<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:08:35 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>EUVD-2026-334049</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-334049</link>
      <description>EUVD-2026-334049</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-334049</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59724</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59724</link>
      <description>&lt;p&gt;Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of the clients object during WebTransport upgrade handling, causing a TypeError and denial of service. This issue is fixed in version 6.6.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of the clients object during WebTransport upgrade handling, causing a TypeError and denial of service. This issue is fixed in version 6.6.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59724</guid>
    </item>
    <item>
      <title>GHSA-gr94-w7qr-f4j3 — Socket.IO: Engine.IO WebTransport SID DoS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gr94-w7qr-f4j3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: engine.io&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Engine.IO servers with **WebTransport enabled** are vulnerable to a remotely triggerable denial of service.&lt;/p&gt;
&lt;p&gt;A malicious unauthenticated client can send a crafted WebTransport upgrade request containing a specially chosen session ID, such as `__proto__`. Because the session ID lookup did not properly verify that the key was an own property of the clients object, the lookup could resolve to an inherited prototype property instead of a valid Engine.IO client.&lt;/p&gt;
&lt;p&gt;This can cause a `TypeError` during WebTransport upgrade handling. Since the failure occurs in an asynchronous context, it may result in an unhandled Promise rejection and terminate the Node.js process on affected Node.js versions/configurations.&lt;/p&gt;
&lt;p&gt;Successful exploitation can allow an unauthenticated remote attacker to crash the server process and cause denial of service. Under a process supervisor, repeated exploitation may cause crash loops.&lt;/p&gt;
&lt;p&gt;Affected configurations are limited to deployments where WebTransport support is enabled. WebTransport is not enabled by default.&lt;/p&gt;
&lt;p&gt;Affected versions:&lt;/p&gt;
&lt;p&gt;- `engine.io &amp;gt;= 6.5.0 &amp;lt; 6.6.7`&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The issue was fixed in:&lt;/p&gt;
&lt;p&gt;- **engine.io 6.6.7**&lt;/p&gt;
&lt;p&gt;Users should upgrade to `engine.io@6.6.7` or later.&lt;/p&gt;
&lt;p&gt;If using Socket.IO packages that depend on Engine.IO, users should update to a Socket.IO release that includes the patched Engine.IO version.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If upgrading immediately is not possible, affected users can mitigate the issue by disabling WebTransport support.&lt;/p&gt;
&lt;p&gt;WebT…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: engine.io&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Engine.IO servers with **WebTransport enabled** are vulnerable to a remotely triggerable denial of service.&lt;/p&gt;
&lt;p&gt;A malicious unauthenticated client can send a crafted WebTransport upgrade request containing a specially chosen session ID, such as `__proto__`. Because the session ID lookup did not properly verify that the key was an own property of the clients object, the lookup could resolve to an inherited prototype property instead of a valid Engine.IO client.&lt;/p&gt;
&lt;p&gt;This can cause a `TypeError` during WebTransport upgrade handling. Since the failure occurs in an asynchronous context, it may result in an unhandled Promise rejection and terminate the Node.js process on affected Node.js versions/configurations.&lt;/p&gt;
&lt;p&gt;Successful exploitation can allow an unauthenticated remote attacker to crash the server process and cause denial of service. Under a process supervisor, repeated exploitation may cause crash loops.&lt;/p&gt;
&lt;p&gt;Affected configurations are limited to deployments where WebTransport support is enabled. WebTransport is not enabled by default.&lt;/p&gt;
&lt;p&gt;Affected versions:&lt;/p&gt;
&lt;p&gt;- `engine.io &amp;gt;= 6.5.0 &amp;lt; 6.6.7`&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The issue was fixed in:&lt;/p&gt;
&lt;p&gt;- **engine.io 6.6.7**&lt;/p&gt;
&lt;p&gt;Users should upgrade to `engine.io@6.6.7` or later.&lt;/p&gt;
&lt;p&gt;If using Socket.IO packages that depend on Engine.IO, users should update to a Socket.IO release that includes the patched Engine.IO version.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If upgrading immediately is not possible, affected users can mitigate the issue by disabling WebTransport support.&lt;/p&gt;
&lt;p&gt;WebT…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gr94-w7qr-f4j3</guid>
    </item>
    <item>
      <title>RHSA-2026:26994 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:26994</link>
      <description>&lt;p&gt;dotnet: .NET: Local file tampering via link following vulnerability dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` engine.io: Engine.IO: Denial of Service via crafted WebTransport session ID js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: .NET: Local file tampering via link following vulnerability dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` engine.io: Engine.IO: Denial of Service via crafted WebTransport session ID js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:26994</guid>
    </item>
  </channel>
</rss>
