<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:13:32 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10945</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10945</link>
      <description>bdu:2026-10945</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10945</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>EUVD-2026-343841</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343841</link>
      <description>EUVD-2026-343841</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343841</guid>
    </item>
    <item>
      <title>fkie_cve-2026-67317</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67317</link>
      <description>&lt;p&gt;axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-67317</guid>
    </item>
    <item>
      <title>GHSA-jqh4-m9w3-8hp9 — Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jqh4-m9w3-8hp9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;axios’ fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined before dispatch. Applications that use `adapter: &amp;#34;fetch&amp;#34;` and rely on `maxBodyLength` to cap untrusted upload/proxy streams can send the full stream even when it exceeds the configured limit.&lt;/p&gt;
&lt;p&gt;This affects fetch-adapter usage in edge runtimes where fetch is selected, and in Node.js or browser environments where the fetch adapter is explicitly selected. The HTTP adapter’s stream upload path is not affected.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can supply or influence a streamed request body can bypass the caller’s configured upload-size limit. Practical impact is unexpected outbound network egress, request-level resource consumption, and possible exhaustion of upstream API quotas or bandwidth.&lt;/p&gt;
&lt;p&gt;This does not expose response data, execute code, or modify axios configuration. Exploitability depends on an application passing attacker-controlled, unknown-length stream data to axios and relying on `maxBodyLength` as the size guard.&lt;/p&gt;
&lt;p&gt;## Affected Functionality&lt;/p&gt;
&lt;p&gt;Affected:
- `adapter: &amp;#34;fetch&amp;#34;` or environments where axios selects the fetch adapter.
- Request methods with bodies, such as `POST`, `PUT`, and `PATCH`.
- `data` as a WHATWG `ReadableStream` without a reliable `Content-Length`.
- Configurations that set `maxBodyLength` to a finite value.&lt;/p&gt;
&lt;p&gt;Not affected:
- Axios versions before the fetch adapter was introduced.
- The Node HTTP adapter stream e…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;axios’ fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined before dispatch. Applications that use `adapter: &amp;#34;fetch&amp;#34;` and rely on `maxBodyLength` to cap untrusted upload/proxy streams can send the full stream even when it exceeds the configured limit.&lt;/p&gt;
&lt;p&gt;This affects fetch-adapter usage in edge runtimes where fetch is selected, and in Node.js or browser environments where the fetch adapter is explicitly selected. The HTTP adapter’s stream upload path is not affected.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can supply or influence a streamed request body can bypass the caller’s configured upload-size limit. Practical impact is unexpected outbound network egress, request-level resource consumption, and possible exhaustion of upstream API quotas or bandwidth.&lt;/p&gt;
&lt;p&gt;This does not expose response data, execute code, or modify axios configuration. Exploitability depends on an application passing attacker-controlled, unknown-length stream data to axios and relying on `maxBodyLength` as the size guard.&lt;/p&gt;
&lt;p&gt;## Affected Functionality&lt;/p&gt;
&lt;p&gt;Affected:
- `adapter: &amp;#34;fetch&amp;#34;` or environments where axios selects the fetch adapter.
- Request methods with bodies, such as `POST`, `PUT`, and `PATCH`.
- `data` as a WHATWG `ReadableStream` without a reliable `Content-Length`.
- Configurations that set `maxBodyLength` to a finite value.&lt;/p&gt;
&lt;p&gt;Not affected:
- Axios versions before the fetch adapter was introduced.
- The Node HTTP adapter stream e…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jqh4-m9w3-8hp9</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11680-1 — agama-web-ui-24+0.a836cced5-52.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1</link>
      <description>&lt;p&gt;agama-web-ui-24+0.a836cced5-52.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;agama-web-ui-24+0.a836cced5-52.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1</guid>
    </item>
    <item>
      <title>RHSA-2026:49714 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:49714</link>
      <description>&lt;p&gt;axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: NO_PROXY bypass allows exposure of local services axios: axios: Prototype Pollution allows unauthorized data transmission and network redirection axios: axios: Denial of Service via maxBodyLength bypass with ReadableStream axios: axios: Denial of Service due to maxBodyLength bypass in HTTP/2 requests&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: NO_PROXY bypass allows exposure of local services axios: axios: Prototype Pollution allows unauthorized data transmission and network redirection axios: axios: Denial of Service via maxBodyLength bypass with ReadableStream axios: axios: Denial of Service due to maxBodyLength bypass in HTTP/2 requests&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:49714</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-67317</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67317</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67317</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2958 — IBM License Metric Tool: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2958</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2958</guid>
    </item>
  </channel>
</rss>
