<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:33:26 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0788 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</link>
      <description>certfr-2026-avi-0788</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AZ83054 — Security fix for CVE-2026-45740 applied in: azure-functions-node 4.1052.200-r0, jitsucom-jitsu 2.14.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-az83054</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: azure-functions-node, CleanStart: jitsucom-jitsu&lt;/p&gt;
&lt;p&gt;CVE-2026-45740 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: azure-functions-node, CleanStart: jitsucom-jitsu&lt;/p&gt;
&lt;p&gt;CVE-2026-45740 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-az83054</guid>
    </item>
    <item>
      <title>EUVD-2026-318167</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318167</link>
      <description>EUVD-2026-318167</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318167</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45740</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45740</link>
      <description>&lt;p&gt;protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading. This vulnerability is fixed in 7.5.8 and 8.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading. This vulnerability is fixed in 7.5.8 and 8.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45740</guid>
    </item>
    <item>
      <title>GHSA-jggg-4jg4-v7c6 — protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jggg-4jg4-v7c6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: protobufjs&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;protobufjs could recurse without a depth limit while expanding nested JSON descriptors through `Root.fromJSON()` and `Namespace.addJSON()`.&lt;/p&gt;
&lt;p&gt;A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can provide JSON descriptors loaded by an application may be able to crash the process or otherwise cause schema loading to fail with a stack overflow.&lt;/p&gt;
&lt;p&gt;This affects applications that load JSON descriptors from untrusted sources with affected versions.&lt;/p&gt;
&lt;p&gt;## Preconditions&lt;/p&gt;
&lt;p&gt;- The application must load JSON descriptor data influenced by an attacker.
- The crafted descriptor must contain deeply nested `nested` namespace objects.
- The affected `Root.fromJSON()` / `Namespace.addJSON()` descriptor expansion path must process the crafted input.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Avoid loading untrusted protobuf JSON descriptors with affected versions. If immediate upgrade is not possible, reject excessively nested descriptor structures at an outer validation boundary where feasible, or isolate descriptor loading in a process that can be safely restarted.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: protobufjs&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;protobufjs could recurse without a depth limit while expanding nested JSON descriptors through `Root.fromJSON()` and `Namespace.addJSON()`.&lt;/p&gt;
&lt;p&gt;A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can provide JSON descriptors loaded by an application may be able to crash the process or otherwise cause schema loading to fail with a stack overflow.&lt;/p&gt;
&lt;p&gt;This affects applications that load JSON descriptors from untrusted sources with affected versions.&lt;/p&gt;
&lt;p&gt;## Preconditions&lt;/p&gt;
&lt;p&gt;- The application must load JSON descriptor data influenced by an attacker.
- The crafted descriptor must contain deeply nested `nested` namespace objects.
- The affected `Root.fromJSON()` / `Namespace.addJSON()` descriptor expansion path must process the crafted input.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Avoid loading untrusted protobuf JSON descriptors with affected versions. If immediate upgrade is not possible, reject excessively nested descriptor structures at an outer validation boundary where feasible, or isolate descriptor loading in a process that can be safely restarted.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jggg-4jg4-v7c6</guid>
    </item>
    <item>
      <title>RHSA-2026:41929 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.7 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:41929</link>
      <description>&lt;p&gt;undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy form-data: form-data: Form field override via CRLF injection undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header opentelemetry-js: opentelemetry/exporter-prometheus: opentelemetry-js: Denial of Service via malformed HTTP request protobufjs: protobufjs: Denial of Service via crafted JSON descriptors&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy form-data: form-data: Form field override via CRLF injection undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header opentelemetry-js: opentelemetry/exporter-prometheus: opentelemetry-js: Denial of Service via malformed HTTP request protobufjs: protobufjs: Denial of Service via crafted JSON descriptors&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:41929</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2452 — Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, DOMPurify): Mehrere S…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</guid>
    </item>
  </channel>
</rss>
