<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:45:16.969135+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10872</id>
    <title>bdu:2026-10872</title>
    <updated>2026-10-03T14:45:17.039444+00:00</updated>
    <content>bdu:2026-10872</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10872"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0917</id>
    <title>certfr-2026-avi-0917 — De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Elles permettent à un attaquant de provoquer un…</title>
    <updated>2026-10-03T14:45:17.039489+00:00</updated>
    <content>certfr-2026-avi-0917</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0917"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-fr63847</id>
    <title>Withdrawn: CLEANSTART-2026-FR63847 — yawkat LZ4 Java provides LZ4 compression for Java</title>
    <updated>2026-10-03T14:45:17.039508+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: elasticsearch</p>
<p>Multiple security vulnerabilities affect the elasticsearch package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-fr63847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261937</id>
    <title>EUVD-2026-261937</title>
    <updated>2026-10-03T14:45:17.039539+00:00</updated>
    <content>EUVD-2026-261937</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261937"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66021</id>
    <title>fkie_cve-2025-66021</title>
    <updated>2026-10-03T14:45:17.039551+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against XSS. In version 20240325.1,  OWASP java html sanitizer is vulnerable to XSS if HtmlPolicyBuilder allows noscript and style tags with allowTextIn inside the style tag. This could lead to XSS if the payload is crafted in such a way that it does not sanitise the CSS and allows tags which is not mentioned in HTML policy. At time of publication no known patch is available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-66021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g9gq-3pfx-2gw2</id>
    <title>GHSA-g9gq-3pfx-2gw2 — OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization</title>
    <updated>2026-10-03T14:45:17.039575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer</p>
<p>### Summary
It is observed that OWASP java html sanitizer is vulnerable to XSS if HtmlPolicyBuilder allows `noscript` and `style` tags with `allowTextIn` inside the style tag. This could lead to XSS if the payload is crafted in such a way that it does not sanitise the CSS and allows tags which is not mentioned in HTML policy.</p>
<p>### Details</p>
<p>The OWASP java HTML sanitizer is vulnerable to XSS. This only happens when HtmlPolicyBuilder allows `noscript` &amp; `style` tag with `allowTextIn` inside style tags.</p>
<p>The following condition is very edge case but if users combine a HtmlPolicyBuilder with any other tags except `noscript` and allow `style` tag with `allowTextIn` inside the style tag then In this case sanitizer would be safe from XSS. This happens because how the browser also perceives `noscript` tags post sanitization.</p>
<p>### PoC</p>
<p>1.  Lets create a `HtmlPolicyBuilder` which allows `p, noscript, style` html tags and allows `.allowTextIn("style")`.
2.  There are two XSS payloads which very identical and only difference is one has p tag and other has noscript tag.
These payload have script tags that could be vulnerable to XSS and should be stripped out after sanitisation.</p>
<p>```HTML
1. &lt;noscript&gt;&lt;style&gt;&lt;/noscript&gt;&lt;script&gt;alert(1)&lt;/script&gt;
2. &lt;p&gt;&lt;style&gt;&lt;/p&gt;&lt;script&gt;alert(1)&lt;/script&gt;
```</p>
<p>3. Run the following piece of code which sanitizes the payload.</p>
<p>```java
public class main {
	private static final String ALLOWED_HTML_TAGS = "p, noscript, style";</p>
<p>/**
	 * Description of vulnerabil…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g9gq-3pfx-2gw2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0438</id>
    <title>WID-SEC-W-2026-0438 — Atlassian Bamboo und Confluence (Data Center und Server): Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:45:17.039630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Atlassian Bamboo und Atlassian Confluence ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und Cross-Site-Scripting-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0438"/>
  </entry>
</feed>
