<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:35:30.718929+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00249</id>
    <title>bdu:2022-00249</title>
    <updated>2026-10-02T15:35:30.735958+00:00</updated>
    <content>bdu:2022-00249</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-655</id>
    <title>certfr-2022-avi-655 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL.
Certaines d'entre elles permettent à un attaquant de…</title>
    <updated>2026-10-02T15:35:30.735996+00:00</updated>
    <content>certfr-2022-avi-655</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-655"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-45995</id>
    <title>EUVD-2026-45995</title>
    <updated>2026-10-02T15:35:30.736016+00:00</updated>
    <content>EUVD-2026-45995</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-45995"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-26237</id>
    <title>fkie_cve-2020-26237</title>
    <updated>2026-10-02T15:35:30.736030+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype pollution of the base object's prototype during highlighting. If you allow users to insert custom HTML code blocks into your page/app via parsing Markdown code blocks (or similar) and do not filter the language names the user can provide you may be vulnerable. The pollution should just be harmless data but this can cause problems for applications not expecting these properties to exist and can result in strange behavior or application crashes, i.e. a potential DOS vector. If your website or application does not render user provided data it should be unaffected. Versions 9.18.2 and 10.1.2 and newer include fixes for this vulnerability. If you are using version 7 or 8 you are encouraged to upgrade to a newer release.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-26237"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vfrc-7r7c-w9mx</id>
    <title>GHSA-vfrc-7r7c-w9mx — Prototype Pollution in highlight.js</title>
    <updated>2026-10-02T15:35:30.736065+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: highlight.js</p>
<p>### Impact</p>
<p>Affected versions of this package are vulnerable to Prototype Pollution.  A malicious HTML code block can be crafted that will result in prototype pollution of the base object's prototype during highlighting.  If you allow users to insert custom HTML code blocks into your page/app via parsing Markdown code blocks (or similar) and do not filter the language names the user can provide you may be vulnerable.</p>
<p>The pollution should just be harmless data but this can cause problems for applications not expecting these properties to exist and can result in strange behavior or application crashes, i.e. a potential DOS vector.</p>
<p>_If your website or application does not render user provided data it should be unaffected._</p>
<p>### Patches</p>
<p>Versions 9.18.2 and 10.1.2 and newer include fixes for this vulnerability.  If you are using version 7 or 8 you are encouraged to upgrade to a newer release.</p>
<p>### Workarounds</p>
<p>#### Patch your library</p>
<p>Manually patch your library to create null objects for both `languages` and `aliases`:</p>
<p>```js
const HLJS = function(hljs) {
  // ...
  var languages = Object.create(null);
  var aliases = Object.create(null);
```</p>
<p>#### Filter out bad data from end users:</p>
<p>Filter the language names that users are allowed to inject into your HTML to guarantee they are valid.</p>
<p>### References</p>
<p>* [What is Prototype Pollution?](https://codeburst.io/what-is-prototype-pollution-49482fc4b638)
* https://github.com/highlightjs/highlight.js/pull/2636</p>
<p>### For more informat…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vfrc-7r7c-w9mx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-26237</id>
    <title>gsd-2020-26237</title>
    <updated>2026-10-02T15:35:30.736115+00:00</updated>
    <content>gsd-2020-26237</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-26237"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:3917</id>
    <title>RHSA-2021:3917 — Red Hat Security Advisory: Red Hat Quay v3.6.0 security, bug fix and enhancement update</title>
    <updated>2026-10-02T15:35:30.736127+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-debug: Regular expression Denial of Service nodejs-mime: Regular expression Denial of Service nodejs-is-my-json-valid: ReDoS when validating JSON fields with email format nodejs-braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js lodash: Prototype pollution in utilities function hoek: Prototype pollution in utilities function nodejs-url-parse: incorrect hostname in url parsing nodejs-extend: Prototype pollution can allow attackers to modify object properties nodejs-stringstream: out-of-bounds read leading to uninitialized memory exposure nodejs-handlebars: lookup helper fails to properly validate templates allowing for arbitrary JavaScript execution nodejs-handlebars: an endless loop while processing specially-crafted templates leads to DoS lodash: uncontrolled resource consumption in Data handler causing denial of service nodejs-yargs-parser: prototype pollution vulnerability nodejs-lodash: prototype pollution in zipObjectDeep function nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function nodejs-highlight-js: prototype pollution via a crafted HTML code block urijs: Hostname spoofing via backslashes in URL python-pillow: Buffer over-read in PCX image reader python-pillow: decoding crafted YCbCr files could result in heap-based buffer overflow browserslist: parsing of invalid queries could result in Regular Expression Denial of Service (ReDoS) nodejs-postcss: Regular expression denial of service during source map parsing no…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:3917"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-26237</id>
    <title>UBUNTU-CVE-2020-26237</title>
    <updated>2026-10-02T15:35:30.736200+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: highlight.js, Ubuntu:Pro:18.04:LTS: highlight.js, Ubuntu:Pro:20.04:LTS: highlight.js</p>
<p>Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype pollution of the base object's prototype during highlighting. If you allow users to insert custom HTML code blocks into your page/app via parsing Markdown code blocks (or similar) and do not filter the language names the user can provide you may be vulnerable. The pollution should just be harmless data but this can cause problems for applications not expecting these properties to exist and can result in strange behavior or application crashes, i.e. a potential DOS vector. If your website or application does not render user provided data it should be unaffected. Versions 9.18.2 and 10.1.2 and newer include fixes for this vulnerability. If you are using version 7 or 8 you are encouraged to upgrade to a newer release.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-26237"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0735</id>
    <title>WID-SEC-W-2022-0735 — Oracle MySQL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:35:30.736229+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0735"/>
  </entry>
</feed>
