<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:21:14 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1233 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</link>
      <description>certfr-2026-avi-1233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-MU53391 — ### Summary



When `qs</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-mu53391</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the langfuse package. ### Summary When `qs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the langfuse package. ### Summary When `qs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-mu53391</guid>
    </item>
    <item>
      <title>EUVD-2026-361964</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361964</link>
      <description>EUVD-2026-361964</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361964</guid>
    </item>
    <item>
      <title>fkie_cve-2026-82562</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-82562</link>
      <description>&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`), an indexed key (`a[0]=`), a nested key (`a[b]=`), or a dotted key (`a.b=` with `allowDots`) throws the documented `RangeError`. A single parameter such as `a[]=1,2,2,...` therefore produces an inner array of arbitrary length even though the caller opted into the hard limit. This is the `[]=` key form that the fix for CVE-2026-2391 (qs 6.14.2) did not cover.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `lib/parse.js`, a comma-separated value under a `[]=` key is split and then wrapped as a single nested element (`val = [val]`, so that each `a[]=x,y` group counts as one element of the outer array). The `arrayLimit` check that 6.14.2 added for comma values runs after that wrap, so for `[]=` parts it only ever saw the wrapper of length 1. 6.15.3 added a pre-split comma count so that an oversized value throws before it is allocated, but gated it on an `isFlatArrayValue` flag that `parseValues` set to `false` for any part containing `[]=`, and did not pass it for object-valued input, so the gap remained.&lt;/p&gt;
&lt;p&gt;#### PoC&lt;/p&gt;
&lt;p&gt;```js&lt;/p&gt;
&lt;p&gt;var qs = require(&amp;#39;qs&amp;#39;);&lt;/p&gt;
&lt;p&gt;var options = { comma: true, arrayLimit: 3, throwOnLimitExceeded: true };&lt;/p&gt;
&lt;p&gt;qs.parse(&amp;#39;a=1,2,3,4&amp;#39;, options);   // RangeError: Array limit exceeded. Only 3 elements allowed in an…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`), an indexed key (`a[0]=`), a nested key (`a[b]=`), or a dotted key (`a.b=` with `allowDots`) throws the documented `RangeError`. A single parameter such as `a[]=1,2,2,...` therefore produces an inner array of arbitrary length even though the caller opted into the hard limit. This is the `[]=` key form that the fix for CVE-2026-2391 (qs 6.14.2) did not cover.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In `lib/parse.js`, a comma-separated value under a `[]=` key is split and then wrapped as a single nested element (`val = [val]`, so that each `a[]=x,y` group counts as one element of the outer array). The `arrayLimit` check that 6.14.2 added for comma values runs after that wrap, so for `[]=` parts it only ever saw the wrapper of length 1. 6.15.3 added a pre-split comma count so that an oversized value throws before it is allocated, but gated it on an `isFlatArrayValue` flag that `parseValues` set to `false` for any part containing `[]=`, and did not pass it for object-valued input, so the gap remained.&lt;/p&gt;
&lt;p&gt;#### PoC&lt;/p&gt;
&lt;p&gt;```js&lt;/p&gt;
&lt;p&gt;var qs = require(&amp;#39;qs&amp;#39;);&lt;/p&gt;
&lt;p&gt;var options = { comma: true, arrayLimit: 3, throwOnLimitExceeded: true };&lt;/p&gt;
&lt;p&gt;qs.parse(&amp;#39;a=1,2,3,4&amp;#39;, options);   // RangeError: Array limit exceeded. Only 3 elements allowed in an…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-82562</guid>
    </item>
    <item>
      <title>GHSA-x5fp-wj9c-mxmx — qs array-limit bypass via bracket-key comma parsing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x5fp-wj9c-mxmx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: qs&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`qs` `v6.15.3` allows bracket-key input to bypass `arrayLimit` and `throwOnLimitExceeded` when `comma: true`. The input `a[]=1,2,3,4` succeeds with `arrayLimit: 3`, while the equivalent plain-key input is rejected.&lt;/p&gt;
&lt;p&gt;Affected version tested:&lt;/p&gt;
&lt;p&gt;```text
qs v6.15.3
commit 18d085e919dae70c8f1b200ab99323058edab2c2
```&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`parseArrayValue()` enforces the comma limit only for flat values. The `a[]` form is marked non-flat, so its comma-separated value is wrapped after parsing and the inner array is not checked. A single parameter can therefore materialize arbitrarily large arrays.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
const qs = require(&amp;#39;qs&amp;#39;)
const options = { comma: true, arrayLimit: 3, throwOnLimitExceeded: true }&lt;/p&gt;
&lt;p&gt;const result = qs.parse(&amp;#39;a[]=1,2,3,4&amp;#39;, options)
console.log(result.a[0].length) // 4; expected RangeError&lt;/p&gt;
&lt;p&gt;const big = qs.parse(&amp;#39;a[]=&amp;#39; + &amp;#39;1,&amp;#39;.repeat(1000000) + &amp;#39;1&amp;#39;, { comma: true, arrayLimit: 20 })
console.log(big.a[0].length) // 1000001
```&lt;/p&gt;
&lt;p&gt;On `v6.15.3`, the first input parses successfully and the second creates an array with 1,000,001 elements. The equivalent `a=1,2,3,4` input throws `RangeError` as expected.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker who can supply a query string or form body can bypass configured array limits and force excessive memory allocation, causing denial of service. The limit must be applied after comma splitting and before the resulting array is wrapped.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: qs&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`qs` `v6.15.3` allows bracket-key input to bypass `arrayLimit` and `throwOnLimitExceeded` when `comma: true`. The input `a[]=1,2,3,4` succeeds with `arrayLimit: 3`, while the equivalent plain-key input is rejected.&lt;/p&gt;
&lt;p&gt;Affected version tested:&lt;/p&gt;
&lt;p&gt;```text
qs v6.15.3
commit 18d085e919dae70c8f1b200ab99323058edab2c2
```&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`parseArrayValue()` enforces the comma limit only for flat values. The `a[]` form is marked non-flat, so its comma-separated value is wrapped after parsing and the inner array is not checked. A single parameter can therefore materialize arbitrarily large arrays.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
const qs = require(&amp;#39;qs&amp;#39;)
const options = { comma: true, arrayLimit: 3, throwOnLimitExceeded: true }&lt;/p&gt;
&lt;p&gt;const result = qs.parse(&amp;#39;a[]=1,2,3,4&amp;#39;, options)
console.log(result.a[0].length) // 4; expected RangeError&lt;/p&gt;
&lt;p&gt;const big = qs.parse(&amp;#39;a[]=&amp;#39; + &amp;#39;1,&amp;#39;.repeat(1000000) + &amp;#39;1&amp;#39;, { comma: true, arrayLimit: 20 })
console.log(big.a[0].length) // 1000001
```&lt;/p&gt;
&lt;p&gt;On `v6.15.3`, the first input parses successfully and the second creates an array with 1,000,001 elements. The equivalent `a=1,2,3,4` input throws `RangeError` as expected.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker who can supply a query string or form body can bypass configured array limits and force excessive memory allocation, causing denial of service. The limit must be applied after comma splitting and before the resulting array is wrapped.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x5fp-wj9c-mxmx</guid>
    </item>
    <item>
      <title>RHSA-2026:60866 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:60866</link>
      <description>&lt;p&gt;github.com/getkin/kin-openapi: kin-openapi: kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects qs: qs: Denial of Service via array limit bypass in query string parsing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/getkin/kin-openapi: kin-openapi: kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects qs: qs: Denial of Service via array limit bypass in query string parsing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:60866</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-82562</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82562</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-qs, Ubuntu:16.04:LTS: node-qs, Ubuntu:18.04:LTS: node-qs, Ubuntu:Pro:20.04:LTS: node-qs, Ubuntu:22.04:LTS: node-qs, Ubuntu:24.04:LTS: node-qs, Ubuntu:26.04:LTS: node-qs&lt;/p&gt;
&lt;p&gt;### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`), an indexed key (`a[0]=`), a nested key (`a[b]=`), or a dotted key (`a.b=` with `allowDots`) throws the documented `RangeError`. A single parameter such as `a[]=1,2,2,...` therefore produces an inner array of arbitrary length even though the caller opted into the hard limit. This is the `[]=` key form that the fix for CVE-2026-2391 (qs 6.14.2) did not cover. ### Details In `lib/parse.js`, a comma-separated value under a `[]=` key is split and then wrapped as a single nested element (`val = [val]`, so that each `a[]=x,y` group counts as one element of the outer array). The `arrayLimit` check that 6.14.2 added for comma values runs after that wrap, so for `[]=` parts it only ever saw the wrapper of length 1. 6.15.3 added a pre-split comma count so that an oversized value throws before it is allocated, but gated it on an `isFlatArrayValue` flag that `parseValues` set to `false` for any part containing `[]=`, and did not pass it for object-valued input, so the gap remained. #### PoC ```js var qs = require(&amp;#39;qs&amp;#39;); var options = { comma: true, arrayLimit: 3, throwOnLimitExceeded: true }; qs.parse(&amp;#39;a=1,2,3,4&amp;#39;, options);   // RangeError: Array limit exceeded. Only 3 elements allowed in an array. qs.parse(&amp;#39;a[]=1,2…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-qs, Ubuntu:16.04:LTS: node-qs, Ubuntu:18.04:LTS: node-qs, Ubuntu:Pro:20.04:LTS: node-qs, Ubuntu:22.04:LTS: node-qs, Ubuntu:24.04:LTS: node-qs, Ubuntu:26.04:LTS: node-qs&lt;/p&gt;
&lt;p&gt;### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`), an indexed key (`a[0]=`), a nested key (`a[b]=`), or a dotted key (`a.b=` with `allowDots`) throws the documented `RangeError`. A single parameter such as `a[]=1,2,2,...` therefore produces an inner array of arbitrary length even though the caller opted into the hard limit. This is the `[]=` key form that the fix for CVE-2026-2391 (qs 6.14.2) did not cover. ### Details In `lib/parse.js`, a comma-separated value under a `[]=` key is split and then wrapped as a single nested element (`val = [val]`, so that each `a[]=x,y` group counts as one element of the outer array). The `arrayLimit` check that 6.14.2 added for comma values runs after that wrap, so for `[]=` parts it only ever saw the wrapper of length 1. 6.15.3 added a pre-split comma count so that an oversized value throws before it is allocated, but gated it on an `isFlatArrayValue` flag that `parseValues` set to `false` for any part containing `[]=`, and did not pass it for object-valued input, so the gap remained. #### PoC ```js var qs = require(&amp;#39;qs&amp;#39;); var options = { comma: true, arrayLimit: 3, throwOnLimitExceeded: true }; qs.parse(&amp;#39;a=1,2,3,4&amp;#39;, options);   // RangeError: Array limit exceeded. Only 3 elements allowed in an array. qs.parse(&amp;#39;a[]=1,2…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82562</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
