<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:10:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-367387</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-367387</link>
      <description>EUVD-2026-367387</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-367387</guid>
    </item>
    <item>
      <title>fkie_cve-2026-88932</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-88932</link>
      <description>&lt;p&gt;multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A remote unauthenticated attacker can repeatedly start and abort uploads to accumulate orphaned files and exhaust disk space, causing a denial of service. The issue is fixed in multer 2.4.0, and users should upgrade to 2.4.0 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A remote unauthenticated attacker can repeatedly start and abort uploads to accumulate orphaned files and exhaust disk space, causing a denial of service. The issue is fixed in multer 2.4.0, and users should upgrade to 2.4.0 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-88932</guid>
    </item>
    <item>
      <title>GHSA-3pph-fpjx-jg34 — multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3pph-fpjx-jg34</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: multer&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Multer&amp;#39;s `diskStorage` can leave complete, orphaned files on disk when a multipart upload is aborted in the brief window before the storage engine assigns the file path. This is an incomplete fix of CVE-2026-5038: the earlier cleanup removes only in-flight uploads that already have a path, so an upload aborted inside that window is written to disk with nothing left to remove it, and the application is not given a handle to clean it up. An unauthenticated attacker sending aborted requests to any route backed by disk storage can accumulate orphaned files until the upload directory or the shared system temporary directory is exhausted. An asynchronous `destination` or `filename` widens the window.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Users should upgrade to `2.4.0` or higher.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: multer&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Multer&amp;#39;s `diskStorage` can leave complete, orphaned files on disk when a multipart upload is aborted in the brief window before the storage engine assigns the file path. This is an incomplete fix of CVE-2026-5038: the earlier cleanup removes only in-flight uploads that already have a path, so an upload aborted inside that window is written to disk with nothing left to remove it, and the application is not given a handle to clean it up. An unauthenticated attacker sending aborted requests to any route backed by disk storage can accumulate orphaned files until the upload directory or the shared system temporary directory is exhausted. An asynchronous `destination` or `filename` widens the window.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Users should upgrade to `2.4.0` or higher.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3pph-fpjx-jg34</guid>
    </item>
    <item>
      <title>RHSA-2026:72712 — Red Hat Security Advisory: Ansible plug-ins for Red Hat Developer Hub Product Release Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:72712</link>
      <description>&lt;p&gt;multer: Multer: Denial of Service via aborted or malformed multipart uploads undici: undici: Denial of Service via unrequested WebSocket subprotocol vm2: vm2: Denial of Service due to memory allocation limit bypass urllib: urllib: Credential leakage via cross-origin redirects js-yaml: js-yaml: Denial of Service via crafted YAML documents immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations qs: qs: Denial of Service via improper validation in stringify function js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing compression: compression: Denial of Service via memory leak on premature response close multer: multer: Denial of Service via orphaned disk writes on aborted uploads isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function. adm-zip: adm-zip: Denial of Service via crafted ZIP archives with zero declared uncompressed size vm2: vm2: Denial of Service via timeout bypass in sandboxed code vm2: vm2: Sandbox escape via denylist bypass in NodeVM vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation vm2: vm2: Denial of Service via memory exhaustion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;multer: Multer: Denial of Service via aborted or malformed multipart uploads undici: undici: Denial of Service via unrequested WebSocket subprotocol vm2: vm2: Denial of Service due to memory allocation limit bypass urllib: urllib: Credential leakage via cross-origin redirects js-yaml: js-yaml: Denial of Service via crafted YAML documents immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations qs: qs: Denial of Service via improper validation in stringify function js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing compression: compression: Denial of Service via memory leak on premature response close multer: multer: Denial of Service via orphaned disk writes on aborted uploads isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function. adm-zip: adm-zip: Denial of Service via crafted ZIP archives with zero declared uncompressed size vm2: vm2: Denial of Service via timeout bypass in sandboxed code vm2: vm2: Sandbox escape via denylist bypass in NodeVM vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation vm2: vm2: Denial of Service via memory exhaustion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:72712</guid>
    </item>
  </channel>
</rss>
