<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:39:24 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:35841 — Important: nodejs24 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:35841</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: nodejs24, AlmaLinux:10: nodejs24-devel, AlmaLinux:10: nodejs24-docs, AlmaLinux:10: nodejs24-full-i18n, AlmaLinux:10: nodejs24-libs, AlmaLinux:10: nodejs24-npm&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
  * undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
  * undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)
  * undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)
  * undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)
  * undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)
  * undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)
  * nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)
  * nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)
  * nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)
  * nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: nodejs24, AlmaLinux:10: nodejs24-devel, AlmaLinux:10: nodejs24-docs, AlmaLinux:10: nodejs24-full-i18n, AlmaLinux:10: nodejs24-libs, AlmaLinux:10: nodejs24-npm&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
  * undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
  * undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)
  * undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)
  * undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)
  * undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)
  * undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)
  * nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)
  * nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)
  * nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)
  * nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:35841</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-48618</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-48618</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: nodejs, Alpaquita:stream: nodejs, BellSoft Hardened Containers:25: nodejs, BellSoft Hardened Containers:stream: nodejs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: nodejs, Alpaquita:stream: nodejs, BellSoft Hardened Containers:25: nodejs, BellSoft Hardened Containers:stream: nodejs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-48618</guid>
    </item>
    <item>
      <title>BIT-node-2026-48618</title>
      <link>https://cve.radiocsirt.org/vuln/bit-node-2026-48618</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: node&lt;/p&gt;
&lt;p&gt;A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat.&#13;
&#13;
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.&#13;
&#13;
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: node&lt;/p&gt;
&lt;p&gt;A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat.&#13;
&#13;
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.&#13;
&#13;
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-node-2026-48618</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0786 — De multiples vulnérabilités ont été découvertes dans Node.js. Certaines d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0786</link>
      <description>certfr-2026-avi-0786</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0786</guid>
    </item>
    <item>
      <title>EUVD-2026-349694</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349694</link>
      <description>EUVD-2026-349694</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349694</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48618</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48618</link>
      <description>&lt;p&gt;A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat.&#13;
&#13;
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.&#13;
&#13;
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat.&#13;
&#13;
This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.&#13;
&#13;
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48618</guid>
    </item>
    <item>
      <title>GHSA-g57m-hr98-5m89</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g57m-hr98-5m89</link>
      <description>&lt;p&gt;A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat.&lt;/p&gt;
&lt;p&gt;This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.&lt;/p&gt;
&lt;p&gt;This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat.&lt;/p&gt;
&lt;p&gt;This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.&lt;/p&gt;
&lt;p&gt;This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g57m-hr98-5m89</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11110-1 — nodejs26-26.3.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11110-1</link>
      <description>&lt;p&gt;nodejs26-26.3.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs26-26.3.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11110-1</guid>
    </item>
    <item>
      <title>RHSA-2026:28727 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:28727</link>
      <description>&lt;p&gt;nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:28727</guid>
    </item>
    <item>
      <title>RLSA-2026:35841 — Important: nodejs24 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:35841</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs24&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)&lt;/p&gt;
&lt;p&gt;* undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)&lt;/p&gt;
&lt;p&gt;* undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)&lt;/p&gt;
&lt;p&gt;* undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)&lt;/p&gt;
&lt;p&gt;* undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs24&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)&lt;/p&gt;
&lt;p&gt;* undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)&lt;/p&gt;
&lt;p&gt;* undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)&lt;/p&gt;
&lt;p&gt;* undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)&lt;/p&gt;
&lt;p&gt;* undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:35841</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22368-1 — Security update for nodejs22</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22368-1</link>
      <description>&lt;p&gt;Security update for nodejs22&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs22&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22368-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48618</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48618</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nodejs, Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:Pro:20.04:LTS: nodejs, Ubuntu:Pro:22.04:LTS: nodejs, Ubuntu:24.04:LTS: nodejs, Ubuntu:25.10: nodejs, Ubuntu:26.04:LTS: nodejs&lt;/p&gt;
&lt;p&gt;A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: nodejs, Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:Pro:20.04:LTS: nodejs, Ubuntu:Pro:22.04:LTS: nodejs, Ubuntu:24.04:LTS: nodejs, Ubuntu:25.10: nodejs, Ubuntu:26.04:LTS: nodejs&lt;/p&gt;
&lt;p&gt;A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48618</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2004 — Node.js: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2004</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2004</guid>
    </item>
  </channel>
</rss>
