<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:42:16 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0934 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0934</link>
      <description>certfr-2026-avi-0934</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0934</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-ED19767 — Security fixes in opensearch-dashboards-fips 3.6.0-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ed19767</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Package opensearch-dashboards-fips version 3.6.0-r4 fixes 7 vulnerabilities: ghsa-cmwh-pvxp-8882, CVE-2026-12143, CVE-2026-46625, CVE-2026-53550, CVE-2026-53655...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Package opensearch-dashboards-fips version 3.6.0-r4 fixes 7 vulnerabilities: ghsa-cmwh-pvxp-8882, CVE-2026-12143, CVE-2026-46625, CVE-2026-53550, CVE-2026-53655...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ed19767</guid>
    </item>
    <item>
      <title>EUVD-2026-365507</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-365507</link>
      <description>EUVD-2026-365507</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-365507</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46625</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46625</link>
      <description>&lt;p&gt;JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie&amp;#39;s internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object&amp;#39;s &amp;#34;__proto__&amp;#34; member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.__proto__ setter on the fresh target ({}). The result is a per-instance prototype hijack: Object.prototype itself is untouched, but the merged attributes object now inherits attacker-controlled keys. Because the consuming set() function then enumerates the merged object with another for...in, every key the attacker placed on the polluted prototype lands in the resulting Set-Cookie string as an attribute pair. The attacker can set domain=, secure=, samesite=, expires=, and path= on cookies whose attributes the developer thought were locked down. This issue has been patched in version 3.0.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie&amp;#39;s internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object&amp;#39;s &amp;#34;__proto__&amp;#34; member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.__proto__ setter on the fresh target ({}). The result is a per-instance prototype hijack: Object.prototype itself is untouched, but the merged attributes object now inherits attacker-controlled keys. Because the consuming set() function then enumerates the merged object with another for...in, every key the attacker placed on the polluted prototype lands in the resulting Set-Cookie string as an attribute pair. The attacker can set domain=, secure=, samesite=, expires=, and path= on cookies whose attributes the developer thought were locked down. This issue has been patched in version 3.0.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46625</guid>
    </item>
    <item>
      <title>GHSA-qjx8-664m-686j — JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qjx8-664m-686j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: js-cookie&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`js-cookie`&amp;#39;s internal `assign()` helper copies properties with `for...in` + plain assignment. When the source object is produced by `JSON.parse`, the JSON object&amp;#39;s `&amp;#34;__proto__&amp;#34;` member is an *own enumerable* property, so the `for…in` enumerates it and the `target[key] = source[key]` write triggers the **`Object.prototype.__proto__` setter** on the fresh `target` (`{}`). The result is a per-instance prototype hijack: `Object.prototype` itself is untouched, but the merged `attributes` object now inherits attacker-controlled keys.&lt;/p&gt;
&lt;p&gt;Because the consuming `set()` function then enumerates the merged object with another `for...in`, every key the attacker placed on the polluted prototype lands in the resulting `Set-Cookie` string as an attribute pair. The attacker can set `domain=`, `secure=`, `samesite=`, `expires=`, and `path=` on cookies whose attributes the developer thought were locked down.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Any application that forwards a JSON-derived object as the `attributes` argument to `Cookies.set`, `Cookies.remove`, `Cookies.withAttributes`, or `Cookies.withConverter` is vulnerable. This is the standard pattern when cookie configuration comes from a backend:&lt;/p&gt;
&lt;p&gt;```js
const cfg = await fetch(&amp;#39;/config&amp;#39;).then(r =&amp;gt; r.json());
Cookies.set(&amp;#39;session&amp;#39;, token, cfg.cookieAttrs);   // cfg.cookieAttrs influenced by attacker
```&lt;/p&gt;
&lt;p&gt;A payload of `{&amp;#34;__proto__&amp;#34;:{&amp;#34;domain&amp;#34;:&amp;#34;evil.example&amp;#34;,&amp;#34;secure&amp;#34;:&amp;#34;false&amp;#34;,&amp;#34;samesite&amp;#34;:&amp;#34;None&amp;#34;}}` causes js-cookie to emit:&lt;/p&gt;
&lt;p&gt;```
Set-Cookie: session=TOKEN; pa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: js-cookie&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`js-cookie`&amp;#39;s internal `assign()` helper copies properties with `for...in` + plain assignment. When the source object is produced by `JSON.parse`, the JSON object&amp;#39;s `&amp;#34;__proto__&amp;#34;` member is an *own enumerable* property, so the `for…in` enumerates it and the `target[key] = source[key]` write triggers the **`Object.prototype.__proto__` setter** on the fresh `target` (`{}`). The result is a per-instance prototype hijack: `Object.prototype` itself is untouched, but the merged `attributes` object now inherits attacker-controlled keys.&lt;/p&gt;
&lt;p&gt;Because the consuming `set()` function then enumerates the merged object with another `for...in`, every key the attacker placed on the polluted prototype lands in the resulting `Set-Cookie` string as an attribute pair. The attacker can set `domain=`, `secure=`, `samesite=`, `expires=`, and `path=` on cookies whose attributes the developer thought were locked down.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Any application that forwards a JSON-derived object as the `attributes` argument to `Cookies.set`, `Cookies.remove`, `Cookies.withAttributes`, or `Cookies.withConverter` is vulnerable. This is the standard pattern when cookie configuration comes from a backend:&lt;/p&gt;
&lt;p&gt;```js
const cfg = await fetch(&amp;#39;/config&amp;#39;).then(r =&amp;gt; r.json());
Cookies.set(&amp;#39;session&amp;#39;, token, cfg.cookieAttrs);   // cfg.cookieAttrs influenced by attacker
```&lt;/p&gt;
&lt;p&gt;A payload of `{&amp;#34;__proto__&amp;#34;:{&amp;#34;domain&amp;#34;:&amp;#34;evil.example&amp;#34;,&amp;#34;secure&amp;#34;:&amp;#34;false&amp;#34;,&amp;#34;samesite&amp;#34;:&amp;#34;None&amp;#34;}}` causes js-cookie to emit:&lt;/p&gt;
&lt;p&gt;```
Set-Cookie: session=TOKEN; pa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qjx8-664m-686j</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>RHSA-2026:33183 — Red Hat Security Advisory: Kiali 2.22.6 for Red Hat OpenShift Service Mesh 3.3</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:33183</link>
      <description>&lt;p&gt;form-data: form-data: Form field override via CRLF injection golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution axios: Axios: Information disclosure due to prototype pollution vulnerability axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name js-cookie: JavaScript Cookie: Cookie attribute manipulation via prototype pollution ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;form-data: form-data: Form field override via CRLF injection golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution axios: Axios: Information disclosure due to prototype pollution vulnerability axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name js-cookie: JavaScript Cookie: Cookie attribute manipulation via prototype pollution ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:33183</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-46625</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46625</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-js-cookie, Ubuntu:20.04:LTS: node-js-cookie, Ubuntu:22.04:LTS: node-js-cookie, Ubuntu:24.04:LTS: node-js-cookie, Ubuntu:25.10: node-js-cookie, Ubuntu:26.04:LTS: node-js-cookie&lt;/p&gt;
&lt;p&gt;JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie&amp;#39;s internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object&amp;#39;s &amp;#34;__proto__&amp;#34; member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.__proto__ setter on the fresh target ({}). The result is a per-instance prototype hijack: Object.prototype itself is untouched, but the merged attributes object now inherits attacker-controlled keys. Because the consuming set() function then enumerates the merged object with another for...in, every key the attacker placed on the polluted prototype lands in the resulting Set-Cookie string as an attribute pair. The attacker can set domain=, secure=, samesite=, expires=, and path= on cookies whose attributes the developer thought were locked down. This issue has been patched in version 3.0.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-js-cookie, Ubuntu:20.04:LTS: node-js-cookie, Ubuntu:22.04:LTS: node-js-cookie, Ubuntu:24.04:LTS: node-js-cookie, Ubuntu:25.10: node-js-cookie, Ubuntu:26.04:LTS: node-js-cookie&lt;/p&gt;
&lt;p&gt;JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie&amp;#39;s internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object&amp;#39;s &amp;#34;__proto__&amp;#34; member is an own enumerable property, so the for…in enumerates it and the target[key] = source[key] write triggers the Object.prototype.__proto__ setter on the fresh target ({}). The result is a per-instance prototype hijack: Object.prototype itself is untouched, but the merged attributes object now inherits attacker-controlled keys. Because the consuming set() function then enumerates the merged object with another for...in, every key the attacker placed on the polluted prototype lands in the resulting Set-Cookie string as an attribute pair. The attacker can set domain=, secure=, samesite=, expires=, and path= on cookies whose attributes the developer thought were locked down. This issue has been patched in version 3.0.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46625</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2299 — HCL BigFix: Schwachstelle ermöglicht Manipulation von Daten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2299</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in HCL BigFix ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in HCL BigFix ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2299</guid>
    </item>
  </channel>
</rss>
