<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:51:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-326908</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326908</link>
      <description>EUVD-2026-326908</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326908</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47139</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47139</link>
      <description>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to http, https, http2, net, dgram, tls, dns, and dns/promises is blocked. However, Node.js also exposes underscored internal HTTP builtins such as _http_client and _http_server. These are not blocked when the public modules are excluded. Sandboxed code can use these internal builtins to make outbound HTTP requests and open listening HTTP sockets even though the public network modules are denied. This issue has been patched in version 3.11.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to http, https, http2, net, dgram, tls, dns, and dns/promises is blocked. However, Node.js also exposes underscored internal HTTP builtins such as _http_client and _http_server. These are not blocked when the public modules are excluded. Sandboxed code can use these internal builtins to make outbound HTTP requests and open listening HTTP sockets even though the public network modules are denied. This issue has been patched in version 3.11.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47139</guid>
    </item>
    <item>
      <title>GHSA-r9pm-gxmw-wv6p — NodeVM network builtin exclusions bypass via internal _http_client and _http_server</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r9pm-gxmw-wv6p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`NodeVM` supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to `http`, `https`, `http2`, `net`, `dgram`, `tls`, `dns`, and `dns/promises` is blocked.&lt;/p&gt;
&lt;p&gt;However, Node.js also exposes underscored internal HTTP builtins such as `_http_client` and `_http_server`. These are not blocked when the public modules are excluded.&lt;/p&gt;
&lt;p&gt;Sandboxed code can use these internal builtins to make outbound HTTP requests and open listening HTTP sockets even though the public network modules are denied.&lt;/p&gt;
&lt;p&gt;**Note**: This is not host RCE. It is a network capability bypass that can lead to SSRF-style access to internal services.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The wildcard builtin expansion is based on Node.js builtin module names:&lt;/p&gt;
&lt;p&gt;```js
const BUILTIN_MODULES = (nmod.builtinModules || Object.getOwnPropertyNames(process.binding(&amp;#39;natives&amp;#39;)))
  .filter(s=&amp;gt;!s.startsWith(&amp;#39;internal/&amp;#39;) &amp;amp;&amp;amp; !DANGEROUS_BUILTINS.has(s));
```&lt;/p&gt;
&lt;p&gt;Public modules can be excluded with `-name`:&lt;/p&gt;
&lt;p&gt;```js
if (builtins.indexOf(`-${name}`) === -1) {
  addDefaultBuiltin(res, name, hostRequire);
}
```&lt;/p&gt;
&lt;p&gt;But excluding `http` and `net` does not exclude internal siblings such as:&lt;/p&gt;
&lt;p&gt;```text
_http_client
_http_server
_tls_wrap
```&lt;/p&gt;
&lt;p&gt;These internal modules expose network primitives.&lt;/p&gt;
&lt;p&gt;Confirmed examples:&lt;/p&gt;
&lt;p&gt;1. `require(&amp;#39;_http_client&amp;#39;).ClientRequest(...)` performs an outbound HTTP request to a host-local service while `http` and `net` are blocked.
2. `require(&amp;#39;_http_server&amp;#39;).Server(...).listen(...)` opens…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`NodeVM` supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to `http`, `https`, `http2`, `net`, `dgram`, `tls`, `dns`, and `dns/promises` is blocked.&lt;/p&gt;
&lt;p&gt;However, Node.js also exposes underscored internal HTTP builtins such as `_http_client` and `_http_server`. These are not blocked when the public modules are excluded.&lt;/p&gt;
&lt;p&gt;Sandboxed code can use these internal builtins to make outbound HTTP requests and open listening HTTP sockets even though the public network modules are denied.&lt;/p&gt;
&lt;p&gt;**Note**: This is not host RCE. It is a network capability bypass that can lead to SSRF-style access to internal services.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The wildcard builtin expansion is based on Node.js builtin module names:&lt;/p&gt;
&lt;p&gt;```js
const BUILTIN_MODULES = (nmod.builtinModules || Object.getOwnPropertyNames(process.binding(&amp;#39;natives&amp;#39;)))
  .filter(s=&amp;gt;!s.startsWith(&amp;#39;internal/&amp;#39;) &amp;amp;&amp;amp; !DANGEROUS_BUILTINS.has(s));
```&lt;/p&gt;
&lt;p&gt;Public modules can be excluded with `-name`:&lt;/p&gt;
&lt;p&gt;```js
if (builtins.indexOf(`-${name}`) === -1) {
  addDefaultBuiltin(res, name, hostRequire);
}
```&lt;/p&gt;
&lt;p&gt;But excluding `http` and `net` does not exclude internal siblings such as:&lt;/p&gt;
&lt;p&gt;```text
_http_client
_http_server
_tls_wrap
```&lt;/p&gt;
&lt;p&gt;These internal modules expose network primitives.&lt;/p&gt;
&lt;p&gt;Confirmed examples:&lt;/p&gt;
&lt;p&gt;1. `require(&amp;#39;_http_client&amp;#39;).ClientRequest(...)` performs an outbound HTTP request to a host-local service while `http` and `net` are blocked.
2. `require(&amp;#39;_http_server&amp;#39;).Server(...).listen(...)` opens…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r9pm-gxmw-wv6p</guid>
    </item>
    <item>
      <title>RHSA-2026:33574 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.6 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:33574</link>
      <description>&lt;p&gt;shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators json-2-csv: json-2-csv: CSV Injection vulnerability allows arbitrary code execution via `preventCsvInjection` bypass. crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME net/mail: golang: Go net/mail: Denial of Service via crafted email inputs axios: Axios: HTTP Transport Hijacking via Prototype Pollution axios: Axios: Arbitrary HTTP header injection via prototype pollution axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling axios: Axios: NO_PROXY bypass via crafted URL axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input net/mail: golang: net/mail: Denial of Service via pathological email address parsing axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators json-2-csv: json-2-csv: CSV Injection vulnerability allows arbitrary code execution via `preventCsvInjection` bypass. crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME net/mail: golang: Go net/mail: Denial of Service via crafted email inputs axios: Axios: HTTP Transport Hijacking via Prototype Pollution axios: Axios: Arbitrary HTTP header injection via prototype pollution axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling axios: Axios: NO_PROXY bypass via crafted URL axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input net/mail: golang: net/mail: Denial of Service via pathological email address parsing axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:33574</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1583 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1583</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1583</guid>
    </item>
  </channel>
</rss>
