<?xml version="1.0" encoding="UTF-8"?>
<!-- This sitemap was dynamically generated on June 1, 2026 at 3:13 pm by All in One SEO v4.9.7.2 - the original SEO plugin for WordPress. -->

<?xml-stylesheet type="text/xsl" href="https://www.netservicesgroup.com/default-sitemap.xsl"?>

<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Network Services Group</title>
		<link><![CDATA[https://www.netservicesgroup.com]]></link>
		<description><![CDATA[Network Services Group]]></description>
		<lastBuildDate><![CDATA[Wed, 04 Sep 2024 01:29:13 +0000]]></lastBuildDate>
		<docs>https://validator.w3.org/feed/docs/rss2.html</docs>
		<atom:link href="https://www.netservicesgroup.com/sitemap.rss" rel="self" type="application/rss+xml" />
		<ttl><![CDATA[60]]></ttl>

		<item>
			<guid><![CDATA[https://www.netservicesgroup.com/blog/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/blog/]]></link>
			<title>Blog</title>
			<pubDate><![CDATA[Wed, 04 Sep 2024 01:29:13 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21717-a-flaw-in-v8s-string-hashing-mechanism-causes-integer-like-strings-to-be-hashed-to-their-numeric-value-making-hash-collisions-trivially-predictable-by-crafting-a-request-that-ca/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-21717-a-flaw-in-v8s-string-hashing-mechanism-causes-integer-like-strings-to-be-hashed-to-their-numeric-value-making-hash-collisions-trivially-predictable-by-crafting-a-request-that-ca/]]></link>
			<title>CVE-2026-21717 A flaw in V8&#039;s string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8&#039;s internal string table, an attacker can significantly degrade performance of the Node.js process.

The most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table.

This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:41:41 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/type-confusion-in-v8-in-google-chrome-prior-to-142-0-7444-59-allowed-a-remote-attacker-to-potentially-exploit-heap-corruption-via-a-crafted-html-page-chromium-security-severity-high/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/type-confusion-in-v8-in-google-chrome-prior-to-142-0-7444-59-allowed-a-remote-attacker-to-potentially-exploit-heap-corruption-via-a-crafted-html-page-chromium-security-severity-high/]]></link>
			<title>Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:41:09 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/blog/transforming-online-retail-through-cloud-order-management-systems/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/blog/transforming-online-retail-through-cloud-order-management-systems/]]></link>
			<title>Transforming online retail through cloud order management systems</title>
			<pubDate><![CDATA[Mon, 01 Jun 2026 14:48:32 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39829-invoking-pathological-rsa-dsa-parameters-may-cause-dos-in-golang-org-x-crypto-ssh/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39829-invoking-pathological-rsa-dsa-parameters-may-cause-dos-in-golang-org-x-crypto-ssh/]]></link>
			<title>CVE-2026-39829 Invoking  pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh</title>
			<pubDate><![CDATA[Mon, 01 Jun 2026 13:42:15 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39821-invoking-failure-to-reject-ascii-only-punycode-encoded-labels-in-golang-org-x-net-idna/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39821-invoking-failure-to-reject-ascii-only-punycode-encoded-labels-in-golang-org-x-net-idna/]]></link>
			<title>CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna</title>
			<pubDate><![CDATA[Mon, 01 Jun 2026 13:42:03 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39835-invoking-server-panic-during-checkhostkey-authenticate-in-golang-org-x-crypto-ssh/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-39835-invoking-server-panic-during-checkhostkey-authenticate-in-golang-org-x-crypto-ssh/]]></link>
			<title>CVE-2026-39835 Invoking  server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh</title>
			<pubDate><![CDATA[Mon, 01 Jun 2026 13:41:51 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-23167-a-flaw-in-node-js-20s-http-parser-allows-improper-termination-of-http-1-headers-using-rnrx-instead-of-the-required-rnrn-this-inconsistency-enables-request-smuggling-a/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-23167-a-flaw-in-node-js-20s-http-parser-allows-improper-termination-of-http-1-headers-using-rnrx-instead-of-the-required-rnrn-this-inconsistency-enables-request-smuggling-a/]]></link>
			<title>CVE-2025-23167 A flaw in Node.js 20&#039;s HTTP parser allows improper termination of HTTP/1 headers using `rnrX` instead of the required `rnrn`.
This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests.

The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination.

Impact:
* This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:40:30 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-36137-a-vulnerability-has-been-identified-in-node-js-affecting-users-of-the-experimental-permission-model-when-the-allow-fs-write-flag-is-used-node-js-permission-model-do-not-operate-o/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-36137-a-vulnerability-has-been-identified-in-node-js-affecting-users-of-the-experimental-permission-model-when-the-allow-fs-write-flag-is-used-node-js-permission-model-do-not-operate-o/]]></link>
			<title>CVE-2024-36137 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the &#8211;allow-fs-write flag is used.

Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a &quot;read-only&quot; file descriptor to change the owner and permissions of a file.</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:40:05 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40034-gitoxide-command-injection-via-partial-gitmodules-override-in-gix-submodule/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40034-gitoxide-command-injection-via-partial-gitmodules-override-in-gix-submodule/]]></link>
			<title>CVE-2026-40034 gitoxide &#8211; Command Injection via Partial .gitmodules Override in gix-submodule</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:04:52 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44839-rabbitmq-unsanitized-vhost-names-allow-for-xss-in-management-ui/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44839-rabbitmq-unsanitized-vhost-names-allow-for-xss-in-management-ui/]]></link>
			<title>CVE-2026-44839 RabbitMQ: Unsanitized vhost names allow for XSS in management UI</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:04:44 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-15649-iouncompressunzip-versions-before-2-215-for-perl-propagate-uncaught-exception-when-parsing-zip-header-with-malformed-dos-date/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-15649-iouncompressunzip-versions-before-2-215-for-perl-propagate-uncaught-exception-when-parsing-zip-header-with-malformed-dos-date/]]></link>
			<title>CVE-2025-15649 IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:04:39 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-48962-iocompress-versions-before-2-220-for-perl-can-execute-arbitrary-code-in-fileglobmapper-via-an-attacker-controlled-output-glob/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-48962-iocompress-versions-before-2-220-for-perl-can-execute-arbitrary-code-in-fileglobmapper-via-an-attacker-controlled-output-glob/]]></link>
			<title>CVE-2026-48962 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:04:34 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28387-potential-use-after-free-in-dane-client-code/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28387-potential-use-after-free-in-dane-client-code/]]></link>
			<title>CVE-2026-28387 Potential Use-after-free in DANE Client Code</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:04:27 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28388-null-pointer-dereference-when-processing-a-delta-crl/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-28388-null-pointer-dereference-when-processing-a-delta-crl/]]></link>
			<title>CVE-2026-28388 NULL Pointer Dereference When Processing a Delta CRL</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:04:12 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34874-an-issue-was-discovered-in-mbed-tls-through-3-6-5-and-4-x-through-4-0-0-there-is-a-null-pointer-dereference-in-distinguished-name-parsing-that-allows-an-attacker-to-write-to-address-0/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34874-an-issue-was-discovered-in-mbed-tls-through-3-6-5-and-4-x-through-4-0-0-there-is-a-null-pointer-dereference-in-distinguished-name-parsing-that-allows-an-attacker-to-write-to-address-0/]]></link>
			<title>CVE-2026-34874 An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:04:01 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/blog/keep-your-mac-safe-from-modern-ransomware-threats/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/blog/keep-your-mac-safe-from-modern-ransomware-threats/]]></link>
			<title>Keep your Mac safe from modern ransomware threats</title>
			<pubDate><![CDATA[Mon, 25 May 2026 01:54:04 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43619-rsync-3-4-3-symlink-race-condition-via-path-based-syscalls/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43619-rsync-3-4-3-symlink-race-condition-via-path-based-syscalls/]]></link>
			<title>CVE-2026-43619 Rsync &lt; 3.4.3 Symlink Race Condition via Path-Based Syscalls</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:44:58 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/blog/how-mtd-boosts-android-devices-security/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/blog/how-mtd-boosts-android-devices-security/]]></link>
			<title>How MTD boosts Android devices&#8217; security</title>
			<pubDate><![CDATA[Mon, 25 May 2026 01:49:30 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/blog/5-ways-softphones-help-businesses-work-smarter/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/blog/5-ways-softphones-help-businesses-work-smarter/]]></link>
			<title>5 Ways softphones help businesses work smarter</title>
			<pubDate><![CDATA[Tue, 19 May 2026 19:26:56 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-22018-a-vulnerability-has-been-identified-in-node-js-affecting-users-of-the-experimental-permission-model-when-the-allow-fs-read-flag-is-used-this-flaw-arises-from-an-inadequate-permissio/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2024-22018-a-vulnerability-has-been-identified-in-node-js-affecting-users-of-the-experimental-permission-model-when-the-allow-fs-read-flag-is-used-this-flaw-arises-from-an-inadequate-permissio/]]></link>
			<title>CVE-2024-22018 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the &#8211;allow-fs-read flag is used.
This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.
This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.</title>
			<pubDate><![CDATA[Sun, 31 May 2026 13:39:56 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/blog/7-windows-11-features-smbs-should-use/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/blog/7-windows-11-features-smbs-should-use/]]></link>
			<title>7 Windows 11 features SMBs should use</title>
			<pubDate><![CDATA[Tue, 19 May 2026 19:26:56 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/]]></link>
			<title>Welcome to Network Services Group</title>
			<pubDate><![CDATA[Tue, 05 Aug 2025 20:21:25 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-25833-mbed-tls-3-5-0-to-3-6-5-fixed-in-3-6-6-and-4-1-0-has-a-buffer-overflow-in-the-x509_inet_pton_ipv6-function/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-25833-mbed-tls-3-5-0-to-3-6-5-fixed-in-3-6-6-and-4-1-0-has-a-buffer-overflow-in-the-x509_inet_pton_ipv6-function/]]></link>
			<title>CVE-2026-25833 Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function</title>
			<pubDate><![CDATA[Tue, 19 May 2026 12:10:33 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41054-missing-exit-out-of-permission-check-in-haveged-could-lead-to-root-exploit/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41054-missing-exit-out-of-permission-check-in-haveged-could-lead-to-root-exploit/]]></link>
			<title>CVE-2026-41054 Missing exit out of permission check in haveged could lead to root exploit</title>
			<pubDate><![CDATA[Sun, 24 May 2026 13:42:19 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68768-inet-frags-flush-pending-skbs-in-fqdir_pre_exit/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-68768-inet-frags-flush-pending-skbs-in-fqdir_pre_exit/]]></link>
			<title>CVE-2025-68768 inet: frags: flush pending skbs in fqdir_pre_exit()</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:42:33 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42944-heap-overflow-with-multiple-nsid-cookie-padding-edns-options/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42944-heap-overflow-with-multiple-nsid-cookie-padding-edns-options/]]></link>
			<title>CVE-2026-42944 Heap overflow with multiple NSID, COOKIE, PADDING EDNS options</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:40:36 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42923-degradation-of-service-with-unbounded-nsec3-hash-calculations/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42923-degradation-of-service-with-unbounded-nsec3-hash-calculations/]]></link>
			<title>CVE-2026-42923 Degradation of service with unbounded NSEC3 hash calculations</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:40:27 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38096-wifi-iwlwifi-dont-warn-when-if-there-is-a-fw-error/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38096-wifi-iwlwifi-dont-warn-when-if-there-is-a-fw-error/]]></link>
			<title>CVE-2025-38096 wifi: iwlwifi: don&#039;t warn when if there is a FW error</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:40:23 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40622-another-ghost-domain-names-attack-variant/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-40622-another-ghost-domain-names-attack-variant/]]></link>
			<title>CVE-2026-40622 Another &#039;ghost domain names&#039; attack variant</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:40:18 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38140-dm-limit-swapping-tables-for-devices-with-zone-write-plugs/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-38140-dm-limit-swapping-tables-for-devices-with-zone-write-plugs/]]></link>
			<title>CVE-2025-38140 dm: limit swapping tables for devices with zone write plugs</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:40:16 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42534-jostle-logic-bypass-degrades-resolution-performance/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42534-jostle-logic-bypass-degrades-resolution-performance/]]></link>
			<title>CVE-2026-42534 Jostle logic bypass degrades resolution performance</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:40:05 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/blog/elevating-search-rankings-through-smart-image-optimization/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/blog/elevating-search-rankings-through-smart-image-optimization/]]></link>
			<title>Elevating search rankings through smart image optimization</title>
			<pubDate><![CDATA[Tue, 19 May 2026 12:10:53 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-25834-mbed-tls-v3-3-0-up-to-3-6-5-and-4-0-0-allows-algorithm-downgrade/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-25834-mbed-tls-v3-3-0-up-to-3-6-5-and-4-0-0-allows-algorithm-downgrade/]]></link>
			<title>CVE-2026-25834 Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.</title>
			<pubDate><![CDATA[Tue, 19 May 2026 12:10:33 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41292-long-list-of-incoming-edns-options-degrades-performance/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41292-long-list-of-incoming-edns-options-degrades-performance/]]></link>
			<title>CVE-2026-41292 Long list of incoming EDNS options degrades performance</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:39:54 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33278-possible-arbitrary-code-execution-during-dnssec-validation/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-33278-possible-arbitrary-code-execution-during-dnssec-validation/]]></link>
			<title>CVE-2026-33278 Possible arbitrary code execution during DNSSEC validation</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:39:45 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41035-in-rsync-3-0-1-through-3-4-1-receive_xattr-relies-on-an-untrusted-length-value-during-a-qsort-call-leading-to-a-receiver-use-after-free-the-victim-must-run-rsync-with-x-aka-xattr/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-41035-in-rsync-3-0-1-through-3-4-1-receive_xattr-relies-on-an-untrusted-length-value-during-a-qsort-call-leading-to-a-receiver-use-after-free-the-victim-must-run-rsync-with-x-aka-xattr/]]></link>
			<title>CVE-2026-41035 In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka &#8211;xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:39:39 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44608-use-after-free-and-crash-under-special-conditions-in-rpz-code/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44608-use-after-free-and-crash-under-special-conditions-in-rpz-code/]]></link>
			<title>CVE-2026-44608 Use after free and crash under special conditions in RPZ code</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:39:36 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42959-crash-during-dnssec-validation-of-malicious-content/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42959-crash-during-dnssec-validation-of-malicious-content/]]></link>
			<title>CVE-2026-42959 Crash during DNSSEC validation of malicious content</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:39:27 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42960-possible-cache-poisoning-via-promiscuous-records-for-the-authority-section/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-42960-possible-cache-poisoning-via-promiscuous-records-for-the-authority-section/]]></link>
			<title>CVE-2026-42960 Possible cache poisoning via promiscuous records for the authority section</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:39:17 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32792-packet-of-death-with-dnscrypt/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-32792-packet-of-death-with-dnscrypt/]]></link>
			<title>CVE-2026-32792 Packet of death with DNSCrypt</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:39:08 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34872-an-issue-was-discovered-in-mbed-tls-3-5-x-and-3-6-x-through-3-6-5-and-tf-psa-crypto-1-0-there-is-a-lack-of-contributory-behavior-in-ffdh-due-to-improper-input-validation-using-finite/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34872-an-issue-was-discovered-in-mbed-tls-3-5-x-and-3-6-x-through-3-6-5-and-tf-psa-crypto-1-0-there-is-a-lack-of-contributory-behavior-in-ffdh-due-to-improper-input-validation-using-finite/]]></link>
			<title>CVE-2026-34872 An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).</title>
			<pubDate><![CDATA[Tue, 19 May 2026 12:10:33 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34871-an-issue-was-discovered-in-mbed-tls-before-3-6-6-and-4-x-before-4-1-0-and-tf-psa-crypto-before-1-1-0-there-is-a-predictable-seed-in-a-pseudo-random-number-generator-prng/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34871-an-issue-was-discovered-in-mbed-tls-before-3-6-6-and-4-x-before-4-1-0-and-tf-psa-crypto-before-1-1-0-there-is-a-predictable-seed-in-a-pseudo-random-number-generator-prng/]]></link>
			<title>CVE-2026-34871 An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).</title>
			<pubDate><![CDATA[Tue, 19 May 2026 12:10:33 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44673-libyang-lyb_read_string-integer-overflow-→-heap-buffer-overflow/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44673-libyang-lyb_read_string-integer-overflow-→-heap-buffer-overflow/]]></link>
			<title>CVE-2026-44673 libyang: lyb_read_string() integer overflow → heap buffer overflow</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:44:35 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-7210-the-expat-and-elementtree-parsers-use-insufficient-entropy-for-xml-hash-flooding-protection/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-7210-the-expat-and-elementtree-parsers-use-insufficient-entropy-for-xml-hash-flooding-protection/]]></link>
			<title>CVE-2026-7210 The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection</title>
			<pubDate><![CDATA[Tue, 19 May 2026 12:10:33 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34873-an-issue-was-discovered-in-mbed-tls-3-5-0-through-4-0-0-client-impersonation-can-occur-while-resuming-a-tls-1-3-session/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-34873-an-issue-was-discovered-in-mbed-tls-3-5-0-through-4-0-0-client-impersonation-can-occur-while-resuming-a-tls-1-3-session/]]></link>
			<title>CVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.</title>
			<pubDate><![CDATA[Tue, 19 May 2026 12:10:33 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44390-unbounded-name-compression-in-certain-cases-causes-degradation-of-service/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-44390-unbounded-name-compression-in-certain-cases-causes-degradation-of-service/]]></link>
			<title>CVE-2026-44390 Unbounded name compression in certain cases causes degradation of service</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:40:45 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43352-i3c-mipi-i3c-hci-correct-ring_ctrl_abort-handling-in-dma-dequeue/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-43352-i3c-mipi-i3c-hci-correct-ring_ctrl_abort-handling-in-dma-dequeue/]]></link>
			<title>CVE-2026-43352 i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue</title>
			<pubDate><![CDATA[Tue, 19 May 2026 12:10:33 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31717-ksmbd-validate-owner-of-durable-handle-on-reconnect/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2026-31717-ksmbd-validate-owner-of-durable-handle-on-reconnect/]]></link>
			<title>CVE-2026-31717 ksmbd: validate owner of durable handle on reconnect</title>
			<pubDate><![CDATA[Tue, 19 May 2026 12:10:33 +0000]]></pubDate>
		</item>
					<item>
			<guid><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-51480-path-traversal-vulnerability-in-onnx-external_data_helper-save_external_data-in-onnx-1-17-0-allows-attackers-to-overwrite-arbitrary-files-by-supplying-crafted-external_data-location-pat/]]></guid>
			<link><![CDATA[https://www.netservicesgroup.com/msrc-blog-alerts/cve-2025-51480-path-traversal-vulnerability-in-onnx-external_data_helper-save_external_data-in-onnx-1-17-0-allows-attackers-to-overwrite-arbitrary-files-by-supplying-crafted-external_data-location-pat/]]></link>
			<title>CVE-2025-51480 Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.</title>
			<pubDate><![CDATA[Sat, 23 May 2026 13:40:43 +0000]]></pubDate>
		</item>
				</channel>
</rss>
