<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 21:30:35 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0281 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0281</link>
      <description>certfr-2026-avi-0281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0281</guid>
    </item>
    <item>
      <title>EUVD-2026-309387</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-309387</link>
      <description>EUVD-2026-309387</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-309387</guid>
    </item>
    <item>
      <title>fkie_cve-2025-13033</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-13033</link>
      <description>&lt;p&gt;A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email to the attacker&amp;#39;s external address instead of the intended internal recipient. This could lead to a significant data leak of sensitive information and allow an attacker to bypass security filters and access controls.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email to the attacker&amp;#39;s external address instead of the intended internal recipient. This could lead to a significant data leak of sensitive information and allow an attacker to bypass security filters and access controls.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-13033</guid>
    </item>
    <item>
      <title>GHSA-mm7p-fcc7-pg87 — Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mm7p-fcc7-pg87</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nodemailer&lt;/p&gt;
&lt;p&gt;The email parsing library incorrectly handles quoted local-parts containing @. This leads to misrouting of email recipients, where the parser extracts and routes to an unintended domain instead of the RFC-compliant target.&lt;/p&gt;
&lt;p&gt;Payload: `&amp;#34;xclow3n@gmail.com x&amp;#34;@internal.domain`
Using the following code to send mail
```
const nodemailer = require(&amp;#34;nodemailer&amp;#34;);&lt;/p&gt;
&lt;p&gt;let transporter = nodemailer.createTransport({
  service: &amp;#34;gmail&amp;#34;,
  auth: {
    user: &amp;#34;&amp;#34;,
    pass: &amp;#34;&amp;#34;,
  },
});&lt;/p&gt;
&lt;p&gt;let mailOptions = {
  from: &amp;#39;&amp;#34;Test Sender&amp;#34; &amp;lt;your_email@gmail.com&amp;gt;&amp;#39;, 
  to: &amp;#34;\&amp;#34;xclow3n@gmail.com x\&amp;#34;@internal.domain&amp;#34;,
  subject: &amp;#34;Hello from Nodemailer&amp;#34;,
  text: &amp;#34;This is a test email sent using Gmail SMTP and Nodemailer!&amp;#34;,
};&lt;/p&gt;
&lt;p&gt;transporter.sendMail(mailOptions, (error, info) =&amp;gt; {
  if (error) {
    return console.log(&amp;#34;Error: &amp;#34;, error);
  }
  console.log(&amp;#34;Message sent: %s&amp;#34;, info.messageId);&lt;/p&gt;
&lt;p&gt;});&lt;/p&gt;
&lt;p&gt;(async () =&amp;gt; {
  const parser = await import(&amp;#34;@sparser/email-address-parser&amp;#34;);
  const { EmailAddress, ParsingOptions } = parser.default;
  const parsed = EmailAddress.parse(mailOptions.to /*, new ParsingOptions(true) */);&lt;/p&gt;
&lt;p&gt;if (!parsed) {
    console.error(&amp;#34;Invalid email address:&amp;#34;, mailOptions.to);
    return;
  }&lt;/p&gt;
&lt;p&gt;console.log(&amp;#34;Parsed email:&amp;#34;, {
    address: `${parsed.localPart}@${parsed.domain}`,
    local: parsed.localPart,
    domain: parsed.domain,
  });
})();
```&lt;/p&gt;
&lt;p&gt;Running the script and seeing how this mail is parsed according to RFC&lt;/p&gt;
&lt;p&gt;```
Parsed email: {
  address: &amp;#39;&amp;#34;xclow3n@gmail.com x&amp;#34;@internal.domain&amp;#39;,
  lo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: nodemailer&lt;/p&gt;
&lt;p&gt;The email parsing library incorrectly handles quoted local-parts containing @. This leads to misrouting of email recipients, where the parser extracts and routes to an unintended domain instead of the RFC-compliant target.&lt;/p&gt;
&lt;p&gt;Payload: `&amp;#34;xclow3n@gmail.com x&amp;#34;@internal.domain`
Using the following code to send mail
```
const nodemailer = require(&amp;#34;nodemailer&amp;#34;);&lt;/p&gt;
&lt;p&gt;let transporter = nodemailer.createTransport({
  service: &amp;#34;gmail&amp;#34;,
  auth: {
    user: &amp;#34;&amp;#34;,
    pass: &amp;#34;&amp;#34;,
  },
});&lt;/p&gt;
&lt;p&gt;let mailOptions = {
  from: &amp;#39;&amp;#34;Test Sender&amp;#34; &amp;lt;your_email@gmail.com&amp;gt;&amp;#39;, 
  to: &amp;#34;\&amp;#34;xclow3n@gmail.com x\&amp;#34;@internal.domain&amp;#34;,
  subject: &amp;#34;Hello from Nodemailer&amp;#34;,
  text: &amp;#34;This is a test email sent using Gmail SMTP and Nodemailer!&amp;#34;,
};&lt;/p&gt;
&lt;p&gt;transporter.sendMail(mailOptions, (error, info) =&amp;gt; {
  if (error) {
    return console.log(&amp;#34;Error: &amp;#34;, error);
  }
  console.log(&amp;#34;Message sent: %s&amp;#34;, info.messageId);&lt;/p&gt;
&lt;p&gt;});&lt;/p&gt;
&lt;p&gt;(async () =&amp;gt; {
  const parser = await import(&amp;#34;@sparser/email-address-parser&amp;#34;);
  const { EmailAddress, ParsingOptions } = parser.default;
  const parsed = EmailAddress.parse(mailOptions.to /*, new ParsingOptions(true) */);&lt;/p&gt;
&lt;p&gt;if (!parsed) {
    console.error(&amp;#34;Invalid email address:&amp;#34;, mailOptions.to);
    return;
  }&lt;/p&gt;
&lt;p&gt;console.log(&amp;#34;Parsed email:&amp;#34;, {
    address: `${parsed.localPart}@${parsed.domain}`,
    local: parsed.localPart,
    domain: parsed.domain,
  });
})();
```&lt;/p&gt;
&lt;p&gt;Running the script and seeing how this mail is parsed according to RFC&lt;/p&gt;
&lt;p&gt;```
Parsed email: {
  address: &amp;#39;&amp;#34;xclow3n@gmail.com x&amp;#34;@internal.domain&amp;#39;,
  lo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mm7p-fcc7-pg87</guid>
    </item>
    <item>
      <title>RHSA-2026:15979 — Red Hat Security Advisory: Red Hat Ceph Storage</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:15979</link>
      <description>&lt;p&gt;nodemailer: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate js-yaml: js-yaml prototype pollution in merge glob: glob: Command Injection Vulnerability via Malicious Filenames github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodemailer: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate js-yaml: js-yaml prototype pollution in merge glob: glob: Command Injection Vulnerability via Malicious Filenames github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:15979</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-13033</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-13033</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-nodemailer, Ubuntu:22.04:LTS: node-nodemailer, Ubuntu:24.04:LTS: node-nodemailer, Ubuntu:25.10: node-nodemailer&lt;/p&gt;
&lt;p&gt;A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email to the attacker&amp;#39;s external address instead of the intended internal recipient. This could lead to a significant data leak of sensitive information and allow an attacker to bypass security filters and access controls.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-nodemailer, Ubuntu:22.04:LTS: node-nodemailer, Ubuntu:24.04:LTS: node-nodemailer, Ubuntu:25.10: node-nodemailer&lt;/p&gt;
&lt;p&gt;A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This causes the application to misdirect the email to the attacker&amp;#39;s external address instead of the intended internal recipient. This could lead to a significant data leak of sensitive information and allow an attacker to bypass security filters and access controls.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-13033</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0592 — Red Hat Developer Hub: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0592</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Red Hat Developer Hub ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen oder um vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Red Hat Developer Hub ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen oder um vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0592</guid>
    </item>
  </channel>
</rss>
