<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 17:54:48 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0279 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0279</link>
      <description>certfr-2025-avi-0279</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0279</guid>
    </item>
    <item>
      <title>EUVD-2026-217761</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217761</link>
      <description>EUVD-2026-217761</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217761</guid>
    </item>
    <item>
      <title>fkie_cve-2025-25289</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-25289</link>
      <description>&lt;p&gt;@octokit/request-error is an error class for Octokit request errors. Starting in version 1.0.0 and prior to version 6.1.7, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the processing of HTTP request headers. By sending an authorization header containing an excessively long sequence of spaces followed by a newline and &amp;#34;@&amp;#34;, an attacker can exploit inefficient regular expression processing, leading to excessive resource consumption. This can significantly degrade server performance or cause a denial-of-service (DoS) condition, impacting availability. Version 6.1.7 contains a fix for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;@octokit/request-error is an error class for Octokit request errors. Starting in version 1.0.0 and prior to version 6.1.7, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the processing of HTTP request headers. By sending an authorization header containing an excessively long sequence of spaces followed by a newline and &amp;#34;@&amp;#34;, an attacker can exploit inefficient regular expression processing, leading to excessive resource consumption. This can significantly degrade server performance or cause a denial-of-service (DoS) condition, impacting availability. Version 6.1.7 contains a fix for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-25289</guid>
    </item>
    <item>
      <title>GHSA-xx4v-prfh-6cgc — @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtrac…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xx4v-prfh-6cgc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @octokit/request-error&lt;/p&gt;
&lt;p&gt;### Summary
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the processing of HTTP request headers. By sending an authorization header containing an excessively long sequence of spaces followed by a newline and &amp;#34;@&amp;#34;, an attacker can exploit inefficient regular expression processing, leading to excessive resource consumption. This can significantly degrade server performance or cause a denial-of-service (DoS) condition, impacting availability.
### Details
The issue occurs at [line 52](https://github.com/octokit/request-error.js/blob/main/src/index.ts) of iterator.ts in the @octokit/request-error repository.
The vulnerability is caused by the use of an inefficient regular expression in the handling of the `authorization` header within the request processing logic:
```js
authorization: options.request.headers.authorization.replace(
  / .*$/, 
  &amp;#34; [REDACTED]&amp;#34;
)
```
The regular expression `/ .*$/` matches a space followed by any number of characters until the end of the line. This pattern is vulnerable to Regular Expression Denial of Service (ReDoS) when processing specially crafted input. Specifically, an attacker can send an `authorization` header containing a long sequence of spaces followed by a newline and &amp;#34;@&amp;#34;, such as:
```js
headers: {
  authorization: &amp;#34;&amp;#34; + &amp;#34; &amp;#34;.repeat(100000) + &amp;#34;\n@&amp;#34;,
}
```
Due to the way JavaScript&amp;#39;s regular expression engine backtracks while attempting to match the space followed by arbitrary characters, this input can cause excessiv…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @octokit/request-error&lt;/p&gt;
&lt;p&gt;### Summary
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the processing of HTTP request headers. By sending an authorization header containing an excessively long sequence of spaces followed by a newline and &amp;#34;@&amp;#34;, an attacker can exploit inefficient regular expression processing, leading to excessive resource consumption. This can significantly degrade server performance or cause a denial-of-service (DoS) condition, impacting availability.
### Details
The issue occurs at [line 52](https://github.com/octokit/request-error.js/blob/main/src/index.ts) of iterator.ts in the @octokit/request-error repository.
The vulnerability is caused by the use of an inefficient regular expression in the handling of the `authorization` header within the request processing logic:
```js
authorization: options.request.headers.authorization.replace(
  / .*$/, 
  &amp;#34; [REDACTED]&amp;#34;
)
```
The regular expression `/ .*$/` matches a space followed by any number of characters until the end of the line. This pattern is vulnerable to Regular Expression Denial of Service (ReDoS) when processing specially crafted input. Specifically, an attacker can send an `authorization` header containing a long sequence of spaces followed by a newline and &amp;#34;@&amp;#34;, such as:
```js
headers: {
  authorization: &amp;#34;&amp;#34; + &amp;#34; &amp;#34;.repeat(100000) + &amp;#34;\n@&amp;#34;,
}
```
Due to the way JavaScript&amp;#39;s regular expression engine backtracks while attempting to match the space followed by arbitrary characters, this input can cause excessiv…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xx4v-prfh-6cgc</guid>
    </item>
  </channel>
</rss>
