<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:34:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-362044</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362044</link>
      <description>EUVD-2026-362044</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362044</guid>
    </item>
    <item>
      <title>fkie_cve-2026-77063</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-77063</link>
      <description>&lt;p&gt;multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition in multer&amp;#39;s file stream handling can allow a file that exceeds the configured size limit to bypass the size-limit rejection. All versions before 2.3.0 are affected. The impact is limited because the underlying multipart parser still truncates the stream at the size limit, so this is a bypass of the limit rejection rather than uncontrolled resource consumption. The issue is fixed in multer 2.3.0. Upgrade to multer 2.3.0 to remediate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition in multer&amp;#39;s file stream handling can allow a file that exceeds the configured size limit to bypass the size-limit rejection. All versions before 2.3.0 are affected. The impact is limited because the underlying multipart parser still truncates the stream at the size limit, so this is a bypass of the limit rejection rather than uncontrolled resource consumption. The issue is fixed in multer 2.3.0. Upgrade to multer 2.3.0 to remediate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-77063</guid>
    </item>
    <item>
      <title>GHSA-qvfw-j98x-7q72 — multer vulnerable to file size limit bypass via async fileFilter race condition</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qvfw-j98x-7q72</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: multer&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When `multer` is configured with an asynchronous `fileFilter`, the `limits.fileSize` limit can be bypassed. The `&amp;#39;limit&amp;#39;` event is registered inside the async `fileFilter` callback, so if a file exceeds `limits.fileSize` before that callback runs, the event is missed and the oversized upload is accepted instead of being rejected with a `LIMIT_FILE_SIZE` error. Applications that rely on `limits.fileSize` to reject oversized uploads are affected on all upload methods (`.single()`, `.array()`, `.fields()`, `.any()`). Uploads using a synchronous `fileFilter` are not affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Users should upgrade to `2.3.0`.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Use a synchronous `fileFilter`, or validate the uploaded file size after the upload completes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: multer&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When `multer` is configured with an asynchronous `fileFilter`, the `limits.fileSize` limit can be bypassed. The `&amp;#39;limit&amp;#39;` event is registered inside the async `fileFilter` callback, so if a file exceeds `limits.fileSize` before that callback runs, the event is missed and the oversized upload is accepted instead of being rejected with a `LIMIT_FILE_SIZE` error. Applications that rely on `limits.fileSize` to reject oversized uploads are affected on all upload methods (`.single()`, `.array()`, `.fields()`, `.any()`). Uploads using a synchronous `fileFilter` are not affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Users should upgrade to `2.3.0`.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Use a synchronous `fileFilter`, or validate the uploaded file size after the upload completes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qvfw-j98x-7q72</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
