<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:41:45 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:5360 — Important: nodejs:16 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:5360</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (16). (BZ#2233891)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs: Permissions policies can be bypassed via Module._load (CVE-2023-32002)
* nodejs-semver: Regular expression denial of service (CVE-2022-25883)
* nodejs: Permissions policies can impersonate other modules in using module.constructor.createRequire() (CVE-2023-32006)
* nodejs: Permissions policies can be bypassed via process.binding (CVE-2023-32559)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs:16/nodejs: nodejs.prov doesn&amp;#39;t generate the bundled dependency for modules starting @ like @colors/colors (BZ#2237394)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: nodejs (16). (BZ#2233891)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs: Permissions policies can be bypassed via Module._load (CVE-2023-32002)
* nodejs-semver: Regular expression denial of service (CVE-2022-25883)
* nodejs: Permissions policies can impersonate other modules in using module.constructor.createRequire() (CVE-2023-32006)
* nodejs: Permissions policies can be bypassed via process.binding (CVE-2023-32559)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* nodejs:16/nodejs: nodejs.prov doesn&amp;#39;t generate the bundled dependency for modules starting @ like @colors/colors (BZ#2237394)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:5360</guid>
    </item>
    <item>
      <title>bdu:2023-04976</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-04976</link>
      <description>bdu:2023-04976</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-04976</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0705 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0705</link>
      <description>certfr-2023-avi-0705</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0705</guid>
    </item>
    <item>
      <title>EUVD-2026-206311</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-206311</link>
      <description>EUVD-2026-206311</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-206311</guid>
    </item>
    <item>
      <title>fkie_cve-2022-25883</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-25883</link>
      <description>&lt;p&gt;Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-25883</guid>
    </item>
    <item>
      <title>GHSA-c2qf-rxjj-qqgw — semver vulnerable to Regular Expression Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c2qf-rxjj-qqgw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: semver&lt;/p&gt;
&lt;p&gt;Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: semver&lt;/p&gt;
&lt;p&gt;Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c2qf-rxjj-qqgw</guid>
    </item>
    <item>
      <title>gsd-2022-25883</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-25883</link>
      <description>gsd-2022-25883</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-25883</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-25883 — Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the func…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-25883</link>
      <description>msrc_CVE-2022-25883</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-25883</guid>
    </item>
    <item>
      <title>NCSC-2026-0034 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0034</link>
      <description>NCSC-2026-0034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0034</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14012-1 — system-user-velociraptor-1.0.0-9.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14012-1</link>
      <description>&lt;p&gt;system-user-velociraptor-1.0.0-9.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;system-user-velociraptor-1.0.0-9.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14012-1</guid>
    </item>
    <item>
      <title>RHSA-2023:4341 — Red Hat Security Advisory: Logging Subsystem 5.7.4 - Red Hat OpenShift bug fix and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:4341</link>
      <description>&lt;p&gt;nodejs-semver: Regular expression denial of service rubygem-activesupport: Regular Expression Denial of Service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-semver: Regular expression denial of service rubygem-activesupport: Regular Expression Denial of Service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:4341</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-25883</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25883</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-semver, Ubuntu:Pro:16.04:LTS: node-semver, Ubuntu:18.04:LTS: node-semver, Ubuntu:20.04:LTS: node-semver, Ubuntu:22.04:LTS: node-semver, Ubuntu:24.04:LTS: node-semver, Ubuntu:25.10: node-semver, Ubuntu:26.04:LTS: node-semver&lt;/p&gt;
&lt;p&gt;Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: node-semver, Ubuntu:Pro:16.04:LTS: node-semver, Ubuntu:18.04:LTS: node-semver, Ubuntu:20.04:LTS: node-semver, Ubuntu:22.04:LTS: node-semver, Ubuntu:24.04:LTS: node-semver, Ubuntu:25.10: node-semver, Ubuntu:26.04:LTS: node-semver&lt;/p&gt;
&lt;p&gt;Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-25883</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2356 — IBM QRadar SIEM: Mehre Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2356</link>
      <description>&lt;p&gt;Ein anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein anonymer Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2356</guid>
    </item>
  </channel>
</rss>
