<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 08:07:31 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-30493</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-30493</link>
      <description>EUVD-2026-30493</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-30493</guid>
    </item>
    <item>
      <title>fkie_cve-2021-39176</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-39176</link>
      <description>&lt;p&gt;detect-character-encoding is a package for detecting character encoding using ICU. In detect-character-encoding v0.3.0 and earlier, allocated memory is not released. The problem has been patched in detect-character-encoding v0.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;detect-character-encoding is a package for detecting character encoding using ICU. In detect-character-encoding v0.3.0 and earlier, allocated memory is not released. The problem has been patched in detect-character-encoding v0.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-39176</guid>
    </item>
    <item>
      <title>GHSA-5rwj-j5m3-3chj — Missing Release of Memory after Effective Lifetime in detect-character-encoding</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5rwj-j5m3-3chj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: detect-character-encoding&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In detect-character-encoding v0.3.0 and earlier, allocated memory is not released.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The problem has been patched in [detect-character-encoding v0.3.1](https://github.com/sonicdoe/detect-character-encoding/releases/tag/v0.3.1).&lt;/p&gt;
&lt;p&gt;### CVSS score&lt;/p&gt;
&lt;p&gt;[CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:O/RC:C](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:O/RC:C)&lt;/p&gt;
&lt;p&gt;Base Score: 7.5 (High)
Temporal Score: 7.2 (High)&lt;/p&gt;
&lt;p&gt;Since detect-character-encoding is a library, the scoring is based on the “[reasonable worst-case implementation scenario](https://www.first.org/cvss/v3.1/user-guide#3-7-Scoring-Vulnerabilities-in-Software-Libraries-and-Similar)”, namely, using detect-character-encoding in a program accessible over the internet which becomes unavailable when running out of memory. Depending on your specific implementation, the vulnerability’s severity in your program may be different.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```js
const express = require(&amp;#34;express&amp;#34;);
const detectCharacterEncoding = require(&amp;#34;detect-character-encoding&amp;#34;);&lt;/p&gt;
&lt;p&gt;const app = express();&lt;/p&gt;
&lt;p&gt;app.get(&amp;#34;/&amp;#34;, (req, res) =&amp;gt; {
  detectCharacterEncoding(Buffer.from(&amp;#34;foo&amp;#34;));&lt;/p&gt;
&lt;p&gt;res.end();
});&lt;/p&gt;
&lt;p&gt;app.listen(3000);
```&lt;/p&gt;
&lt;p&gt;`hey -n 1000000 http://localhost:3000` ([`hey`](https://github.com/rakyll/hey)) causes the Node.js process to consume more and more memory.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- https://github.com/sonicdoe/detect-character-encoding/commit/d44356927b92e3b13e178071bf6d7c671766f588
- https://g…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: detect-character-encoding&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In detect-character-encoding v0.3.0 and earlier, allocated memory is not released.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The problem has been patched in [detect-character-encoding v0.3.1](https://github.com/sonicdoe/detect-character-encoding/releases/tag/v0.3.1).&lt;/p&gt;
&lt;p&gt;### CVSS score&lt;/p&gt;
&lt;p&gt;[CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:O/RC:C](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:O/RC:C)&lt;/p&gt;
&lt;p&gt;Base Score: 7.5 (High)
Temporal Score: 7.2 (High)&lt;/p&gt;
&lt;p&gt;Since detect-character-encoding is a library, the scoring is based on the “[reasonable worst-case implementation scenario](https://www.first.org/cvss/v3.1/user-guide#3-7-Scoring-Vulnerabilities-in-Software-Libraries-and-Similar)”, namely, using detect-character-encoding in a program accessible over the internet which becomes unavailable when running out of memory. Depending on your specific implementation, the vulnerability’s severity in your program may be different.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```js
const express = require(&amp;#34;express&amp;#34;);
const detectCharacterEncoding = require(&amp;#34;detect-character-encoding&amp;#34;);&lt;/p&gt;
&lt;p&gt;const app = express();&lt;/p&gt;
&lt;p&gt;app.get(&amp;#34;/&amp;#34;, (req, res) =&amp;gt; {
  detectCharacterEncoding(Buffer.from(&amp;#34;foo&amp;#34;));&lt;/p&gt;
&lt;p&gt;res.end();
});&lt;/p&gt;
&lt;p&gt;app.listen(3000);
```&lt;/p&gt;
&lt;p&gt;`hey -n 1000000 http://localhost:3000` ([`hey`](https://github.com/rakyll/hey)) causes the Node.js process to consume more and more memory.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- https://github.com/sonicdoe/detect-character-encoding/commit/d44356927b92e3b13e178071bf6d7c671766f588
- https://g…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5rwj-j5m3-3chj</guid>
    </item>
    <item>
      <title>gsd-2021-39176</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-39176</link>
      <description>gsd-2021-39176</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-39176</guid>
    </item>
  </channel>
</rss>
