<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:22:37.028892+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-29848</id>
    <title>EUVD-2026-29848</title>
    <updated>2026-10-03T07:22:37.084482+00:00</updated>
    <content>EUVD-2026-29848</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-29848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-37634</id>
    <title>fkie_cve-2021-37634</title>
    <updated>2026-10-03T07:22:37.084522+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Leafkit is a templating language with Swift-inspired syntax. Versions prior to 1.3.0 are susceptible to Cross-site Scripting (XSS) attacks. This affects anyone passing unsanitised data to Leaf's variable tags. Before this fix, Leaf would not escape any strings passed to tags as variables. If an attacker managed to find a variable that was rendered with their unsanitised data, they could inject scripts into a generated Leaf page, which could enable XSS attacks if other mitigations such as a Content Security Policy were not enabled. This has been patched in 1.3.0. As a workaround sanitize any untrusted input before passing it to Leaf and enable a CSP to block inline script and CSS data.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-37634"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rv3x-xq3r-8j9h</id>
    <title>GHSA-rv3x-xq3r-8j9h — LeafKit allows XSS with untrusted user input</title>
    <updated>2026-10-03T07:22:37.084576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> SwiftURL: github.com/vapor/leaf-kit</p>
<p>### Impact
This affects anyone passing unsanitised data to Leaf's variable tags. Before this fix, Leaf would not escape any strings passed to tags as variables. If an attacker managed to find a variable that was rendered with their unsanitised data, they could inject scripts into a generated Leaf page, which could enable XSS attacks if other mitigations such as a Content Security Policy were not enabled.</p>
<p>### Patches
This has been patched in 1.3.0</p>
<p>### Workarounds
Sanitise any untrusted input before passing it to Leaf and enable a CSP to block inline script and CSS data.</p>
<p>### References
https://github.com/vapor/leaf-kit-ghsa-rv3x-xq3r-8j9h/pull/1</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Leaf Kit](https://github.com/vapor/leaf-kit)
* Email us at [security@vapor.codes](mailto:security@vapor.codes)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rv3x-xq3r-8j9h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-37634</id>
    <title>gsd-2021-37634</title>
    <updated>2026-10-03T07:22:37.084633+00:00</updated>
    <content>gsd-2021-37634</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-37634"/>
  </entry>
</feed>
