<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:32:23 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BG21634 — Security fixes in langfuse-worker 3.216.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bg21634</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 3.216.0-r1 fixes 29 vulnerabilities: ghsa-frvp-7c67-39w9, ghsa-p63j-vcc4-9vmv, ghsa-55q2-fjhq-7xh7, ghsa-c2j3-45gr-mqc4, CVE-2026-69192...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 3.216.0-r1 fixes 29 vulnerabilities: ghsa-frvp-7c67-39w9, ghsa-p63j-vcc4-9vmv, ghsa-55q2-fjhq-7xh7, ghsa-c2j3-45gr-mqc4, CVE-2026-69192...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bg21634</guid>
    </item>
    <item>
      <title>EUVD-2026-344164</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344164</link>
      <description>EUVD-2026-344164</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344164</guid>
    </item>
    <item>
      <title>fkie_cve-2026-69198</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69198</link>
      <description>&lt;p&gt;ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address&amp;#39;s own subnet mask is shorter than the reference range&amp;#39;s mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address&amp;#39;s own subnet mask is shorter than the reference range&amp;#39;s mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-69198</guid>
    </item>
    <item>
      <title>GHSA-4xrf-jv44-h6hh — ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-bou…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4xrf-jv44-h6hh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ip-address&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Every special-use classification method is built on `isInSubnet`, which short-circuits to `false` whenever the address&amp;#39;s own subnet mask is *shorter* than the reference range&amp;#39;s mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as `/0` suppresses classification entirely: `isLoopback()`, `isPrivate()`, `isLinkLocal()`, `isCGNAT()`, `isMulticast()`, `isUnspecified()`, `isBroadcast()`, `isULA()`, and `getType()` all report an internal address as unremarkable, while `correctForm()` and `address` still return the real internal target.&lt;/p&gt;
&lt;p&gt;An application that builds a network trust-boundary decision on these checks (for example a filter intended to block Server-Side Request Forgery, or SSRF) may therefore treat an internal target as external and allow the request. SSRF is an attack in which a user-supplied address coaxes the server into making a request to an internal destination the user could not otherwise reach, such as a loopback service or a cloud metadata endpoint.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`isInSubnet` in `src/common.ts` opens with a guard that compares the two prefix lengths:&lt;/p&gt;
&lt;p&gt;```js
export function isInSubnet(this, address) {
  if (this.subnetMask &amp;lt; address.subnetMask) {
    return false;                                  // &amp;lt;-- reached before any bit comparison
  }&lt;/p&gt;
&lt;p&gt;if (this.mask(address.subnetMask) === address.mask()) {
    return true;
  }&lt;/p&gt;
&lt;p&gt;return false;
}
```&lt;/p&gt;
&lt;p&gt;That guard is correct for the question `isInSubnet` is named…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: ip-address&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Every special-use classification method is built on `isInSubnet`, which short-circuits to `false` whenever the address&amp;#39;s own subnet mask is *shorter* than the reference range&amp;#39;s mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as `/0` suppresses classification entirely: `isLoopback()`, `isPrivate()`, `isLinkLocal()`, `isCGNAT()`, `isMulticast()`, `isUnspecified()`, `isBroadcast()`, `isULA()`, and `getType()` all report an internal address as unremarkable, while `correctForm()` and `address` still return the real internal target.&lt;/p&gt;
&lt;p&gt;An application that builds a network trust-boundary decision on these checks (for example a filter intended to block Server-Side Request Forgery, or SSRF) may therefore treat an internal target as external and allow the request. SSRF is an attack in which a user-supplied address coaxes the server into making a request to an internal destination the user could not otherwise reach, such as a loopback service or a cloud metadata endpoint.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`isInSubnet` in `src/common.ts` opens with a guard that compares the two prefix lengths:&lt;/p&gt;
&lt;p&gt;```js
export function isInSubnet(this, address) {
  if (this.subnetMask &amp;lt; address.subnetMask) {
    return false;                                  // &amp;lt;-- reached before any bit comparison
  }&lt;/p&gt;
&lt;p&gt;if (this.mask(address.subnetMask) === address.mask()) {
    return true;
  }&lt;/p&gt;
&lt;p&gt;return false;
}
```&lt;/p&gt;
&lt;p&gt;That guard is correct for the question `isInSubnet` is named…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4xrf-jv44-h6hh</guid>
    </item>
    <item>
      <title>RHSA-2026:49401 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:49401</link>
      <description>&lt;p&gt;fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority axios: axios: Information disclosure and data manipulation via prototype pollution ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority axios: axios: Information disclosure and data manipulation via prototype pollution ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:49401</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-69198</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69198</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-ip-address, Ubuntu:22.04:LTS: node-ip-address, Ubuntu:24.04:LTS: node-ip-address, Ubuntu:26.04:LTS: node-ip-address&lt;/p&gt;
&lt;p&gt;ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address&amp;#39;s own subnet mask is shorter than the reference range&amp;#39;s mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-ip-address, Ubuntu:22.04:LTS: node-ip-address, Ubuntu:24.04:LTS: node-ip-address, Ubuntu:26.04:LTS: node-ip-address&lt;/p&gt;
&lt;p&gt;ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address&amp;#39;s own subnet mask is shorter than the reference range&amp;#39;s mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69198</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
