<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:46:12 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BG95605 — Security fixes in langfuse-worker 4.0.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bg95605</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 4.0.0-r1 fixes 24 vulnerabilities: ghsa-55q2-fjhq-7xh7, CVE-2026-18446, CVE-2026-69207, CVE-2026-71848, CVE-2026-71850...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 4.0.0-r1 fixes 24 vulnerabilities: ghsa-55q2-fjhq-7xh7, CVE-2026-18446, CVE-2026-69207, CVE-2026-71848, CVE-2026-71850...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bg95605</guid>
    </item>
    <item>
      <title>EUVD-2026-349519</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349519</link>
      <description>EUVD-2026-349519</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349519</guid>
    </item>
    <item>
      <title>fkie_cve-2026-71848</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71848</link>
      <description>&lt;p&gt;Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen separated subtags. To implement progressive language tag truncation, normalizeLanguage() repeatedly calls parts.slice(0, i).join(&amp;#39;-&amp;#39;) for every possible prefix, so the total amount of string processing grows quadratically with the number of subtags. Language values may come from a query parameter, cookie, Accept-Language header, or URL path, depending on the detector configuration, and the default detector order enables query string, cookie, and header detection, so applications using languageDetector() may expose this processing to unauthenticated requests. An attacker may repeatedly send requests containing long, hyphen separated language tags, causing excessive CPU consumption and preventing unrelated requests from being processed. This issue is fixed in version 4.12.34.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen separated subtags. To implement progressive language tag truncation, normalizeLanguage() repeatedly calls parts.slice(0, i).join(&amp;#39;-&amp;#39;) for every possible prefix, so the total amount of string processing grows quadratically with the number of subtags. Language values may come from a query parameter, cookie, Accept-Language header, or URL path, depending on the detector configuration, and the default detector order enables query string, cookie, and header detection, so applications using languageDetector() may expose this processing to unauthenticated requests. An attacker may repeatedly send requests containing long, hyphen separated language tags, causing excessive CPU consumption and preventing unrelated requests from being processed. This issue is fixed in version 4.12.34.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-71848</guid>
    </item>
    <item>
      <title>GHSA-54fx-42gc-7vw4 — Hono: Algorithmic Complexity DoS in Language Middleware</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-54fx-42gc-7vw4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: hono&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `languageDetector` middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;To implement progressive language-tag truncation, `normalizeLanguage()` repeatedly calls `parts.slice(0, i).join(&amp;#39;-&amp;#39;)` for every possible prefix. The total amount of string processing grows quadratically with the number of subtags.&lt;/p&gt;
&lt;p&gt;Language values may come from a query parameter, cookie, `Accept-Language` header, or URL path, depending on the detector configuration. The default detector order enables query-string, cookie, and header detection, so applications using `languageDetector()` may expose this processing to unauthenticated requests.&lt;/p&gt;
&lt;p&gt;Request-size limits reduce the maximum cost of a single request but do not eliminate the issue. Inputs accepted by common JavaScript runtimes can still cause noticeable synchronous event-loop blocking.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker may repeatedly send requests containing long, hyphen-separated language tags, causing excessive CPU consumption and preventing unrelated requests from being processed.&lt;/p&gt;
&lt;p&gt;The practical impact depends on the runtime&amp;#39;s request-size limits, reverse-proxy configuration, and the detectors enabled by the application.&lt;/p&gt;
&lt;p&gt;### Resolution&lt;/p&gt;
&lt;p&gt;The progressive lookup should avoid reconstructing every shorter prefix. The implementation can instead inspect the configured supported languages and select the longest value that m…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: hono&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `languageDetector` middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;To implement progressive language-tag truncation, `normalizeLanguage()` repeatedly calls `parts.slice(0, i).join(&amp;#39;-&amp;#39;)` for every possible prefix. The total amount of string processing grows quadratically with the number of subtags.&lt;/p&gt;
&lt;p&gt;Language values may come from a query parameter, cookie, `Accept-Language` header, or URL path, depending on the detector configuration. The default detector order enables query-string, cookie, and header detection, so applications using `languageDetector()` may expose this processing to unauthenticated requests.&lt;/p&gt;
&lt;p&gt;Request-size limits reduce the maximum cost of a single request but do not eliminate the issue. Inputs accepted by common JavaScript runtimes can still cause noticeable synchronous event-loop blocking.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker may repeatedly send requests containing long, hyphen-separated language tags, causing excessive CPU consumption and preventing unrelated requests from being processed.&lt;/p&gt;
&lt;p&gt;The practical impact depends on the runtime&amp;#39;s request-size limits, reverse-proxy configuration, and the detectors enabled by the application.&lt;/p&gt;
&lt;p&gt;### Resolution&lt;/p&gt;
&lt;p&gt;The progressive lookup should avoid reconstructing every shorter prefix. The implementation can instead inspect the configured supported languages and select the longest value that m…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-54fx-42gc-7vw4</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3221 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3221</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3221</guid>
    </item>
  </channel>
</rss>
