<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:07:20 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</link>
      <description>certfr-2026-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-JR64129 — Security fixes in renovate 44.32.4-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-jr64129</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: renovate&lt;/p&gt;
&lt;p&gt;Package renovate version 44.32.4-r1 fixes 27 vulnerabilities: CVE-2026-59873, CVE-2026-59874, CVE-2026-59871, CVE-2026-59875, ghsa-r292-9mhp-454m...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: renovate&lt;/p&gt;
&lt;p&gt;Package renovate version 44.32.4-r1 fixes 27 vulnerabilities: CVE-2026-59873, CVE-2026-59874, CVE-2026-59871, CVE-2026-59875, ghsa-r292-9mhp-454m...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-jr64129</guid>
    </item>
    <item>
      <title>EUVD-2026-335279</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335279</link>
      <description>EUVD-2026-335279</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335279</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59875</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59875</link>
      <description>&lt;p&gt;node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59875</guid>
    </item>
    <item>
      <title>GHSA-gvwx-54wh-qm9j — node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gvwx-54wh-qm9j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tar&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`node-tar` strips trailing `NUL` bytes from long-name (`L`) and long-linkpath (`K`) GNU extended headers but does **not** apply the same sanitization to equivalent fields delivered via PAX (`x` typeflag) extended headers. A PAX record of the form `path=visible.txt\x00hidden.txt` is parsed verbatim into `entry.path` and flows into `fs.lstat()` / `fs.open()`, which Node.js core rejects with `ERR_INVALID_ARG_VALUE`. The throw originates inside an `FSReqCallback` async chain that is **not** wrapped by the consumer&amp;#39;s `await/try-catch` around `tar.x()` — it surfaces as `uncaughtException` and terminates the process.&lt;/p&gt;
&lt;p&gt;This is a remote denial-of-service primitive against any process that extracts attacker-supplied tarballs through `tar.x` / `tar.extract` / `tar.t` / `tar.Parser`, even when the consumer follows the documented `try/catch` error-handling pattern.&lt;/p&gt;
&lt;p&gt;A secondary parser-differential (CWE-436) exists because `tar(1)`, `bsdtar`, and Python `tarfile` truncate the path at the first `NUL` (yielding `visible.txt`) while node-tar retains the full string. A validator that pre-scans a tarball with one tool and extracts with the other is bypassed.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;### Vulnerable sink — `src/pax.ts:157-183`&lt;/p&gt;
&lt;p&gt;PAX KV records flow through `parseKVLine`. The value half (`v`) is assigned directly to the result object with no sanitization for embedded NUL bytes:&lt;/p&gt;
&lt;p&gt;```ts
// src/pax.ts:157
const parseKVLine = (set: Record&amp;lt;string, unknown&amp;gt;, line: string) =&amp;gt; {
  const n = parseI…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tar&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`node-tar` strips trailing `NUL` bytes from long-name (`L`) and long-linkpath (`K`) GNU extended headers but does **not** apply the same sanitization to equivalent fields delivered via PAX (`x` typeflag) extended headers. A PAX record of the form `path=visible.txt\x00hidden.txt` is parsed verbatim into `entry.path` and flows into `fs.lstat()` / `fs.open()`, which Node.js core rejects with `ERR_INVALID_ARG_VALUE`. The throw originates inside an `FSReqCallback` async chain that is **not** wrapped by the consumer&amp;#39;s `await/try-catch` around `tar.x()` — it surfaces as `uncaughtException` and terminates the process.&lt;/p&gt;
&lt;p&gt;This is a remote denial-of-service primitive against any process that extracts attacker-supplied tarballs through `tar.x` / `tar.extract` / `tar.t` / `tar.Parser`, even when the consumer follows the documented `try/catch` error-handling pattern.&lt;/p&gt;
&lt;p&gt;A secondary parser-differential (CWE-436) exists because `tar(1)`, `bsdtar`, and Python `tarfile` truncate the path at the first `NUL` (yielding `visible.txt`) while node-tar retains the full string. A validator that pre-scans a tarball with one tool and extracts with the other is bypassed.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;### Vulnerable sink — `src/pax.ts:157-183`&lt;/p&gt;
&lt;p&gt;PAX KV records flow through `parseKVLine`. The value half (`v`) is assigned directly to the result object with no sanitization for embedded NUL bytes:&lt;/p&gt;
&lt;p&gt;```ts
// src/pax.ts:157
const parseKVLine = (set: Record&amp;lt;string, unknown&amp;gt;, line: string) =&amp;gt; {
  const n = parseI…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gvwx-54wh-qm9j</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-59875 — node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-59875</link>
      <description>msrc_CVE-2026-59875</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-59875</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59875</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59875</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-tar, Ubuntu:Pro:16.04:LTS: node-tar, Ubuntu:18.04:LTS: node-tar, Ubuntu:Pro:20.04:LTS: node-tar, Ubuntu:22.04:LTS: node-tar, Ubuntu:24.04:LTS: node-tar, Ubuntu:25.10: node-tar, Ubuntu:26.04:LTS: node-tar&lt;/p&gt;
&lt;p&gt;node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-tar, Ubuntu:Pro:16.04:LTS: node-tar, Ubuntu:18.04:LTS: node-tar, Ubuntu:Pro:20.04:LTS: node-tar, Ubuntu:22.04:LTS: node-tar, Ubuntu:24.04:LTS: node-tar, Ubuntu:25.10: node-tar, Ubuntu:26.04:LTS: node-tar&lt;/p&gt;
&lt;p&gt;node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59875</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3621 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3621</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Daten zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Daten zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3621</guid>
    </item>
  </channel>
</rss>
