<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:38:36 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10948</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10948</link>
      <description>bdu:2026-10948</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10948</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>EUVD-2026-343843</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343843</link>
      <description>EUVD-2026-343843</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343843</guid>
    </item>
    <item>
      <title>fkie_cve-2026-67319</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67319</link>
      <description>&lt;p&gt;axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process&amp;#39;s Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain objects such as auth and paramsSerializer are cloned into ordinary objects and read without own-property checks. When an application passes placeholder nested objects such as auth: {} or paramsSerializer: {}, inherited username/password values can cause silent injection of an Authorization: Basic header, and inherited encode/serialize values can alter query-string serialization (full serializer replacement requires a function-valued pollution primitive). This is exploitable only in the presence of pre-existing prototype pollution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process&amp;#39;s Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain objects such as auth and paramsSerializer are cloned into ordinary objects and read without own-property checks. When an application passes placeholder nested objects such as auth: {} or paramsSerializer: {}, inherited username/password values can cause silent injection of an Authorization: Basic header, and inherited encode/serialize values can alter query-string serialization (full serializer replacement requires a function-valued pollution primitive). This is exploitable only in the presence of pre-existing prototype pollution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-67319</guid>
    </item>
    <item>
      <title>GHSA-7q8q-rj6j-mhjq — Axios: Nested axios option objects can consume polluted prototype values</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7q8q-rj6j-mhjq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Axios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.prototype`.&lt;/p&gt;
&lt;p&gt;The top-level merged config is protected with a null prototype, but nested plain objects such as `auth` and `paramsSerializer` are cloned into ordinary objects. If application code passes placeholders such as `auth: {}` or `paramsSerializer: {}`, inherited `username`, `password`, `encode`, or `serialize` properties can influence outbound requests.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;This is reachable only when another component has already polluted `Object.prototype` and the application passes an affected nested axios option object.&lt;/p&gt;
&lt;p&gt;Confirmed impacts include silent injection of an `Authorization: Basic ...` header from inherited `username` and `password` values, and query-string tampering when inherited `paramsSerializer` fields are function-valued.&lt;/p&gt;
&lt;p&gt;The `auth` case requires only string-valued pollution. Full query-string replacement through `paramsSerializer.serialize` requires a function-valued pollution primitive; string-only pollution may still cause request failures or encoding changes through `encode`.&lt;/p&gt;
&lt;p&gt;This does not mean every axios request is affected. Requests that do not pass `auth`, do not pass `paramsSerializer`, or provide explicit own properties for the relevant nested fields are not affected by this specific gadget.&lt;/p&gt;
&lt;p&gt;## Affected Functionality&lt;/p&gt;
&lt;p&gt;Affected runtime functionality:&lt;/p&gt;
&lt;p&gt;- Node HTTP adapter Basic auth handling in `lib/adap…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: axios&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Axios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.prototype`.&lt;/p&gt;
&lt;p&gt;The top-level merged config is protected with a null prototype, but nested plain objects such as `auth` and `paramsSerializer` are cloned into ordinary objects. If application code passes placeholders such as `auth: {}` or `paramsSerializer: {}`, inherited `username`, `password`, `encode`, or `serialize` properties can influence outbound requests.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;This is reachable only when another component has already polluted `Object.prototype` and the application passes an affected nested axios option object.&lt;/p&gt;
&lt;p&gt;Confirmed impacts include silent injection of an `Authorization: Basic ...` header from inherited `username` and `password` values, and query-string tampering when inherited `paramsSerializer` fields are function-valued.&lt;/p&gt;
&lt;p&gt;The `auth` case requires only string-valued pollution. Full query-string replacement through `paramsSerializer.serialize` requires a function-valued pollution primitive; string-only pollution may still cause request failures or encoding changes through `encode`.&lt;/p&gt;
&lt;p&gt;This does not mean every axios request is affected. Requests that do not pass `auth`, do not pass `paramsSerializer`, or provide explicit own properties for the relevant nested fields are not affected by this specific gadget.&lt;/p&gt;
&lt;p&gt;## Affected Functionality&lt;/p&gt;
&lt;p&gt;Affected runtime functionality:&lt;/p&gt;
&lt;p&gt;- Node HTTP adapter Basic auth handling in `lib/adap…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7q8q-rj6j-mhjq</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-67319 — axios before 0.33.0 Prototype Pollution via nested option objects</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-67319</link>
      <description>msrc_CVE-2026-67319</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-67319</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11680-1 — agama-web-ui-24+0.a836cced5-52.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1</link>
      <description>&lt;p&gt;agama-web-ui-24+0.a836cced5-52.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;agama-web-ui-24+0.a836cced5-52.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1</guid>
    </item>
    <item>
      <title>RHSA-2026:49387 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:49387</link>
      <description>&lt;p&gt;fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority axios: axios: Information disclosure and data manipulation via prototype pollution&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority axios: axios: Information disclosure and data manipulation via prototype pollution&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:49387</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-67319</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67319</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process&amp;#39;s Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain objects such as auth and paramsSerializer are cloned into ordinary objects and read without own-property checks. When an application passes placeholder nested objects such as auth: {} or paramsSerializer: {}, inherited username/password values can cause silent injection of an Authorization: Basic header, and inherited encode/serialize values can alter query-string serialization (full serializer replacement requires a function-valued pollution primitive). This is exploitable only in the presence of pre-existing prototype pollution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: node-axios, Ubuntu:Pro:22.04:LTS: node-axios, Ubuntu:Pro:24.04:LTS: node-axios, Ubuntu:Pro:26.04:LTS: node-axios&lt;/p&gt;
&lt;p&gt;axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process&amp;#39;s Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain objects such as auth and paramsSerializer are cloned into ordinary objects and read without own-property checks. When an application passes placeholder nested objects such as auth: {} or paramsSerializer: {}, inherited username/password values can cause silent injection of an Authorization: Basic header, and inherited encode/serialize values can alter query-string serialization (full serializer replacement requires a function-valued pollution primitive). This is exploitable only in the presence of pre-existing prototype pollution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67319</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2958 — IBM License Metric Tool: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2958</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2958</guid>
    </item>
  </channel>
</rss>
