<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:35:46 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:35841 — Important: nodejs24 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:35841</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: nodejs24, AlmaLinux:10: nodejs24-devel, AlmaLinux:10: nodejs24-docs, AlmaLinux:10: nodejs24-full-i18n, AlmaLinux:10: nodejs24-libs, AlmaLinux:10: nodejs24-npm&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
  * undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
  * undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)
  * undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)
  * undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)
  * undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)
  * undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)
  * nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)
  * nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)
  * nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)
  * nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: nodejs24, AlmaLinux:10: nodejs24-devel, AlmaLinux:10: nodejs24-docs, AlmaLinux:10: nodejs24-full-i18n, AlmaLinux:10: nodejs24-libs, AlmaLinux:10: nodejs24-npm&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
  * undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
  * undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)
  * undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)
  * undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)
  * undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)
  * undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)
  * nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)
  * nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)
  * nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)
  * nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:35841</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-ID18571 — brace-expansion through 5</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-id18571</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: npm&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the npm package. brace-expansion through 5. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: npm&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the npm package. brace-expansion through 5. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-id18571</guid>
    </item>
    <item>
      <title>EUVD-2026-328307</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328307</link>
      <description>EUVD-2026-328307</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328307</guid>
    </item>
    <item>
      <title>fkie_cve-2026-6733</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-6733</link>
      <description>&lt;p&gt;Impact:
Undici&amp;#39;s HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests.&lt;/p&gt;
&lt;p&gt;This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse.&lt;/p&gt;
&lt;p&gt;Patches:
Upgrade to undici v6.26.0, v7.28.0 or v8.5.0.&lt;/p&gt;
&lt;p&gt;Workarounds:
Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Impact:
Undici&amp;#39;s HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests.&lt;/p&gt;
&lt;p&gt;This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse.&lt;/p&gt;
&lt;p&gt;Patches:
Upgrade to undici v6.26.0, v7.28.0 or v8.5.0.&lt;/p&gt;
&lt;p&gt;Workarounds:
Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-6733</guid>
    </item>
    <item>
      <title>GHSA-35p6-xmwp-9g52 — undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-35p6-xmwp-9g52</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Undici&amp;#39;s HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests.&lt;/p&gt;
&lt;p&gt;This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Upgrade to undici v6.27.0, v7.28.0 or v8.5.0.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Disable keep-alive connection reuse by setting `keepAliveTimeout: 0` on the Client or Pool.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Undici&amp;#39;s HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests.&lt;/p&gt;
&lt;p&gt;This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Upgrade to undici v6.27.0, v7.28.0 or v8.5.0.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Disable keep-alive connection reuse by setting `keepAliveTimeout: 0` on the Client or Pool.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-35p6-xmwp-9g52</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11121-1 — corepack24-24.17.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11121-1</link>
      <description>&lt;p&gt;corepack24-24.17.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;corepack24-24.17.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11121-1</guid>
    </item>
    <item>
      <title>RHSA-2026:38009 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:38009</link>
      <description>&lt;p&gt;undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:38009</guid>
    </item>
    <item>
      <title>RLSA-2026:35841 — Important: nodejs24 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:35841</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs24&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)&lt;/p&gt;
&lt;p&gt;* undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)&lt;/p&gt;
&lt;p&gt;* undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)&lt;/p&gt;
&lt;p&gt;* undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)&lt;/p&gt;
&lt;p&gt;* undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs24&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)&lt;/p&gt;
&lt;p&gt;* undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)&lt;/p&gt;
&lt;p&gt;* undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)&lt;/p&gt;
&lt;p&gt;* undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)&lt;/p&gt;
&lt;p&gt;* undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:35841</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22368-1 — Security update for nodejs22</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22368-1</link>
      <description>&lt;p&gt;Security update for nodejs22&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs22&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22368-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-6733</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-6733</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;Impact: Undici&amp;#39;s HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;Impact: Undici&amp;#39;s HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-6733</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2618 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2618</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2618</guid>
    </item>
  </channel>
</rss>
