<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 19:16:43 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-EA45070 — Security fix for CVE-2026-59887 applied in: argo-workflows 3.6.19-r7, argo-workflows 3.7.15-r3, n8n 2.28.0-r2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ea45070</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows, CleanStart: n8n&lt;/p&gt;
&lt;p&gt;CVE-2026-59887 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows, CleanStart: n8n&lt;/p&gt;
&lt;p&gt;CVE-2026-59887 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ea45070</guid>
    </item>
    <item>
      <title>EUVD-2026-335370</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335370</link>
      <description>EUVD-2026-335370</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335370</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59887</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59887</link>
      <description>&lt;p&gt;linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59887</guid>
    </item>
    <item>
      <title>GHSA-v245-v573-v5vm — linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v245-v573-v5vm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: linkify-it&lt;/p&gt;
&lt;p&gt;### Summary
`linkify-it`&amp;#39;s schema-scan loop (`.test()` / `.match()`, the documented public API) invokes the `mailto:`
schema validator at **every** `mailto:` occurrence in the input text. For each occurrence the validator does
`text.slice(pos)` (an O(n) copy) and runs an email regex whose local-part class `src_email_name` greedily
scans the **entire remaining tail** (O(n)) before failing. With N `mailto:` occurrences that is
**N × O(n) = O(n²)**. Because linkify-it runs on arbitrary user text (markdown-it feeds it whole documents
when `linkify:true`), an unauthenticated attacker can block the single-threaded event loop for many seconds
with a small input. No length bound (unlike an HTTP header).&lt;/p&gt;
&lt;p&gt;### Root cause — `index.mjs` + `lib/re.mjs`
```js
// index.mjs (mailto validator) — runs at every &amp;#34;mailto:&amp;#34; hit
&amp;#39;mailto:&amp;#39;: { validate: function (text, pos, self) {
  const tail = text.slice(pos)                                  // O(n) copy per hit
  if (!self.re.mailto) self.re.mailto = new RegExp(&amp;#39;^&amp;#39; + self.re.src_email_name + &amp;#39;@&amp;#39; + self.re.src_host_strict, &amp;#39;i&amp;#39;)
  if (self.re.mailto.test(tail)) { ... }                        // scans the whole O(n) tail
  return 0
}}
// lib/re.mjs:91-93 — every char of &amp;#34;mailto:&amp;#34; (incl. &amp;#39;:&amp;#39;,&amp;#39;-&amp;#39;,&amp;#39;;&amp;#39;) is in this class:
re.src_email_name = &amp;#39;[\\-;:&amp;amp;=\\+\\$,\\.a-zA-Z0-9_][\\-;:&amp;amp;=\\+\\$,\\&amp;#34;\\.a-zA-Z0-9_]*&amp;#39;
```
The `while ((m = re.exec(text)) !== null) { …testSchemaAt… }` scan loop calls the validator at each
`mailto:` hit; `src_email_name` greedily consu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: linkify-it&lt;/p&gt;
&lt;p&gt;### Summary
`linkify-it`&amp;#39;s schema-scan loop (`.test()` / `.match()`, the documented public API) invokes the `mailto:`
schema validator at **every** `mailto:` occurrence in the input text. For each occurrence the validator does
`text.slice(pos)` (an O(n) copy) and runs an email regex whose local-part class `src_email_name` greedily
scans the **entire remaining tail** (O(n)) before failing. With N `mailto:` occurrences that is
**N × O(n) = O(n²)**. Because linkify-it runs on arbitrary user text (markdown-it feeds it whole documents
when `linkify:true`), an unauthenticated attacker can block the single-threaded event loop for many seconds
with a small input. No length bound (unlike an HTTP header).&lt;/p&gt;
&lt;p&gt;### Root cause — `index.mjs` + `lib/re.mjs`
```js
// index.mjs (mailto validator) — runs at every &amp;#34;mailto:&amp;#34; hit
&amp;#39;mailto:&amp;#39;: { validate: function (text, pos, self) {
  const tail = text.slice(pos)                                  // O(n) copy per hit
  if (!self.re.mailto) self.re.mailto = new RegExp(&amp;#39;^&amp;#39; + self.re.src_email_name + &amp;#39;@&amp;#39; + self.re.src_host_strict, &amp;#39;i&amp;#39;)
  if (self.re.mailto.test(tail)) { ... }                        // scans the whole O(n) tail
  return 0
}}
// lib/re.mjs:91-93 — every char of &amp;#34;mailto:&amp;#34; (incl. &amp;#39;:&amp;#39;,&amp;#39;-&amp;#39;,&amp;#39;;&amp;#39;) is in this class:
re.src_email_name = &amp;#39;[\\-;:&amp;amp;=\\+\\$,\\.a-zA-Z0-9_][\\-;:&amp;amp;=\\+\\$,\\&amp;#34;\\.a-zA-Z0-9_]*&amp;#39;
```
The `while ((m = re.exec(text)) !== null) { …testSchemaAt… }` scan loop calls the validator at each
`mailto:` hit; `src_email_name` greedily consu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v245-v573-v5vm</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>RHSA-2026:68754 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.30.1 Release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:68754</link>
      <description>&lt;p&gt;lodash: lodash: Arbitrary code execution via untrusted input in template imports postcss: PostCSS: Information disclosure and denial of service via crafted CSS input baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak linkify-it: linkify-it: Denial of Service via crafted mailto: links io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) nanoid: nanoid: Denial of Service via infinite loop in random ID generation axios: axios: Denial of Service via uncontrolled recursion in form data processing axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lodash: lodash: Arbitrary code execution via untrusted input in template imports postcss: PostCSS: Information disclosure and denial of service via crafted CSS input baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak linkify-it: linkify-it: Denial of Service via crafted mailto: links io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) nanoid: nanoid: Denial of Service via infinite loop in random ID generation axios: axios: Denial of Service via uncontrolled recursion in form data processing axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:68754</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2923 — Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2923</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2923</guid>
    </item>
  </channel>
</rss>
