<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:50:17 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1067 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1067</link>
      <description>certfr-2026-avi-1067</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1067</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-BB25914 — Immutable</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bb25914</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. Immutable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the argo-workflows package. Immutable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bb25914</guid>
    </item>
    <item>
      <title>EUVD-2026-334048</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-334048</link>
      <description>EUVD-2026-334048</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-334048</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59879</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59879</link>
      <description>&lt;p&gt;Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, causing an empty List to enter an uncatchable infinite loop, a populated List to allocate without bound until process abort, or setSize to silently wrap large values. This issue is fixed in versions 4.3.9 and 5.1.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, causing an empty List to enter an uncatchable infinite loop, a populated List to allocate without bound until process abort, or setSize to silently wrap large values. This issue is fixed in versions 4.3.9 and 5.1.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59879</guid>
    </item>
    <item>
      <title>GHSA-v56q-mh7h-f735 — Immutable.js `List` 32-bit trie overflow → unrecoverable DoS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v56q-mh7h-f735</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: immutable&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`List#set`, `List#setSize`, `List#setIn`, `List#updateIn` (and the functional `set` / `setIn` / `updateIn`) mishandle an index or size in the range `[2 ** 30, 2 ** 31)`:&lt;/p&gt;
&lt;p&gt;- On an **empty** `List` the operation enters an **uncatchable infinite loop** (a tight CPU spin; a surrounding `try/catch` never regains control). Only killing the worker recovers it.
- On a **populated** `List` (≥ 32 elements — i.e. any array of ≥ 32 items turned into a `List` by `fromJS`) the loop allocates without bound → heap exhaustion → the **process aborts** (`SIGABRT`, exit `134`, or kernel OOM-kill `137`). A real crash, not a recoverable error.&lt;/p&gt;
&lt;p&gt;The index may be a **numeric string**, so it can come straight from a request body, URL, or key-path. A single small unauthenticated request is enough.&lt;/p&gt;
&lt;p&gt;There is also a companion **silent data-corruption** issue in `setSize`:&lt;/p&gt;
&lt;p&gt;```js
List([1, 2, 3]).setSize(2 ** 31); // before fix =&amp;gt; size 0  (silently cleared)
List([1, 2, 3]).setSize(2 ** 32 + 5); // before fix =&amp;gt; size 5  (huge value wraps to 5)
```&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Availability only. A reachable configuration is any endpoint that routes untrusted input into a `List` index or a `setIn`/`updateIn` key-path — which the extremely common `state = fromJS(body); state.setIn(userPath, value)` pattern does (config stores, document/collection editors, redux-immutable reducers, JSON-Patch endpoints, etc.).&lt;/p&gt;
&lt;p&gt;No confidentiality or integrity impact, no RCE. The companion `setSize` bug can silently corrupt applica…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: immutable&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`List#set`, `List#setSize`, `List#setIn`, `List#updateIn` (and the functional `set` / `setIn` / `updateIn`) mishandle an index or size in the range `[2 ** 30, 2 ** 31)`:&lt;/p&gt;
&lt;p&gt;- On an **empty** `List` the operation enters an **uncatchable infinite loop** (a tight CPU spin; a surrounding `try/catch` never regains control). Only killing the worker recovers it.
- On a **populated** `List` (≥ 32 elements — i.e. any array of ≥ 32 items turned into a `List` by `fromJS`) the loop allocates without bound → heap exhaustion → the **process aborts** (`SIGABRT`, exit `134`, or kernel OOM-kill `137`). A real crash, not a recoverable error.&lt;/p&gt;
&lt;p&gt;The index may be a **numeric string**, so it can come straight from a request body, URL, or key-path. A single small unauthenticated request is enough.&lt;/p&gt;
&lt;p&gt;There is also a companion **silent data-corruption** issue in `setSize`:&lt;/p&gt;
&lt;p&gt;```js
List([1, 2, 3]).setSize(2 ** 31); // before fix =&amp;gt; size 0  (silently cleared)
List([1, 2, 3]).setSize(2 ** 32 + 5); // before fix =&amp;gt; size 5  (huge value wraps to 5)
```&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Availability only. A reachable configuration is any endpoint that routes untrusted input into a `List` index or a `setIn`/`updateIn` key-path — which the extremely common `state = fromJS(body); state.setIn(userPath, value)` pattern does (config stores, document/collection editors, redux-immutable reducers, JSON-Patch endpoints, etc.).&lt;/p&gt;
&lt;p&gt;No confidentiality or integrity impact, no RCE. The companion `setSize` bug can silently corrupt applica…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v56q-mh7h-f735</guid>
    </item>
    <item>
      <title>RHSA-2026:67539 — Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.14.5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:67539</link>
      <description>&lt;p&gt;database/sql: Postgres Scan Race Condition grafana: Grafana: Privilege escalation via dashboard overwrite github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution stolostron/multicluster-observability-addon: Cross-namespace Secret disclosure in multicluster-observability-addon via unvalidated configuration references&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;database/sql: Postgres Scan Race Condition grafana: Grafana: Privilege escalation via dashboard overwrite github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution stolostron/multicluster-observability-addon: Cross-namespace Secret disclosure in multicluster-observability-addon via unvalidated configuration references&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:67539</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59879</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59879</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-immutable, Ubuntu:22.04:LTS: node-immutable, Ubuntu:24.04:LTS: node-immutable, Ubuntu:25.10: node-immutable, Ubuntu:26.04:LTS: node-immutable&lt;/p&gt;
&lt;p&gt;Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, causing an empty List to enter an uncatchable infinite loop, a populated List to allocate without bound until process abort, or setSize to silently wrap large values. This issue is fixed in versions 4.3.9 and 5.1.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-immutable, Ubuntu:22.04:LTS: node-immutable, Ubuntu:24.04:LTS: node-immutable, Ubuntu:25.10: node-immutable, Ubuntu:26.04:LTS: node-immutable&lt;/p&gt;
&lt;p&gt;Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, causing an empty List to enter an uncatchable infinite loop, a populated List to allocate without bound until process abort, or setSize to silently wrap large values. This issue is fixed in versions 4.3.9 and 5.1.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59879</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2636 — IBM Tivoli Netcool/OMNIbus (Immutable.js): Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2636</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Tivoli Netcool/OMNIbus ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Tivoli Netcool/OMNIbus ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2636</guid>
    </item>
  </channel>
</rss>
