<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:17:18 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0279 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0279</link>
      <description>certfr-2025-avi-0279</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0279</guid>
    </item>
    <item>
      <title>EUVD-2026-217762</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217762</link>
      <description>EUVD-2026-217762</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217762</guid>
    </item>
    <item>
      <title>fkie_cve-2025-25288</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-25288</link>
      <description>&lt;p&gt;@octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package `@octokit/plugin-paginate-rest`, when calling `octokit.paginate.iterator()`, a specially crafted `octokit` instance—particularly with a malicious `link` parameter in the `headers` section of the `request`—can trigger a ReDoS attack. Version 11.4.1 contains a fix for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;@octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1.0.0 and prior to 11.4.1 of the npm package `@octokit/plugin-paginate-rest`, when calling `octokit.paginate.iterator()`, a specially crafted `octokit` instance—particularly with a malicious `link` parameter in the `headers` section of the `request`—can trigger a ReDoS attack. Version 11.4.1 contains a fix for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-25288</guid>
    </item>
    <item>
      <title>GHSA-h5c3-5r3r-rr8q — @octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Bac…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h5c3-5r3r-rr8q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @octokit/plugin-paginate-rest&lt;/p&gt;
&lt;p&gt;### Summary
For the npm package `@octokit/plugin-paginate-rest`, when calling `octokit.paginate.iterator()`, a specially crafted `octokit` instance—particularly with a malicious `link` parameter in the `headers` section of the `request`—can trigger a ReDoS attack.&lt;/p&gt;
&lt;p&gt;### Details
The issue occurs at [line 39](https://github.com/octokit/plugin-paginate-rest.js/blob/main/src/iterator.ts) of iterator.ts in the @octokit/plugin-paginate-rest repository. The relevant code is as follows:
```js
url = ((normalizedResponse.headers.link || &amp;#34;&amp;#34;).match(
  /&amp;lt;([^&amp;gt;]+)&amp;gt;;\s*rel=&amp;#34;next&amp;#34;/,
) || [])[1];
```
The regular expression `/&amp;lt;([^&amp;gt;]+)&amp;gt;;\s*rel=&amp;#34;next&amp;#34;/` may lead to a potential backtracking vulnerability, resulting in a ReDoS (Regular Expression Denial of Service) attack. This could cause high CPU utilization and even service slowdowns or freezes when processing specially crafted `Link` headers.&lt;/p&gt;
&lt;p&gt;### PoC
[The gist of PoC.js](https://gist.github.com/ShiyuBanzhou/d3f2ad000be8384d2105c87c2ed7ce7d)
1. run npm i @octokit/plugin-paginate-rest
2. run &amp;#39;node poc.js&amp;#39;
result:
3. then the program will stuck forever with high CPU usage
```js
import { Octokit } from &amp;#34;@octokit/core&amp;#34;;
import { paginateRest } from &amp;#34;@octokit/plugin-paginate-rest&amp;#34;;&lt;/p&gt;
&lt;p&gt;const MyOctokit = Octokit.plugin(paginateRest);
const octokit = new MyOctokit({
  auth: &amp;#34;your-github-token&amp;#34;,
});&lt;/p&gt;
&lt;p&gt;// Intercept the request to inject a malicious &amp;#39;link&amp;#39; header for ReDoS
octokit.hook.wrap(&amp;#34;request&amp;#34;, async (request, options) =&amp;gt; {
  const maliciousLinkHeader…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @octokit/plugin-paginate-rest&lt;/p&gt;
&lt;p&gt;### Summary
For the npm package `@octokit/plugin-paginate-rest`, when calling `octokit.paginate.iterator()`, a specially crafted `octokit` instance—particularly with a malicious `link` parameter in the `headers` section of the `request`—can trigger a ReDoS attack.&lt;/p&gt;
&lt;p&gt;### Details
The issue occurs at [line 39](https://github.com/octokit/plugin-paginate-rest.js/blob/main/src/iterator.ts) of iterator.ts in the @octokit/plugin-paginate-rest repository. The relevant code is as follows:
```js
url = ((normalizedResponse.headers.link || &amp;#34;&amp;#34;).match(
  /&amp;lt;([^&amp;gt;]+)&amp;gt;;\s*rel=&amp;#34;next&amp;#34;/,
) || [])[1];
```
The regular expression `/&amp;lt;([^&amp;gt;]+)&amp;gt;;\s*rel=&amp;#34;next&amp;#34;/` may lead to a potential backtracking vulnerability, resulting in a ReDoS (Regular Expression Denial of Service) attack. This could cause high CPU utilization and even service slowdowns or freezes when processing specially crafted `Link` headers.&lt;/p&gt;
&lt;p&gt;### PoC
[The gist of PoC.js](https://gist.github.com/ShiyuBanzhou/d3f2ad000be8384d2105c87c2ed7ce7d)
1. run npm i @octokit/plugin-paginate-rest
2. run &amp;#39;node poc.js&amp;#39;
result:
3. then the program will stuck forever with high CPU usage
```js
import { Octokit } from &amp;#34;@octokit/core&amp;#34;;
import { paginateRest } from &amp;#34;@octokit/plugin-paginate-rest&amp;#34;;&lt;/p&gt;
&lt;p&gt;const MyOctokit = Octokit.plugin(paginateRest);
const octokit = new MyOctokit({
  auth: &amp;#34;your-github-token&amp;#34;,
});&lt;/p&gt;
&lt;p&gt;// Intercept the request to inject a malicious &amp;#39;link&amp;#39; header for ReDoS
octokit.hook.wrap(&amp;#34;request&amp;#34;, async (request, options) =&amp;gt; {
  const maliciousLinkHeader…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h5c3-5r3r-rr8q</guid>
    </item>
  </channel>
</rss>
