<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:06:53 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-339298</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339298</link>
      <description>EUVD-2026-339298</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339298</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45820</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45820</link>
      <description>&lt;p&gt;fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces to 0, keeping the loop condition permanently true.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces to 0, keeping the loop condition permanently true.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45820</guid>
    </item>
    <item>
      <title>GHSA-px8p-9vwx-vf98 — fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-px8p-9vwx-vf98</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fflate&lt;/p&gt;
&lt;p&gt;fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces to 0, keeping the loop condition permanently true.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fflate&lt;/p&gt;
&lt;p&gt;fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces to 0, keeping the loop condition permanently true.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-px8p-9vwx-vf98</guid>
    </item>
    <item>
      <title>RHSA-2026:68690 — Red Hat Security Advisory: Kiali 2.22.10 for Red Hat OpenShift Service Mesh 3.3</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:68690</link>
      <description>&lt;p&gt;encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal fflate: fflate: Denial of Service via crafted ZIP archives net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal fflate: fflate: Denial of Service via crafted ZIP archives net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:68690</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
