<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:25:28 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-VG66348 — Security fix for CVE-2026-48801 applied in: argo-workflows 3.6.19-r7, argo-workflows 3.7.15-r3</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-vg66348</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;CVE-2026-48801 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;CVE-2026-48801 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-vg66348</guid>
    </item>
    <item>
      <title>EUVD-2026-337881</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337881</link>
      <description>EUVD-2026-337881</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337881</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48801</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48801</link>
      <description>&lt;p&gt;linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package&amp;#39;s primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package&amp;#39;s primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48801</guid>
    </item>
    <item>
      <title>GHSA-22p9-wv53-3rq4 — LinkifyIt#match scan loop has quadratic algorithmic complexity</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-22p9-wv53-3rq4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: linkify-it&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`LinkifyIt.prototype.match` — the package&amp;#39;s primary public API — has **O(N²) algorithmic complexity** for inputs containing many fuzzy links or emails. This is not a regex backtrack bug; it&amp;#39;s a structural issue in the JS-level scan loop that re-slices the input and re-runs unanchored regex searches on progressively shorter tails, N times.&lt;/p&gt;
&lt;p&gt;64 KB of `&amp;#34;a@b.com\n&amp;#34;` repeated burns ~2.5 s of single-threaded CPU; 128 KB takes ~10 s. Doubling the input quadruples the time — textbook O(N²).&lt;/p&gt;
&lt;p&gt;The same cost passes through `markdown-it` (`linkify:true`) unmodified. Any service that synchronously renders untrusted Markdown with linkify enabled on a request hot-path (forums, comments, chat, wikis, AI chat UIs) inherits a worker-process DoS triggerable by a tens-of-KB request body.&lt;/p&gt;
&lt;p&gt;## Affected component&lt;/p&gt;
&lt;p&gt;- HEAD audited: `8e887d5bace3f5b09b1d1f70492fa0364ef1793d` (v5.0.0)
- Vulnerable function: `LinkifyIt.prototype.match` — `index.mjs:528-554`
- Re-scan call sites inside `test()`: `index.mjs:444` (fuzzy host search), `:448` (fuzzy link match), `:467` (fuzzy email match)
- Transitive consumer: `markdown-it` (~21.6M weekly npm DLs) calls `linkify.match()` at `lib/rules_core/linkify.mjs:57` when `linkify:true`
- **All versions affected** — the vulnerable loop exists since the initial commit (2014) through v5.0.0&lt;/p&gt;
&lt;p&gt;## Vulnerability details&lt;/p&gt;
&lt;p&gt;### The O(N²) outer loop&lt;/p&gt;
&lt;p&gt;`index.mjs:528-554`:&lt;/p&gt;
&lt;p&gt;```js
LinkifyIt.prototype.match = function match (text) {
  const result = []
  let shift = 0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: linkify-it&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`LinkifyIt.prototype.match` — the package&amp;#39;s primary public API — has **O(N²) algorithmic complexity** for inputs containing many fuzzy links or emails. This is not a regex backtrack bug; it&amp;#39;s a structural issue in the JS-level scan loop that re-slices the input and re-runs unanchored regex searches on progressively shorter tails, N times.&lt;/p&gt;
&lt;p&gt;64 KB of `&amp;#34;a@b.com\n&amp;#34;` repeated burns ~2.5 s of single-threaded CPU; 128 KB takes ~10 s. Doubling the input quadruples the time — textbook O(N²).&lt;/p&gt;
&lt;p&gt;The same cost passes through `markdown-it` (`linkify:true`) unmodified. Any service that synchronously renders untrusted Markdown with linkify enabled on a request hot-path (forums, comments, chat, wikis, AI chat UIs) inherits a worker-process DoS triggerable by a tens-of-KB request body.&lt;/p&gt;
&lt;p&gt;## Affected component&lt;/p&gt;
&lt;p&gt;- HEAD audited: `8e887d5bace3f5b09b1d1f70492fa0364ef1793d` (v5.0.0)
- Vulnerable function: `LinkifyIt.prototype.match` — `index.mjs:528-554`
- Re-scan call sites inside `test()`: `index.mjs:444` (fuzzy host search), `:448` (fuzzy link match), `:467` (fuzzy email match)
- Transitive consumer: `markdown-it` (~21.6M weekly npm DLs) calls `linkify.match()` at `lib/rules_core/linkify.mjs:57` when `linkify:true`
- **All versions affected** — the vulnerable loop exists since the initial commit (2014) through v5.0.0&lt;/p&gt;
&lt;p&gt;## Vulnerability details&lt;/p&gt;
&lt;p&gt;### The O(N²) outer loop&lt;/p&gt;
&lt;p&gt;`index.mjs:528-554`:&lt;/p&gt;
&lt;p&gt;```js
LinkifyIt.prototype.match = function match (text) {
  const result = []
  let shift = 0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-22p9-wv53-3rq4</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>RHSA-2026:38187 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:38187</link>
      <description>&lt;p&gt;linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability js-yaml: js-yaml: Denial of Service via crafted YAML documents&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability js-yaml: js-yaml: Denial of Service via crafted YAML documents&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:38187</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48801</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48801</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-markdown-it, Ubuntu:24.04:LTS: node-markdown-it, Ubuntu:26.04:LTS: node-markdown-it&lt;/p&gt;
&lt;p&gt;linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package&amp;#39;s primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-markdown-it, Ubuntu:24.04:LTS: node-markdown-it, Ubuntu:26.04:LTS: node-markdown-it&lt;/p&gt;
&lt;p&gt;linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package&amp;#39;s primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48801</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2452 — Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, DOMPurify): Mehrere S…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</guid>
    </item>
  </channel>
</rss>
