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass dotnet: .NET Framework: Denial of Service via improper input validation dotnet: .NET: Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local tampering via improper link resolution dotnet: .NET Framework: Denial of Service via network-based buffer overflow dotnet: .NET: Security feature bypass due to incorrect authorization dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM .NET: .NET: Network Spoofing Vulnerability ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation dotnet: .NET Core: Denial of Service via type confusion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:26638</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-45736</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45736</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-ws, Ubuntu:18.04:LTS: node-ws, Ubuntu:20.04:LTS: node-ws, Ubuntu:22.04:LTS: node-ws, Ubuntu:24.04:LTS: node-ws, Ubuntu:25.10: node-ws, Ubuntu:26.04:LTS: node-ws&lt;/p&gt;
&lt;p&gt;ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-ws, Ubuntu:18.04:LTS: node-ws, Ubuntu:20.04:LTS: node-ws, Ubuntu:22.04:LTS: node-ws, Ubuntu:24.04:LTS: node-ws, Ubuntu:25.10: node-ws, Ubuntu:26.04:LTS: node-ws&lt;/p&gt;
&lt;p&gt;ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45736</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1955 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1955</guid>
    </item>
  </channel>
</rss>
