<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:01:18.883087+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:2132</id>
    <title>ALSA-2024:2132 — Moderate: fence-agents security and bug fix update</title>
    <updated>2026-10-04T06:01:19.075771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: fence-agents-aliyun, AlmaLinux:9: fence-agents-all, AlmaLinux:9: fence-agents-amt-ws, AlmaLinux:9: fence-agents-apc, AlmaLinux:9: fence-agents-apc-snmp, AlmaLinux:9: fence-agents-aws, AlmaLinux:9: fence-agents-azure-arm, AlmaLinux:9: fence-agents-bladecenter, AlmaLinux:9: fence-agents-brocade, AlmaLinux:9: fence-agents-cisco-mds and 45 more</p>
<p>The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.</p>
<p>Security Fix(es):</p>
<p>* urllib3: Request body not stripped after redirect from 303 status changes request method to GET (CVE-2023-45803)
* pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex (CVE-2023-52323)
* jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:2132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-00884</id>
    <title>bdu:2024-00884</title>
    <updated>2026-10-04T06:01:19.075925+00:00</updated>
    <content>bdu:2024-00884</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-00884"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-22195</id>
    <title>BELL-CVE-2024-22195</title>
    <updated>2026-10-04T06:01:19.075946+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: py3-jinja2, Alpaquita:stream: py3-jinja2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-22195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2024-22195</id>
    <title>BREW-adr-viewer-CVE-2024-22195 — Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter</title>
    <updated>2026-10-04T06:01:19.075967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: adr-viewer</p>
<p>The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2024-22195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0305</id>
    <title>certfr-2024-avi-0305 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-04T06:01:19.075992+00:00</updated>
    <content>certfr-2024-avi-0305</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0305"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258564</id>
    <title>EUVD-2026-258564</title>
    <updated>2026-10-04T06:01:19.076009+00:00</updated>
    <content>EUVD-2026-258564</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-22195</id>
    <title>fkie_cve-2024-22195</title>
    <updated>2026-10-04T06:01:19.076020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-22195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h5c8-rqwp-cp95</id>
    <title>GHSA-h5c8-rqwp-cp95 — Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter</title>
    <updated>2026-10-04T06:01:19.076042+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: jinja2</p>
<p>The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h5c8-rqwp-cp95"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-22195</id>
    <title>gsd-2024-22195</title>
    <updated>2026-10-04T06:01:19.076064+00:00</updated>
    <content>gsd-2024-22195</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-22195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-22195</id>
    <title>msrc_CVE-2024-22195 — Jinja vulnerable to Cross-Site Scripting (XSS)</title>
    <updated>2026-10-04T06:01:19.076076+00:00</updated>
    <content>msrc_CVE-2024-22195</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-22195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1128</id>
    <title>OESA-2024-1128 — python-jinja2 security update</title>
    <updated>2026-10-04T06:01:19.076091+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: python-jinja2, openEuler:20.03-LTS-SP4: python-jinja2, openEuler:22.03-LTS: python-jinja2, openEuler:22.03-LTS-SP1: python-jinja2, openEuler:22.03-LTS-SP2: python-jinja2, openEuler:22.03-LTS-SP3: python-jinja2</p>
<p>Jinja2 is one of the most used template engines for Python. It is inspired by Django&amp;apos;s templating system but extends it with an expressive language that gives template authors a more powerful set of tools. On top of that it adds sandboxed execution and optional automatic escaping for applications where security is important.

Security Fix(es):

Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.
(CVE-2024-22195)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13581-1</id>
    <title>openSUSE-SU-2024:13581-1 — python310-Jinja2-3.1.3-1.1 on GA media</title>
    <updated>2026-10-04T06:01:19.076125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-Jinja2-3.1.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13581-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1473</id>
    <title>PYSEC-2026-1473 — Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter</title>
    <updated>2026-10-04T06:01:19.076142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: jinja2</p>
<p>The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1473"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2024:0891</id>
    <title>RHBA-2024:0891 — Red Hat Bug Fix Advisory: fence-agents update</title>
    <updated>2026-10-04T06:01:19.076162+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jinja2: HTML attribute injection when passing user input as keys to xmlattr filter</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2024:0891"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1863-1</id>
    <title>SUSE-SU-2024:1863-1 — Security update for python-Jinja2</title>
    <updated>2026-10-04T06:01:19.076178+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Jinja2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1863-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-22195</id>
    <title>UBUNTU-CVE-2024-22195</title>
    <updated>2026-10-04T06:01:19.076193+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: jinja2, Ubuntu:Pro:16.04:LTS: jinja2, Ubuntu:Pro:18.04:LTS: jinja2, Ubuntu:20.04:LTS: jinja2, Ubuntu:22.04:LTS: jinja2, Ubuntu:24.04:LTS: jinja2</p>
<p>Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-22195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0522</id>
    <title>WID-SEC-W-2024-0522 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-04T06:01:19.076221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, Phishing-Angriffe durchzuführen oder Cross-Site Scripting (XSS)-Angriffe auszuführen. Einige dieser Schwachstellen erfordern eine Benutzerinteraktion, um sie erfolgreich auszunutzen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0522"/>
  </entry>
</feed>
