<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:11:01.267734+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-01008</id>
    <title>bdu:2021-01008</title>
    <updated>2026-10-04T01:11:01.533655+00:00</updated>
    <content>bdu:2021-01008</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-01008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-26247</id>
    <title>Withdrawn: BELL-CVE-2020-26247 — CVE-2020-26247 does not affect BellSoft software</title>
    <updated>2026-10-04T01:11:01.533693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-26247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-mikutter-cve-2020-26247</id>
    <title>BREW-mikutter-CVE-2020-26247 — Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability</title>
    <updated>2026-10-04T01:11:01.533713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: mikutter</p>
<p>### Severity</p>
<p>Nokogiri maintainers have evaluated this as [__Low Severity__ (CVSS3 2.6)](https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N).</p>
<p>### Description</p>
<p>In Nokogiri versions &lt;= 1.11.0.rc3, XML Schemas parsed by `Nokogiri::XML::Schema` are **trusted** by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks.</p>
<p>This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as **untrusted** by default whenever possible.</p>
<p>Please note that this security fix was pushed into a new minor version, 1.11.x, rather than a patch release to the 1.10.x branch, because it is a breaking change for some schemas and the risk was assessed to be "Low Severity".</p>
<p>### Affected Versions</p>
<p>Nokogiri `&lt;= 1.10.10` as well as prereleases `1.11.0.rc1`, `1.11.0.rc2`, and `1.11.0.rc3`</p>
<p>### Mitigation</p>
<p>There are no known workarounds for affected versions. Upgrade to Nokogiri `1.11.0.rc4` or later.</p>
<p>If, after upgrading to `1.11.0.rc4` or later, you wish to re-enable network access for resolution of external resources (i.e., return to the previous behavior):</p>
<p>1. Ensure the input is trusted. Do not enable this option for untrusted input.
2. When invoking the `Nokogiri::XML::Schema` constructor, pass as the second parameter an instance of `Nokogiri::XML::ParseOptions` with the `NONET` flag turned off.</p>
<p>So if your previous code was:</p>
<p>``` ruby
# in v1.11.0.rc3 and ear…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-mikutter-cve-2020-26247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-01538</id>
    <title>cnvd-2021-01538</title>
    <updated>2026-10-04T01:11:01.533771+00:00</updated>
    <content>cnvd-2021-01538</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-01538"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-46139</id>
    <title>EUVD-2026-46139</title>
    <updated>2026-10-04T01:11:01.533786+00:00</updated>
    <content>EUVD-2026-46139</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-46139"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-26247</id>
    <title>fkie_cve-2020-26247</title>
    <updated>2026-10-04T01:11:01.533798+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-26247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vr8q-g5c7-m54m</id>
    <title>GHSA-vr8q-g5c7-m54m — Nokogiri::XML::Schema trusts input by default, exposing risk of XXE vulnerability</title>
    <updated>2026-10-04T01:11:01.533821+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: nokogiri</p>
<p>### Severity</p>
<p>Nokogiri maintainers have evaluated this as [__Low Severity__ (CVSS3 2.6)](https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N).</p>
<p>### Description</p>
<p>In Nokogiri versions &lt;= 1.11.0.rc3, XML Schemas parsed by `Nokogiri::XML::Schema` are **trusted** by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks.</p>
<p>This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as **untrusted** by default whenever possible.</p>
<p>Please note that this security fix was pushed into a new minor version, 1.11.x, rather than a patch release to the 1.10.x branch, because it is a breaking change for some schemas and the risk was assessed to be "Low Severity".</p>
<p>### Affected Versions</p>
<p>Nokogiri `&lt;= 1.10.10` as well as prereleases `1.11.0.rc1`, `1.11.0.rc2`, and `1.11.0.rc3`</p>
<p>### Mitigation</p>
<p>There are no known workarounds for affected versions. Upgrade to Nokogiri `1.11.0.rc4` or later.</p>
<p>If, after upgrading to `1.11.0.rc4` or later, you wish to re-enable network access for resolution of external resources (i.e., return to the previous behavior):</p>
<p>1. Ensure the input is trusted. Do not enable this option for untrusted input.
2. When invoking the `Nokogiri::XML::Schema` constructor, pass as the second parameter an instance of `Nokogiri::XML::ParseOptions` with the `NONET` flag turned off.</p>
<p>So if your previous code was:</p>
<p>``` ruby
# in v1.11.0.rc3 and ear…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vr8q-g5c7-m54m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-26247</id>
    <title>gsd-2020-26247</title>
    <updated>2026-10-04T01:11:01.533867+00:00</updated>
    <content>gsd-2020-26247</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-26247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1144</id>
    <title>OESA-2021-1144 — rubygem-nokogiri security update</title>
    <updated>2026-10-04T01:11:01.533879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: rubygem-nokogiri</p>
<p>Nokogiri parses and searches XML/HTML very quickly, and also has correctly implemented CSS3 selector support as well as XPath support. Nokogiri also features an Hpricot compatibility layer to help ease the change to using correct CSS and XPath.

Security Fix(es):

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.(CVE-2020-26247)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1144"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0237-1</id>
    <title>openSUSE-SU-2021:0237-1 — Security update for rubygem-nokogiri</title>
    <updated>2026-10-04T01:11:01.533902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-nokogiri</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0237-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:4702</id>
    <title>RHSA-2021:4702 — Red Hat Security Advisory: Satellite 6.10 Release</title>
    <updated>2026-10-04T01:11:01.533921+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-ecdsa: Unexpected and  undocumented exceptions during signature decoding python-ecdsa: DER encoding is not being verified in signatures rubygem-activerecord-session_store: hijack sessions by using timing attacks targeting the session id rake: OS Command Injection via egrep in Rake::FileList guava: local information disclosure via temporary directory created with unsafe permissions PyYAML: incomplete fix for CVE-2020-1747 rubygem-nokogiri: XML external entity injection via Nokogiri::XML::Schema Satellite: Azure compute resource secret_key leak to authenticated users foreman: possible man-in-the-middle in smart_proxy realm_freeipa Satellite: BMC controller credential leak via API python-aiohttp: Open redirect in aiohttp.web_middlewares.normalize_path_middleware rubygem-actionpack: Possible Information Disclosure / Unintended Method Execution in Action Pack rails: Possible Denial of Service vulnerability in Action Dispatch rails: Possible DoS Vulnerability in Action Controller Token Authentication django: potential directory-traversal via uploaded files rubygem-puma: incomplete fix for CVE-2019-16770 allows Denial of Service (DoS) django: Potential directory-traversal via uploaded files rubygem-addressable: ReDoS in templates django: Potential directory traversal via ``admindocs`` python-urllib3: ReDoS in the parsing of authority part of URL django: Possible indeterminate SSRF, RFI, and LFI attacks since validators accepted leading zeros in IPv4 addresses</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:4702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:0210-1</id>
    <title>SUSE-SU-2021:0210-1 — Security update for rubygem-nokogiri</title>
    <updated>2026-10-04T01:11:01.533974+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-nokogiri</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:0210-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-26247</id>
    <title>UBUNTU-CVE-2020-26247</title>
    <updated>2026-10-04T01:11:01.533990+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: ruby-nokogiri</p>
<p>Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-26247"/>
  </entry>
</feed>
