<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 04:30:13 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:35841 — Important: nodejs24 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:35841</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: nodejs24, AlmaLinux:10: nodejs24-devel, AlmaLinux:10: nodejs24-docs, AlmaLinux:10: nodejs24-full-i18n, AlmaLinux:10: nodejs24-libs, AlmaLinux:10: nodejs24-npm&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
  * undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
  * undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)
  * undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)
  * undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)
  * undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)
  * undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)
  * nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)
  * nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)
  * nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)
  * nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: nodejs24, AlmaLinux:10: nodejs24-devel, AlmaLinux:10: nodejs24-docs, AlmaLinux:10: nodejs24-full-i18n, AlmaLinux:10: nodejs24-libs, AlmaLinux:10: nodejs24-npm&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
  * undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
  * undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)
  * undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)
  * undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)
  * undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)
  * undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)
  * nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)
  * nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)
  * nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)
  * nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:35841</guid>
    </item>
    <item>
      <title>bdu:2026-14861</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14861</link>
      <description>bdu:2026-14861</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14861</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0812 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812</link>
      <description>certfr-2026-avi-0812</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0812</guid>
    </item>
    <item>
      <title>EUVD-2026-366093</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366093</link>
      <description>EUVD-2026-366093</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366093</guid>
    </item>
    <item>
      <title>fkie_cve-2026-9697</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9697</link>
      <description>&lt;p&gt;Impact:
undici&amp;#39;s ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node&amp;#39;s default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.&lt;/p&gt;
&lt;p&gt;Applications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange.&lt;/p&gt;
&lt;p&gt;Affected applications are those that use undici&amp;#39;s ProxyAgent (or Socks5ProxyAgent directly) with SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added.&lt;/p&gt;
&lt;p&gt;Patches:
Upgrade to undici v7.28.0 or v8.5.0.&lt;/p&gt;
&lt;p&gt;Workarounds:
No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead, where requestTls is honored correctly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Impact:
undici&amp;#39;s ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node&amp;#39;s default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.&lt;/p&gt;
&lt;p&gt;Applications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange.&lt;/p&gt;
&lt;p&gt;Affected applications are those that use undici&amp;#39;s ProxyAgent (or Socks5ProxyAgent directly) with SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added.&lt;/p&gt;
&lt;p&gt;Patches:
Upgrade to undici v7.28.0 or v8.5.0.&lt;/p&gt;
&lt;p&gt;Workarounds:
No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead, where requestTls is honored correctly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-9697</guid>
    </item>
    <item>
      <title>GHSA-vmh5-mc38-953g — undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vmh5-mc38-953g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;undici&amp;#39;s `ProxyAgent` silently drops the `requestTls` option when configured with a SOCKS5 proxy URI (`socks5://` or `socks://`). The target HTTPS connection through the SOCKS5 tunnel falls back to Node&amp;#39;s default trust store, ignoring user-configured `ca`, `cert`, `key`, `rejectUnauthorized`, and `servername` settings.&lt;/p&gt;
&lt;p&gt;Applications that pin to an internal or corporate CA via `requestTls.ca` will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange.&lt;/p&gt;
&lt;p&gt;Affected applications are those that use undici&amp;#39;s `ProxyAgent` (or `Socks5ProxyAgent` directly) with SOCKS5 AND rely on `requestTls` for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Upgrade to undici v7.28.0 or v8.5.0.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy `ProxyAgent` instead, where `requestTls` is honored correctly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: undici&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;undici&amp;#39;s `ProxyAgent` silently drops the `requestTls` option when configured with a SOCKS5 proxy URI (`socks5://` or `socks://`). The target HTTPS connection through the SOCKS5 tunnel falls back to Node&amp;#39;s default trust store, ignoring user-configured `ca`, `cert`, `key`, `rejectUnauthorized`, and `servername` settings.&lt;/p&gt;
&lt;p&gt;Applications that pin to an internal or corporate CA via `requestTls.ca` will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange.&lt;/p&gt;
&lt;p&gt;Affected applications are those that use undici&amp;#39;s `ProxyAgent` (or `Socks5ProxyAgent` directly) with SOCKS5 AND rely on `requestTls` for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Upgrade to undici v7.28.0 or v8.5.0.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy `ProxyAgent` instead, where `requestTls` is honored correctly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vmh5-mc38-953g</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-9697 — undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-9697</link>
      <description>msrc_CVE-2026-9697</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-9697</guid>
    </item>
    <item>
      <title>RHSA-2026:22380 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:22380</link>
      <description>&lt;p&gt;undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: undici WebSocket client vulnerable to denial of service via cumulative fragment bypass undici: Undici: Information disclosure due to improper cache-control header parsing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: undici WebSocket client vulnerable to denial of service via cumulative fragment bypass undici: Undici: Information disclosure due to improper cache-control header parsing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:22380</guid>
    </item>
    <item>
      <title>RHSA-2026:35841 — Red Hat Security Advisory: nodejs24 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:35841</link>
      <description>&lt;p&gt;undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: Undici: Information disclosure due to improper cache-control header parsing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() nodejs: Node.js: Certification validation bypass in TLS host verification nodejs: Node.js: Unauthorized file metadata modification&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: Undici: Information disclosure due to improper cache-control header parsing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() nodejs: Node.js: Certification validation bypass in TLS host verification nodejs: Node.js: Unauthorized file metadata modification&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:35841</guid>
    </item>
    <item>
      <title>RLSA-2026:35841 — Important: nodejs24 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:35841</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs24&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)&lt;/p&gt;
&lt;p&gt;* undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)&lt;/p&gt;
&lt;p&gt;* undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)&lt;/p&gt;
&lt;p&gt;* undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)&lt;/p&gt;
&lt;p&gt;* undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: nodejs24&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;#39;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)&lt;/p&gt;
&lt;p&gt;* undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)&lt;/p&gt;
&lt;p&gt;* undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)&lt;/p&gt;
&lt;p&gt;* undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)&lt;/p&gt;
&lt;p&gt;* undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)&lt;/p&gt;
&lt;p&gt;* undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)&lt;/p&gt;
&lt;p&gt;* nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:35841</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-9697</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9697</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;Impact: undici&amp;#39;s ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node&amp;#39;s default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings. Applications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange. Affected applications are those that use undici&amp;#39;s ProxyAgent (or Socks5ProxyAgent directly) with SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added. Patches: Upgrade to undici v7.28.0 or v8.5.0. Workarounds: No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead, where requestTls is honored correctly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-undici, Ubuntu:25.10: node-undici, Ubuntu:26.04:LTS: node-undici&lt;/p&gt;
&lt;p&gt;Impact: undici&amp;#39;s ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node&amp;#39;s default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings. Applications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange. Affected applications are those that use undici&amp;#39;s ProxyAgent (or Socks5ProxyAgent directly) with SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added. Patches: Upgrade to undici v7.28.0 or v8.5.0. Workarounds: No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead, where requestTls is honored correctly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9697</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2618 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2618</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2618</guid>
    </item>
  </channel>
</rss>
