<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:10:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-375174</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-375174</link>
      <description>EUVD-2026-375174</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-375174</guid>
    </item>
    <item>
      <title>fkie_cve-2026-97058</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-97058</link>
      <description>&lt;p&gt;sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-97058</guid>
    </item>
    <item>
      <title>GHSA-hp3w-g68c-fv3c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hp3w-g68c-fv3c</link>
      <description>&lt;p&gt;sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hp3w-g68c-fv3c</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-97058 — sprintf-js through 1.1.3 Denial of Service via Unbounded Precision</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-97058</link>
      <description>msrc_CVE-2026-97058</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-97058</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-97058</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-97058</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-sprintf-js, Ubuntu:18.04:LTS: node-sprintf-js, Ubuntu:20.04:LTS: node-sprintf-js, Ubuntu:22.04:LTS: node-sprintf-js, Ubuntu:24.04:LTS: node-sprintf-js, Ubuntu:26.04:LTS: node-sprintf-js&lt;/p&gt;
&lt;p&gt;sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: node-sprintf-js, Ubuntu:18.04:LTS: node-sprintf-js, Ubuntu:20.04:LTS: node-sprintf-js, Ubuntu:22.04:LTS: node-sprintf-js, Ubuntu:24.04:LTS: node-sprintf-js, Ubuntu:26.04:LTS: node-sprintf-js&lt;/p&gt;
&lt;p&gt;sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-97058</guid>
    </item>
  </channel>
</rss>
