<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:27:28 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:73428 — Important: nodejs24 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:73428</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: nodejs24, AlmaLinux:10: nodejs24-devel, AlmaLinux:10: nodejs24-docs, AlmaLinux:10: nodejs24-full-i18n, AlmaLinux:10: nodejs24-libs, AlmaLinux:10: nodejs24-npm&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152)
  * undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961)
  * undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* nodejs24: Rebase to the latest Node.js 24 release [almalinux-10] (JIRA:AlmaLinux-249187)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: nodejs24, AlmaLinux:10: nodejs24-devel, AlmaLinux:10: nodejs24-docs, AlmaLinux:10: nodejs24-full-i18n, AlmaLinux:10: nodejs24-libs, AlmaLinux:10: nodejs24-npm&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152)
  * undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961)
  * undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* nodejs24: Rebase to the latest Node.js 24 release [almalinux-10] (JIRA:AlmaLinux-249187)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:73428</guid>
    </item>
    <item>
      <title>EUVD-2026-364077</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364077</link>
      <description>EUVD-2026-364077</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364077</guid>
    </item>
    <item>
      <title>fkie_cve-2026-85152</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-85152</link>
      <description>&lt;p&gt;undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-85152</guid>
    </item>
    <item>
      <title>GHSA-vp8m-p9jh-q5pm — undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vp8m-p9jh-q5pm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;When `interceptors.cache()` or `interceptors.deduplicate()` is used with a dispatcher that does not carry a single authoritative origin, or when a request supplies its own `origin`, undici builds the cache and deduplication keys without the actual destination origin. If a cache store or interceptor instance is shared across more than one origin, otherwise-identical requests to different origins are keyed together.&lt;/p&gt;
&lt;p&gt;An attacker who controls the response from one origin can then have that response returned for a request to a different, trusted origin when the method, path, and relevant headers match. This allows cross-origin information disclosure and persistent cache poisoning, including chains such as JWKS cache poisoning where a token signed with an attacker-held key is accepted as belonging to a trusted issuer.&lt;/p&gt;
&lt;p&gt;Applications that share `interceptors.cache()` or `interceptors.deduplicate()` state across origins are affected. An `Agent` is not affected, because its dispatch options include the request origin.&lt;/p&gt;
&lt;p&gt;This was introduced in undici 8.10.0 and affects 8.10.0 and 8.10.1.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Upgrade to undici v8.10.2.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Use a separate cache store and a separate interceptor instance for each origin, and do not share them across origins.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;When `interceptors.cache()` or `interceptors.deduplicate()` is used with a dispatcher that does not carry a single authoritative origin, or when a request supplies its own `origin`, undici builds the cache and deduplication keys without the actual destination origin. If a cache store or interceptor instance is shared across more than one origin, otherwise-identical requests to different origins are keyed together.&lt;/p&gt;
&lt;p&gt;An attacker who controls the response from one origin can then have that response returned for a request to a different, trusted origin when the method, path, and relevant headers match. This allows cross-origin information disclosure and persistent cache poisoning, including chains such as JWKS cache poisoning where a token signed with an attacker-held key is accepted as belonging to a trusted issuer.&lt;/p&gt;
&lt;p&gt;Applications that share `interceptors.cache()` or `interceptors.deduplicate()` state across origins are affected. An `Agent` is not affected, because its dispatch options include the request origin.&lt;/p&gt;
&lt;p&gt;This was introduced in undici 8.10.0 and affects 8.10.0 and 8.10.1.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Upgrade to undici v8.10.2.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Use a separate cache store and a separate interceptor instance for each origin, and do not share them across origins.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vp8m-p9jh-q5pm</guid>
    </item>
    <item>
      <title>RHSA-2026:54389 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:54389</link>
      <description>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function undici: undici: Denial of Service due to orphaned response body in retry handler brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation undici: undici: Denial of Service via unbounded decompression of compressed responses undici: undici: Cross-user cookie disclosure via Set-Cookie caching undici: Undici: Response truncation and connection termination undici: undici: Integrity failure due to caching of unsafe HTTP method responses undici: undici: Denial of Service via WebSocketStream unclean close undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function undici: undici: Denial of Service due to orphaned response body in retry handler brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation undici: undici: Denial of Service via unbounded decompression of compressed responses undici: undici: Cross-user cookie disclosure via Set-Cookie caching undici: Undici: Response truncation and connection termination undici: undici: Integrity failure due to caching of unsafe HTTP method responses undici: undici: Denial of Service via WebSocketStream unclean close undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:54389</guid>
    </item>
    <item>
      <title>RHSA-2026:73428 — security update for nodejs24</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:73428</link>
      <description>&lt;p&gt;security update for nodejs24&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for nodejs24&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:73428</guid>
    </item>
    <item>
      <title>RLSA-2026:73428 — Important: nodejs24 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:73428</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs24&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152)&lt;/p&gt;
&lt;p&gt;* undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961)&lt;/p&gt;
&lt;p&gt;* undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* nodejs24: Rebase to the latest Node.js 24 release [rhel-10] (JIRA:Rocky Linux-249187)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs24&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152)&lt;/p&gt;
&lt;p&gt;* undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961)&lt;/p&gt;
&lt;p&gt;* undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* nodejs24: Rebase to the latest Node.js 24 release [rhel-10] (JIRA:Rocky Linux-249187)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:73428</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-85152</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-85152</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-85152</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
