<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:27:09 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-HR55516 — nanoid is a secure, URL-friendly, unique string ID generator for JavaScript</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-hr55516</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: qdrant&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the qdrant package. nanoid is a secure, URL-friendly, unique string ID generator for JavaScript.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: qdrant&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the qdrant package. nanoid is a secure, URL-friendly, unique string ID generator for JavaScript.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-hr55516</guid>
    </item>
    <item>
      <title>EUVD-2026-351488</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351488</link>
      <description>EUVD-2026-351488</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351488</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73086</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73086</link>
      <description>&lt;p&gt;nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string &amp;#34;uuuuuuuuuuuuuuuuuuuuu&amp;#34; until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string &amp;#34;uuuuuuuuuuuuuuuuuuuuu&amp;#34; until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73086</guid>
    </item>
    <item>
      <title>GHSA-xwg4-73v4-xw9w — nanoid: Integer Overflow or Wraparound</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xwg4-73v4-xw9w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nanoid&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An integer overflow in `nanoid(size)` permanently corrupts the process-wide CSPRNG pool, causing all subsequent ID generation to return the deterministic string `&amp;#34;uuuuuuuuuuuuuuuuuuuuu&amp;#34;`. Any application that passes user-influenced values to the `size` parameter loses all randomness guarantees for session tokens, CSRF tokens, and unique identifiers until process restart.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`nanoid()` at [`index.js:101`](https://github.com/ai/nanoid/blob/main/index.js#L101) coerces the `size` parameter with `size |= 0`, which converts it to a signed 32-bit integer. When `size &amp;gt;= 2^31` (e.g., `2147483648`), this wraps to `-2147483648`.&lt;/p&gt;
&lt;p&gt;The negative value is passed to `fillPool()` ([`index.js:15`](https://github.com/ai/nanoid/blob/main/index.js#L15)):&lt;/p&gt;
&lt;p&gt;```javascript
function fillPool(bytes) {
  if (!pool || pool.length &amp;lt; bytes) {       // false: pool exists, -2B &amp;lt; pool.length
    pool = Buffer.allocUnsafe(bytes * POOL_SIZE_MULTIPLIER)
    crypto.getRandomValues(pool)
    poolOffset = 0
  } else if (poolOffset + bytes &amp;gt; pool.length) {  // false: poolOffset + (-2B) &amp;lt; pool.length
    crypto.getRandomValues(pool)
    poolOffset = 0
  }
  poolOffset += bytes  // poolOffset += -2147483648 → deeply negative
}
```&lt;/p&gt;
&lt;p&gt;Neither branch triggers, so the pool is never refreshed. `poolOffset` becomes ~-2.1 billion.&lt;/p&gt;
&lt;p&gt;Subsequent `nanoid()` calls execute:
```javascript
for (let i = poolOffset - size; i &amp;lt; poolOffset; i++) {
  id += scopedUrlAlphabet[pool[i] &amp;amp; 63]
}
```&lt;/p&gt;
&lt;p&gt;`pool[negative_inde…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nanoid&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An integer overflow in `nanoid(size)` permanently corrupts the process-wide CSPRNG pool, causing all subsequent ID generation to return the deterministic string `&amp;#34;uuuuuuuuuuuuuuuuuuuuu&amp;#34;`. Any application that passes user-influenced values to the `size` parameter loses all randomness guarantees for session tokens, CSRF tokens, and unique identifiers until process restart.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`nanoid()` at [`index.js:101`](https://github.com/ai/nanoid/blob/main/index.js#L101) coerces the `size` parameter with `size |= 0`, which converts it to a signed 32-bit integer. When `size &amp;gt;= 2^31` (e.g., `2147483648`), this wraps to `-2147483648`.&lt;/p&gt;
&lt;p&gt;The negative value is passed to `fillPool()` ([`index.js:15`](https://github.com/ai/nanoid/blob/main/index.js#L15)):&lt;/p&gt;
&lt;p&gt;```javascript
function fillPool(bytes) {
  if (!pool || pool.length &amp;lt; bytes) {       // false: pool exists, -2B &amp;lt; pool.length
    pool = Buffer.allocUnsafe(bytes * POOL_SIZE_MULTIPLIER)
    crypto.getRandomValues(pool)
    poolOffset = 0
  } else if (poolOffset + bytes &amp;gt; pool.length) {  // false: poolOffset + (-2B) &amp;lt; pool.length
    crypto.getRandomValues(pool)
    poolOffset = 0
  }
  poolOffset += bytes  // poolOffset += -2147483648 → deeply negative
}
```&lt;/p&gt;
&lt;p&gt;Neither branch triggers, so the pool is never refreshed. `poolOffset` becomes ~-2.1 billion.&lt;/p&gt;
&lt;p&gt;Subsequent `nanoid()` calls execute:
```javascript
for (let i = poolOffset - size; i &amp;lt; poolOffset; i++) {
  id += scopedUrlAlphabet[pool[i] &amp;amp; 63]
}
```&lt;/p&gt;
&lt;p&gt;`pool[negative_inde…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xwg4-73v4-xw9w</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11680-1 — agama-web-ui-24+0.a836cced5-52.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1</link>
      <description>&lt;p&gt;agama-web-ui-24+0.a836cced5-52.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;agama-web-ui-24+0.a836cced5-52.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1</guid>
    </item>
    <item>
      <title>RHSA-2026:48758 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:48758</link>
      <description>&lt;p&gt;pyOpenSSL: DTLS cookie callback buffer overflow joserfc: joserfc: JWT Malleability via Non-Standard Padding axios: axios: Denial of Service via uncontrolled recursion in form data processing axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter axios: axios: Denial of Service via object serialization bypass nanoid: nanoid: Predictable ID generation due to integer overflow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pyOpenSSL: DTLS cookie callback buffer overflow joserfc: joserfc: JWT Malleability via Non-Standard Padding axios: axios: Denial of Service via uncontrolled recursion in form data processing axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter axios: axios: Denial of Service via object serialization bypass nanoid: nanoid: Predictable ID generation due to integer overflow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:48758</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-73086</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73086</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-mocha, Ubuntu:18.04:LTS: node-mocha, Ubuntu:20.04:LTS: node-mocha, Ubuntu:20.04:LTS: node-postcss, Ubuntu:22.04:LTS: node-postcss, Ubuntu:24.04:LTS: node-postcss, Ubuntu:26.04:LTS: node-postcss&lt;/p&gt;
&lt;p&gt;nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string &amp;#34;uuuuuuuuuuuuuuuuuuuuu&amp;#34; until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-mocha, Ubuntu:18.04:LTS: node-mocha, Ubuntu:20.04:LTS: node-mocha, Ubuntu:20.04:LTS: node-postcss, Ubuntu:22.04:LTS: node-postcss, Ubuntu:24.04:LTS: node-postcss, Ubuntu:26.04:LTS: node-postcss&lt;/p&gt;
&lt;p&gt;nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string &amp;#34;uuuuuuuuuuuuuuuuuuuuu&amp;#34; until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73086</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3376 — Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management: Mehrere Schwachst…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3376</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, serverseitige Request-Forgery-Angriffe (SSRF) durchzuführen, Cross-Site-Scripting-Angriffe zu starten, sensible Informationen offenzulegen, Daten zu manipulieren oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, serverseitige Request-Forgery-Angriffe (SSRF) durchzuführen, Cross-Site-Scripting-Angriffe zu starten, sensible Informationen offenzulegen, Daten zu manipulieren oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3376</guid>
    </item>
  </channel>
</rss>
