<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:25:22.754997+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-11516</id>
    <title>bdu:2024-11516</title>
    <updated>2026-10-03T15:25:22.833015+00:00</updated>
    <content>bdu:2024-11516</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-11516"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-186138</id>
    <title>EUVD-2026-186138</title>
    <updated>2026-10-03T15:25:22.833052+00:00</updated>
    <content>EUVD-2026-186138</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-186138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-46976</id>
    <title>fkie_cve-2024-46976</title>
    <updated>2026-10-03T15:25:22.833067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or navigating to an attacker provided link. This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package. users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-46976"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5j94-f3mf-8685</id>
    <title>GHSA-5j94-f3mf-8685 — @backstage/plugin-techdocs-backend vulnerable to circumvention of cross site scripting protection</title>
    <updated>2026-10-03T15:25:22.833101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @backstage/plugin-techdocs-backend</p>
<p>### Impact</p>
<p>An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or navigating to an attacker provided link.</p>
<p>### Patches</p>
<p>This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package.</p>
<p>### References</p>
<p>If you have any questions or comments about this advisory:</p>
<p>Open an issue in the [Backstage repository](https://github.com/backstage/backstage)
Visit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5j94-f3mf-8685"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2024:11265</id>
    <title>RHBA-2024:11265 — Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.4.0 release.</title>
    <updated>2026-10-03T15:25:22.833133+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>http-proxy-middleware: http-proxy-middleware: Denial of Service via unhandled error during path matching cross-spawn: regular expression denial of service path-to-regexp: Backtracking regular expressions cause ReDoS body-parser: Denial of Service Vulnerability in body-parser plugin-catalog-backend: prototype pollution vulnerability plugin-techdocs-backend: storage bucket directory traversal in TechDocs plugin-techdocs-backend: circumvention of XSS protection in TechDocs backstage/plugin-app-backend: Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2024:11265"/>
  </entry>
</feed>
