<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:02:40 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:71543 — Important: cockpit-image-builder security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:71543</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: cockpit-image-builder&lt;/p&gt;
&lt;p&gt;The image-builder-frontend generates custom images suitable for deploying systems or uploading to the cloud. It integrates into Cockpit as a frontend for osbuild.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)
  * fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)
  * fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)
  * fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: cockpit-image-builder&lt;/p&gt;
&lt;p&gt;The image-builder-frontend generates custom images suitable for deploying systems or uploading to the cloud. It integrates into Cockpit as a frontend for osbuild.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)
  * fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)
  * fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)
  * fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:71543</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1233 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</link>
      <description>certfr-2026-avi-1233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-CC59685 — fast-uri serializes the port component of a URI without validating it</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cc59685</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the langfuse package. fast-uri serializes the port component of a URI without validating it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the langfuse package. fast-uri serializes the port component of a URI without validating it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cc59685</guid>
    </item>
    <item>
      <title>EUVD-2026-363436</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363436</link>
      <description>EUVD-2026-363436</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363436</guid>
    </item>
    <item>
      <title>fkie_cve-2026-84292</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84292</link>
      <description>&lt;p&gt;fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node&amp;#39;s URL read the result back as the attacker&amp;#39;s host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node&amp;#39;s URL read the result back as the attacker&amp;#39;s host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-84292</guid>
    </item>
    <item>
      <title>GHSA-qw65-cvwx-89v3 — fast-uri vulnerable to authority injection via an unvalidated port in serialize</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qw65-cvwx-89v3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-uri&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;`fast-uri` serializes the `port` component of a URI without validating it. When recomposing the authority, `fast-uri` escapes the userinfo and host components but concatenates the port verbatim, so a `port` value that is not a sequence of digits can inject authority delimiters. For example, serializing a component whose `port` is `@127.0.0.1:8124` produces `http://trusted.example:@127.0.0.1:8124/app`, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both `fast-uri` and Node&amp;#39;s `URL` read the result back as the attacker&amp;#39;s host with no error, so re-validating the built URI does not catch it.&lt;/p&gt;
&lt;p&gt;This affects applications that build URIs from parts and assign untrusted data to the `port` component (for example a fixed host from configuration and a port taken from user input or a service record). The same path is reachable through `serialize()`, `normalize()`, and `equal()` in their object forms. A `port` obtained from `parse()` is always digits and is not affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This vulnerability has been patched in fast-uri `4.1.4`, `3.1.7`, and `2.4.6`. `recomposeAuthority` now rejects any port that is not `*DIGIT` per RFC 3986. All users should upgrade.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If upgrading is not immediately possible, validate the `port` value against the RFC 3986 grammar (digits only) before passing a component to `serialize()`, `normalize()`, or `equal()`, and reject anything else, for example `if (!/^\d*$/.test(String(po…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-uri&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;`fast-uri` serializes the `port` component of a URI without validating it. When recomposing the authority, `fast-uri` escapes the userinfo and host components but concatenates the port verbatim, so a `port` value that is not a sequence of digits can inject authority delimiters. For example, serializing a component whose `port` is `@127.0.0.1:8124` produces `http://trusted.example:@127.0.0.1:8124/app`, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both `fast-uri` and Node&amp;#39;s `URL` read the result back as the attacker&amp;#39;s host with no error, so re-validating the built URI does not catch it.&lt;/p&gt;
&lt;p&gt;This affects applications that build URIs from parts and assign untrusted data to the `port` component (for example a fixed host from configuration and a port taken from user input or a service record). The same path is reachable through `serialize()`, `normalize()`, and `equal()` in their object forms. A `port` obtained from `parse()` is always digits and is not affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This vulnerability has been patched in fast-uri `4.1.4`, `3.1.7`, and `2.4.6`. `recomposeAuthority` now rejects any port that is not `*DIGIT` per RFC 3986. All users should upgrade.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If upgrading is not immediately possible, validate the `port` value against the RFC 3986 grammar (digits only) before passing a component to `serialize()`, `normalize()`, or `equal()`, and reject anything else, for example `if (!/^\d*$/.test(String(po…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qw65-cvwx-89v3</guid>
    </item>
    <item>
      <title>RHSA-2026:63782 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:63782</link>
      <description>&lt;p&gt;fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies undici: undici: Denial of Service via unhandled error in WebSocket permessage-deflate decompression undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies undici: undici: Denial of Service via unhandled error in WebSocket permessage-deflate decompression undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:63782</guid>
    </item>
    <item>
      <title>RLSA-2026:71543 — Important: cockpit-image-builder security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:71543</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: cockpit-image-builder&lt;/p&gt;
&lt;p&gt;The image-builder-frontend generates custom images suitable for deploying systems or uploading to the cloud. It integrates into Cockpit as a frontend for osbuild.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)&lt;/p&gt;
&lt;p&gt;* fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)&lt;/p&gt;
&lt;p&gt;* fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)&lt;/p&gt;
&lt;p&gt;* fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: cockpit-image-builder&lt;/p&gt;
&lt;p&gt;The image-builder-frontend generates custom images suitable for deploying systems or uploading to the cloud. It integrates into Cockpit as a frontend for osbuild.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)&lt;/p&gt;
&lt;p&gt;* fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)&lt;/p&gt;
&lt;p&gt;* fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)&lt;/p&gt;
&lt;p&gt;* fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization (CVE-2026-84292)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:71543</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-84292</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-84292</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-ajv, Ubuntu:20.04:LTS: node-ajv, Ubuntu:22.04:LTS: node-ajv, Ubuntu:24.04:LTS: node-ajv, Ubuntu:26.04:LTS: node-ajv&lt;/p&gt;
&lt;p&gt;fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node&amp;#39;s URL read the result back as the attacker&amp;#39;s host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-ajv, Ubuntu:20.04:LTS: node-ajv, Ubuntu:22.04:LTS: node-ajv, Ubuntu:24.04:LTS: node-ajv, Ubuntu:26.04:LTS: node-ajv&lt;/p&gt;
&lt;p&gt;fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node&amp;#39;s URL read the result back as the attacker&amp;#39;s host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-84292</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3555 — Red Hat Ansible Automation Platform (automation-controller): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</guid>
    </item>
  </channel>
</rss>
