<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:00:14 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-14936</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14936</link>
      <description>bdu:2026-14936</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14936</guid>
    </item>
    <item>
      <title>EUVD-2026-370757</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-370757</link>
      <description>EUVD-2026-370757</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-370757</guid>
    </item>
    <item>
      <title>fkie_cve-2026-92941</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92941</link>
      <description>&lt;p&gt;vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-92941</guid>
    </item>
    <item>
      <title>GHSA-98xx-8mx4-x7cm — vm2 NodeVM can replace the host process TLS trust store</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-98xx-8mx4-x7cm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;Summary&lt;/p&gt;
&lt;p&gt;vm2 3.11.6 exposes the host `tls` module to a `NodeVM` when that builtin is explicitly allowed. Although the module object is wrapped as read-only, its functions still execute against process-wide host state. On Node.js versions that provide `tls.setDefaultCACertificates()`, sandbox code can replace the certificate authorities trusted by subsequent host-realm TLS clients.&lt;/p&gt;
&lt;p&gt;The exploit needs only the narrowly allowed `tls` and `url` builtins. It does not require `fs`, `process`, `module`, `child_process`, an external package, or a general `&amp;#39;*&amp;#39;` builtin grant. A host HTTPS request rejected an attacker certificate before sandbox execution, then accepted the same certificate and returned an application marker after the sandbox replaced the default CA list.&lt;/p&gt;
&lt;p&gt;This crosses the intended sandbox boundary. An attacker can make host HTTPS clients trust an attacker-controlled CA, enabling credential theft and response tampering when the attacker can influence a subsequent destination or network path. Replacing the list also removes the normal trust roots, disrupting unrelated host TLS traffic.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable boundary is the default builtin loader in `lib/builtin.js`. Builtins that are not classified as dangerous are exposed through a recursive read-only bridge:&lt;/p&gt;
&lt;p&gt;```js
builtins.set(key, special ? special : vm =&amp;gt; vm.readonly(hostRequire(key)));
```&lt;/p&gt;
&lt;p&gt;The read-only wrapper prevents ordinary property assignment through the sandbox proxy. It does not make calls such as…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;Summary&lt;/p&gt;
&lt;p&gt;vm2 3.11.6 exposes the host `tls` module to a `NodeVM` when that builtin is explicitly allowed. Although the module object is wrapped as read-only, its functions still execute against process-wide host state. On Node.js versions that provide `tls.setDefaultCACertificates()`, sandbox code can replace the certificate authorities trusted by subsequent host-realm TLS clients.&lt;/p&gt;
&lt;p&gt;The exploit needs only the narrowly allowed `tls` and `url` builtins. It does not require `fs`, `process`, `module`, `child_process`, an external package, or a general `&amp;#39;*&amp;#39;` builtin grant. A host HTTPS request rejected an attacker certificate before sandbox execution, then accepted the same certificate and returned an application marker after the sandbox replaced the default CA list.&lt;/p&gt;
&lt;p&gt;This crosses the intended sandbox boundary. An attacker can make host HTTPS clients trust an attacker-controlled CA, enabling credential theft and response tampering when the attacker can influence a subsequent destination or network path. Replacing the list also removes the normal trust roots, disrupting unrelated host TLS traffic.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable boundary is the default builtin loader in `lib/builtin.js`. Builtins that are not classified as dangerous are exposed through a recursive read-only bridge:&lt;/p&gt;
&lt;p&gt;```js
builtins.set(key, special ? special : vm =&amp;gt; vm.readonly(hostRequire(key)));
```&lt;/p&gt;
&lt;p&gt;The read-only wrapper prevents ordinary property assignment through the sandbox proxy. It does not make calls such as…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-98xx-8mx4-x7cm</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</guid>
    </item>
  </channel>
</rss>
