<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:50:45.428899+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-07164</id>
    <title>bdu:2024-07164</title>
    <updated>2026-10-02T19:50:45.444706+00:00</updated>
    <content>bdu:2024-07164</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-07164"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-40896</id>
    <title>BELL-CVE-2024-40896</title>
    <updated>2026-10-02T19:50:45.444742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: libxml2, BellSoft Hardened Containers:stream: libxml2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-40896"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-java-2024-40896</id>
    <title>BIT-java-2024-40896</title>
    <updated>2026-10-02T19:50:45.444770+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: java</p>
<p>In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-java-2024-40896"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0320</id>
    <title>certfr-2025-avi-0320 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Elles permettent à un attaquant de provoquer un déni…</title>
    <updated>2026-10-02T19:50:45.444792+00:00</updated>
    <content>certfr-2025-avi-0320</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0320"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-219884</id>
    <title>EUVD-2026-219884</title>
    <updated>2026-10-02T19:50:45.444808+00:00</updated>
    <content>EUVD-2026-219884</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-219884"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-40896</id>
    <title>fkie_cve-2024-40896</title>
    <updated>2026-10-02T19:50:45.444819+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-40896"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6c2p-rqx3-w4px</id>
    <title>GHSA-6c2p-rqx3-w4px</title>
    <updated>2026-10-02T19:50:45.444839+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6c2p-rqx3-w4px"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-40896</id>
    <title>msrc_CVE-2024-40896 — In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for extern…</title>
    <updated>2026-10-02T19:50:45.444853+00:00</updated>
    <content>msrc_CVE-2024-40896</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-40896"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1950</id>
    <title>OESA-2024-1950 — libxml2 security update</title>
    <updated>2026-10-02T19:50:45.444868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: libxml2</p>
<p>This library allows to manipulate XML files. It includes support to read, modify and write XML and HTML files. There is DTDs support this includes parsing and validation even with complex DtDs, either at parse time or later once the document has been modified. The output can be a simple SAX stream or and in-memory DOM like representations. In this case one can use the built-in XPath and XPointer implementation to select sub nodes or ranges. A flexible Input/Output mechanism is available, with existing HTTP and FTP modules and combined to an URI library.

Security Fix(es):

(CVE-2024-40896)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1950"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14241-1</id>
    <title>openSUSE-SU-2024:14241-1 — libxml2-2-2.12.9-1.1 on GA media</title>
    <updated>2026-10-02T19:50:45.444889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libxml2-2-2.12.9-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14241-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:20116-1</id>
    <title>SUSE-SU-2025:20116-1 — Security update for libxml2</title>
    <updated>2026-10-02T19:50:45.444903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libxml2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:20116-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-40896</id>
    <title>Withdrawn: UBUNTU-CVE-2024-40896</title>
    <updated>2026-10-02T19:50:45.444915+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:24.10: libxml2</p>
<p>In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-40896"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3746</id>
    <title>WID-SEC-W-2024-3746 — libxml2: Schwachstelle ermöglicht XXE Angriffe</title>
    <updated>2026-10-02T19:50:45.444932+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libxml2 ausnutzen, um Dateien zu manipulieren oder einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3746"/>
  </entry>
</feed>
