<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:14:46 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0901 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</link>
      <description>certfr-2026-avi-0901</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-TX42489 — Security fixes in pulumi 3.248.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-tx42489</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: pulumi&lt;/p&gt;
&lt;p&gt;Package pulumi version 3.248.0-r0 fixes 30 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-56864, CVE-2026-56865, CVE-2026-56852, CVE-2026-71556...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: pulumi&lt;/p&gt;
&lt;p&gt;Package pulumi version 3.248.0-r0 fixes 30 vulnerabilities: ghsa-hrxh-6v49-42gf, CVE-2026-56864, CVE-2026-56865, CVE-2026-56852, CVE-2026-71556...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-tx42489</guid>
    </item>
    <item>
      <title>EUVD-2026-329324</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329324</link>
      <description>EUVD-2026-329324</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329324</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54285</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54285</link>
      <description>&lt;p&gt;opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size limits when parsing inbound baggage HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and 180 entries; these limits were only enforced on the outbound (inject()) path, not on the inbound (extract()) path. Parsing oversized baggage causes memory allocation proportional to the header size without any cap. This vulnerability is fixed in 2.8.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size limits when parsing inbound baggage HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and 180 entries; these limits were only enforced on the outbound (inject()) path, not on the inbound (extract()) path. Parsing oversized baggage causes memory allocation proportional to the header size without any cap. This vulnerability is fixed in 2.8.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54285</guid>
    </item>
    <item>
      <title>GHSA-8988-4f7v-96qf — OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8988-4f7v-96qf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @opentelemetry/core&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;`W3CBaggagePropagator.extract()` in `@opentelemetry/core` does not enforce size limits when parsing inbound `baggage` HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and 180 entries; these limits were only enforced on the outbound (`inject()`) path, not on the inbound (`extract()`) path. Parsing oversized baggage causes memory allocation proportional to the header size without any cap.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The practical availability impact for most Node.js deployments is limited. Node.js enforces a default `--max-http-header-size` of 16,384 bytes on the total combined size of all HTTP headers, constraining what an external attacker can deliver before the propagator is reached. Additionally, the header is already in memory (parsed by the HTTP layer) by the time it reaches the propagator - the additional allocation is the overhead of splitting into entry objects, not an unbounded read.&lt;/p&gt;
&lt;p&gt;The risk is higher when transport-layer limits are absent - e.g., non-HTTP transports (messaging systems, custom `TextMapGetter` implementations) or deployments that have raised `--max-http-header-size`.&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;Update `@opentelemetry/core` to version 2.8.0 or later. The fix enforces limits consistent with the W3C Baggage specification at the propagator level:&lt;/p&gt;
&lt;p&gt;- Maximum total baggage size: 8,192 bytes
- Maximum number of entries: 180
- Maximum per-entry size: 4,096 bytes&lt;/p&gt;
&lt;p&gt;Headers that exceed these limits are truncated at the point the limit is reach…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @opentelemetry/core&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;`W3CBaggagePropagator.extract()` in `@opentelemetry/core` does not enforce size limits when parsing inbound `baggage` HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and 180 entries; these limits were only enforced on the outbound (`inject()`) path, not on the inbound (`extract()`) path. Parsing oversized baggage causes memory allocation proportional to the header size without any cap.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The practical availability impact for most Node.js deployments is limited. Node.js enforces a default `--max-http-header-size` of 16,384 bytes on the total combined size of all HTTP headers, constraining what an external attacker can deliver before the propagator is reached. Additionally, the header is already in memory (parsed by the HTTP layer) by the time it reaches the propagator - the additional allocation is the overhead of splitting into entry objects, not an unbounded read.&lt;/p&gt;
&lt;p&gt;The risk is higher when transport-layer limits are absent - e.g., non-HTTP transports (messaging systems, custom `TextMapGetter` implementations) or deployments that have raised `--max-http-header-size`.&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;Update `@opentelemetry/core` to version 2.8.0 or later. The fix enforces limits consistent with the W3C Baggage specification at the propagator level:&lt;/p&gt;
&lt;p&gt;- Maximum total baggage size: 8,192 bytes
- Maximum number of entries: 180
- Maximum per-entry size: 4,096 bytes&lt;/p&gt;
&lt;p&gt;Headers that exceed these limits are truncated at the point the limit is reach…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8988-4f7v-96qf</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2618 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2618</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2618</guid>
    </item>
  </channel>
</rss>
