<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:52:59 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10947</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10947</link>
      <description>bdu:2026-10947</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10947</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>EUVD-2026-343929</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343929</link>
      <description>EUVD-2026-343929</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343929</guid>
    </item>
    <item>
      <title>fkie_cve-2026-67318</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67318</link>
      <description>&lt;p&gt;axios versions &amp;gt;=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node&amp;#39;s HTTP/2 request API does not honor the maxBodyLength option and axios&amp;#39;s byte-counting stream wrapper is gated on maxRedirects === 0, an attacker who controls a stream passed to axios can cause the application to transmit outbound data exceeding the configured finite maxBodyLength. Impact is limited to resource consumption and policy bypass (excess egress, upstream quota consumption, limited availability); it does not enable code execution, credential disclosure, or request-destination control. Calls using the default maxBodyLength: -1 and browser adapters are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;axios versions &amp;gt;=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node&amp;#39;s HTTP/2 request API does not honor the maxBodyLength option and axios&amp;#39;s byte-counting stream wrapper is gated on maxRedirects === 0, an attacker who controls a stream passed to axios can cause the application to transmit outbound data exceeding the configured finite maxBodyLength. Impact is limited to resource consumption and policy bypass (excess egress, upstream quota consumption, limited availability); it does not enable code execution, credential disclosure, or request-destination control. Calls using the default maxBodyLength: -1 and browser adapters are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-67318</guid>
    </item>
    <item>
      <title>GHSA-mwf2-3pr3-8698 — Axios: HTTP/2 streamed uploads bypass `maxBodyLength`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mwf2-3pr3-8698</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Axios versions with Node.js HTTP/2 support allow streamed request bodies to bypass `maxBodyLength` enforcement when requests are sent with `httpVersion: 2`.&lt;/p&gt;
&lt;p&gt;This affects applications that rely on `maxBodyLength` as a hard cap while forwarding attacker-controlled streams, such as upload endpoints proxying user data to an upstream HTTP/2 service. Buffered request bodies are still checked before the request is sent.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can control a stream passed to axios can cause the application to transmit more outbound data than the configured `maxBodyLength` limit.&lt;/p&gt;
&lt;p&gt;Practical impact is limited to resource consumption and policy bypass: excess outbound bandwidth, egress cost, upstream quota consumption, and limited availability impact on the application or upstream peer. This does not provide code execution, credential disclosure, or request destination control.&lt;/p&gt;
&lt;p&gt;Browser adapters are not affected. Axios calls using the default unlimited `maxBodyLength: -1` do not cross this specific configured-limit boundary.&lt;/p&gt;
&lt;p&gt;## Affected Functionality&lt;/p&gt;
&lt;p&gt;Affected calls require all of the following:&lt;/p&gt;
&lt;p&gt;- Node.js HTTP adapter.
- `httpVersion: 2`.
- Request `data` supplied as a stream.
- A finite `maxBodyLength`.
- Attacker-controlled or attacker-influenced stream contents.&lt;/p&gt;
&lt;p&gt;Unaffected or differently affected paths:&lt;/p&gt;
&lt;p&gt;- String, Buffer, and ArrayBuffer request bodies are checked before transport selection.
- Browser XHR/fetch adapters are not affected.
- HTTP/1.1 requests using…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Axios versions with Node.js HTTP/2 support allow streamed request bodies to bypass `maxBodyLength` enforcement when requests are sent with `httpVersion: 2`.&lt;/p&gt;
&lt;p&gt;This affects applications that rely on `maxBodyLength` as a hard cap while forwarding attacker-controlled streams, such as upload endpoints proxying user data to an upstream HTTP/2 service. Buffered request bodies are still checked before the request is sent.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who can control a stream passed to axios can cause the application to transmit more outbound data than the configured `maxBodyLength` limit.&lt;/p&gt;
&lt;p&gt;Practical impact is limited to resource consumption and policy bypass: excess outbound bandwidth, egress cost, upstream quota consumption, and limited availability impact on the application or upstream peer. This does not provide code execution, credential disclosure, or request destination control.&lt;/p&gt;
&lt;p&gt;Browser adapters are not affected. Axios calls using the default unlimited `maxBodyLength: -1` do not cross this specific configured-limit boundary.&lt;/p&gt;
&lt;p&gt;## Affected Functionality&lt;/p&gt;
&lt;p&gt;Affected calls require all of the following:&lt;/p&gt;
&lt;p&gt;- Node.js HTTP adapter.
- `httpVersion: 2`.
- Request `data` supplied as a stream.
- A finite `maxBodyLength`.
- Attacker-controlled or attacker-influenced stream contents.&lt;/p&gt;
&lt;p&gt;Unaffected or differently affected paths:&lt;/p&gt;
&lt;p&gt;- String, Buffer, and ArrayBuffer request bodies are checked before transport selection.
- Browser XHR/fetch adapters are not affected.
- HTTP/1.1 requests using…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mwf2-3pr3-8698</guid>
    </item>
    <item>
      <title>RHSA-2026:49714 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:49714</link>
      <description>&lt;p&gt;axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: NO_PROXY bypass allows exposure of local services axios: axios: Prototype Pollution allows unauthorized data transmission and network redirection axios: axios: Denial of Service via maxBodyLength bypass with ReadableStream axios: axios: Denial of Service due to maxBodyLength bypass in HTTP/2 requests&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: NO_PROXY bypass allows exposure of local services axios: axios: Prototype Pollution allows unauthorized data transmission and network redirection axios: axios: Denial of Service via maxBodyLength bypass with ReadableStream axios: axios: Denial of Service due to maxBodyLength bypass in HTTP/2 requests&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:49714</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-67318</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67318</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;axios versions &amp;gt;=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node&amp;#39;s HTTP/2 request API does not honor the maxBodyLength option and axios&amp;#39;s byte-counting stream wrapper is gated on maxRedirects === 0, an attacker who controls a stream passed to axios can cause the application to transmit outbound data exceeding the configured finite maxBodyLength. Impact is limited to resource consumption and policy bypass (excess egress, upstream quota consumption, limited availability); it does not enable code execution, credential disclosure, or request-destination control. Calls using the default maxBodyLength: -1 and browser adapters are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;axios versions &amp;gt;=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node&amp;#39;s HTTP/2 request API does not honor the maxBodyLength option and axios&amp;#39;s byte-counting stream wrapper is gated on maxRedirects === 0, an attacker who controls a stream passed to axios can cause the application to transmit outbound data exceeding the configured finite maxBodyLength. Impact is limited to resource consumption and policy bypass (excess egress, upstream quota consumption, limited availability); it does not enable code execution, credential disclosure, or request-destination control. Calls using the default maxBodyLength: -1 and browser adapters are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67318</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2958 — IBM License Metric Tool: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2958</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2958</guid>
    </item>
  </channel>
</rss>
