<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:47:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-330234</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330234</link>
      <description>EUVD-2026-330234</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330234</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44726</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44726</link>
      <description>&lt;p&gt;Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno&amp;#39;s Node.js tls compatibility layer could cause a TLS client to transmit application data in plaintext after a connection retry. When `autoSelectFamily was enabled and the first address-family attempt failed, the socket reinitialization path reused a stale TLS upgrade hook that was bound to the original, failed handle. As a result, the replacement TCP connection was never upgraded to TLS, and any data the application wrote before the secureConnect event travelled over the network unencrypted. A network attacker positioned to cause the initial connection attempt to fail (for example, by dropping IPv6 traffic on a dual-stack host) could deterministically trigger the fallback path and observe or tamper with traffic that the application believed was TLS-protected. This vulnerability is fixed in 2.7.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno&amp;#39;s Node.js tls compatibility layer could cause a TLS client to transmit application data in plaintext after a connection retry. When `autoSelectFamily was enabled and the first address-family attempt failed, the socket reinitialization path reused a stale TLS upgrade hook that was bound to the original, failed handle. As a result, the replacement TCP connection was never upgraded to TLS, and any data the application wrote before the secureConnect event travelled over the network unencrypted. A network attacker positioned to cause the initial connection attempt to fail (for example, by dropping IPv6 traffic on a dual-stack host) could deterministically trigger the fallback path and observe or tamper with traffic that the application believed was TLS-protected. This vulnerability is fixed in 2.7.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44726</guid>
    </item>
    <item>
      <title>GHSA-chqv-56wv-7564 — Deno's TLS retry copies stale upgrade hook, risking plaintext traffic</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-chqv-56wv-7564</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: deno&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A flaw in Deno&amp;#39;s Node.js tls compatibility layer could cause a TLS client to transmit application data in plaintext after a connection retry. When `autoSelectFamily was enabled and the first address-family attempt failed, the socket reinitialization path reused a stale TLS upgrade hook that was bound to the original, failed handle.&lt;/p&gt;
&lt;p&gt;As a result, the replacement TCP connection was never upgraded to TLS, and any data the application wrote before the `secureConnect` event travelled over the network unencrypted.&lt;/p&gt;
&lt;p&gt;A network attacker positioned to cause the initial connection attempt to fail (for example, by dropping IPv6 traffic on a dual-stack host) could deterministically trigger the fallback path and observe or tamper with traffic that the application believed was TLS-protected.&lt;/p&gt;
&lt;p&gt;**Affected APIs**: Applications using Deno&amp;#39;s `node:tls` or `node:https` surface with `autoSelectFamily` enabled (the default) that wrote to the socket before the `secureConnect` event.&lt;/p&gt;
&lt;p&gt;## Proof of concept&lt;/p&gt;
&lt;p&gt;`attacker.mjs` (captures whatever the client sends)&lt;/p&gt;
&lt;p&gt;```ts
import net from &amp;#34;node:net&amp;#34;;&lt;/p&gt;
&lt;p&gt;const server = net.createServer((socket) =&amp;gt; {
  console.log(&amp;#34;[attacker] client connected from&amp;#34;, socket.remoteAddress);
  socket.on(&amp;#34;data&amp;#34;, (chunk) =&amp;gt; {
    // If TLS were working, this would be an opaque ClientHello.
    // If the bug fires, we see the application payload in cleartext.
    console.log(&amp;#34;[attacker] received&amp;#34;, chunk.length, &amp;#34;bytes:&amp;#34;);
    console.log(chunk.toString(&amp;#34;utf8&amp;#34;));
  });
});…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: deno&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A flaw in Deno&amp;#39;s Node.js tls compatibility layer could cause a TLS client to transmit application data in plaintext after a connection retry. When `autoSelectFamily was enabled and the first address-family attempt failed, the socket reinitialization path reused a stale TLS upgrade hook that was bound to the original, failed handle.&lt;/p&gt;
&lt;p&gt;As a result, the replacement TCP connection was never upgraded to TLS, and any data the application wrote before the `secureConnect` event travelled over the network unencrypted.&lt;/p&gt;
&lt;p&gt;A network attacker positioned to cause the initial connection attempt to fail (for example, by dropping IPv6 traffic on a dual-stack host) could deterministically trigger the fallback path and observe or tamper with traffic that the application believed was TLS-protected.&lt;/p&gt;
&lt;p&gt;**Affected APIs**: Applications using Deno&amp;#39;s `node:tls` or `node:https` surface with `autoSelectFamily` enabled (the default) that wrote to the socket before the `secureConnect` event.&lt;/p&gt;
&lt;p&gt;## Proof of concept&lt;/p&gt;
&lt;p&gt;`attacker.mjs` (captures whatever the client sends)&lt;/p&gt;
&lt;p&gt;```ts
import net from &amp;#34;node:net&amp;#34;;&lt;/p&gt;
&lt;p&gt;const server = net.createServer((socket) =&amp;gt; {
  console.log(&amp;#34;[attacker] client connected from&amp;#34;, socket.remoteAddress);
  socket.on(&amp;#34;data&amp;#34;, (chunk) =&amp;gt; {
    // If TLS were working, this would be an opaque ClientHello.
    // If the bug fires, we see the application payload in cleartext.
    console.log(&amp;#34;[attacker] received&amp;#34;, chunk.length, &amp;#34;bytes:&amp;#34;);
    console.log(chunk.toString(&amp;#34;utf8&amp;#34;));
  });
});…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-chqv-56wv-7564</guid>
    </item>
  </channel>
</rss>
