<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:53:53 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:52841 — Important: nodejs-nodemon security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:52841</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: nodejs-nodemon&lt;/p&gt;
&lt;p&gt;Simple monitor script for use during development of a node.js app. For use during development of a node.js based application. nodemon will watch the files in the directory in which nodemon was started, and if any files change, nodemon will automatically restart your node application. nodemon does not require any changes to your code or method of development. nodemon simply wraps your node application and keeps an eye on any files that have changed. Remember that nodemon is a replacement wrapper for node, think of it as replacing the word &amp;#34;node&amp;#34; on the command line when you run your script.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: nodejs-nodemon&lt;/p&gt;
&lt;p&gt;Simple monitor script for use during development of a node.js app. For use during development of a node.js based application. nodemon will watch the files in the directory in which nodemon was started, and if any files change, nodemon will automatically restart your node application. nodemon does not require any changes to your code or method of development. nodemon simply wraps your node application and keeps an eye on any files that have changed. Remember that nodemon is a replacement wrapper for node, think of it as replacing the word &amp;#34;node&amp;#34; on the command line when you run your script.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:52841</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AE26966 — Security fix for CVE-2026-69152 applied in: argo-workflows 3.6.19-r7, langfuse-worker 3.224.0-r3, langfuse-worker 3.224…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ae26966</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows, CleanStart: langfuse-worker, CleanStart: n8n, CleanStart: npm, CleanStart: pulumi, CleanStart: renovate&lt;/p&gt;
&lt;p&gt;CVE-2026-69152 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-workflows, CleanStart: langfuse-worker, CleanStart: n8n, CleanStart: npm, CleanStart: pulumi, CleanStart: renovate&lt;/p&gt;
&lt;p&gt;CVE-2026-69152 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ae26966</guid>
    </item>
    <item>
      <title>EUVD-2026-343962</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343962</link>
      <description>EUVD-2026-343962</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343962</guid>
    </item>
    <item>
      <title>fkie_cve-2026-69152</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69152</link>
      <description>&lt;p&gt;The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-69152</guid>
    </item>
    <item>
      <title>GHSA-rgw5-rvv9-x895 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rgw5-rvv9-x895</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: brace-expansion&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `maxLength` mitigation added in `5.0.8` for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are *combined*, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an **uncatchable** out-of-memory error, so `try/catch` around `expand()` does not help.&lt;/p&gt;
&lt;p&gt;A second, related path in the same function lets a ~400 KB input block the event loop for over two minutes without ever exceeding the memory bound.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`maxLength` was enforced in `combine()`, the single place output grows. Two arrays are built *before* `combine()` runs, and neither was bounded.&lt;/p&gt;
&lt;p&gt;**1. Comma alternatives accumulate without a running total (memory exhaustion)**&lt;/p&gt;
&lt;p&gt;Each alternative in `{a,b,c,...}` is expanded by its own recursive `expand_()` call, so each receives a full, independent `maxLength` allowance. The results were then concatenated into a single `values` array with no cumulative limit:&lt;/p&gt;
&lt;p&gt;```js
values = []
for (let j = 0; j &amp;lt; n.length; j++) {
  values.push.apply(values, expand_(n[j], max, maxLength, false))
}&lt;/p&gt;
&lt;p&gt;acc = combine(acc, pre, values, max, maxLength, ...)
```&lt;/p&gt;
&lt;p&gt;With `A` alternatives, `values` can reach `A * maxLength` characters before `combine()` gets a chance to truncate it. At the default `maxLength` of 4,000,000 and 400 alternatives, that is well past any default heap.&lt;/p&gt;
&lt;p&gt;**2. Padded sequences ignore `maxLength` while generating (CPU exhaustion)**&lt;/p&gt;
&lt;p&gt;`expandSequence()` was bounded by `max` (…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: brace-expansion&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `maxLength` mitigation added in `5.0.8` for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are *combined*, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an **uncatchable** out-of-memory error, so `try/catch` around `expand()` does not help.&lt;/p&gt;
&lt;p&gt;A second, related path in the same function lets a ~400 KB input block the event loop for over two minutes without ever exceeding the memory bound.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`maxLength` was enforced in `combine()`, the single place output grows. Two arrays are built *before* `combine()` runs, and neither was bounded.&lt;/p&gt;
&lt;p&gt;**1. Comma alternatives accumulate without a running total (memory exhaustion)**&lt;/p&gt;
&lt;p&gt;Each alternative in `{a,b,c,...}` is expanded by its own recursive `expand_()` call, so each receives a full, independent `maxLength` allowance. The results were then concatenated into a single `values` array with no cumulative limit:&lt;/p&gt;
&lt;p&gt;```js
values = []
for (let j = 0; j &amp;lt; n.length; j++) {
  values.push.apply(values, expand_(n[j], max, maxLength, false))
}&lt;/p&gt;
&lt;p&gt;acc = combine(acc, pre, values, max, maxLength, ...)
```&lt;/p&gt;
&lt;p&gt;With `A` alternatives, `values` can reach `A * maxLength` characters before `combine()` gets a chance to truncate it. At the default `maxLength` of 4,000,000 and 400 alternatives, that is well past any default heap.&lt;/p&gt;
&lt;p&gt;**2. Padded sequences ignore `maxLength` while generating (CPU exhaustion)**&lt;/p&gt;
&lt;p&gt;`expandSequence()` was bounded by `max` (…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rgw5-rvv9-x895</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-69152</link>
      <description>msrc_CVE-2026-69152</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-69152</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>RHSA-2026:50079 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:50079</link>
      <description>&lt;p&gt;brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation postcss: PostCSS: Information disclosure via crafted sourceMappingURL&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation postcss: PostCSS: Information disclosure via crafted sourceMappingURL&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:50079</guid>
    </item>
    <item>
      <title>RHSA-2026:52841 — Red Hat Security Advisory: nodejs-nodemon security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:52841</link>
      <description>&lt;p&gt;brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:52841</guid>
    </item>
    <item>
      <title>RLSA-2026:52841 — Important: nodejs-nodemon security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:52841</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs-nodemon&lt;/p&gt;
&lt;p&gt;Simple monitor script for use during development of a node.js app.  For use during development of a node.js based application.  nodemon will watch the files in the directory in which nodemon was started, and if any files change, nodemon will automatically restart your node application.  nodemon does not require any changes to your code or method of development. nodemon simply wraps your node application and keeps an eye on any files that have changed. Remember that nodemon is a replacement wrapper for node, think of it as replacing the word &amp;#34;node&amp;#34; on the command line when you run your script.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs-nodemon&lt;/p&gt;
&lt;p&gt;Simple monitor script for use during development of a node.js app.  For use during development of a node.js based application.  nodemon will watch the files in the directory in which nodemon was started, and if any files change, nodemon will automatically restart your node application.  nodemon does not require any changes to your code or method of development. nodemon simply wraps your node application and keeps an eye on any files that have changed. Remember that nodemon is a replacement wrapper for node, think of it as replacing the word &amp;#34;node&amp;#34; on the command line when you run your script.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:52841</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-69152</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69152</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:26.04:LTS: node-brace-expansion&lt;/p&gt;
&lt;p&gt;The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-brace-expansion, Ubuntu:20.04:LTS: node-brace-expansion, Ubuntu:22.04:LTS: node-brace-expansion, Ubuntu:24.04:LTS: node-brace-expansion, Ubuntu:26.04:LTS: node-brace-expansion&lt;/p&gt;
&lt;p&gt;The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69152</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2725 — Red Hat Enterprise Linux (brace-expansion): Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2725</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2725</guid>
    </item>
  </channel>
</rss>
