<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:55:18.240629+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</id>
    <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T15:55:18.282949+00:00</updated>
    <content>certfr-2026-avi-0667</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</id>
    <title>Withdrawn: CLEANSTART-2026-CE10526 — Security fixes for CVE-2025-64756, CVE-2025-69873, CVE-2026-1525, CVE-2026-1526, CVE-2026-1527, CVE-2026-1528, CVE-2026…</title>
    <updated>2026-10-03T15:55:18.282997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: renovate</p>
<p>Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-268116</id>
    <title>EUVD-2026-268116</title>
    <updated>2026-10-03T15:55:18.283035+00:00</updated>
    <content>EUVD-2026-268116</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-268116"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25128</id>
    <title>fkie_cve-2026-25128</title>
    <updated>2026-10-03T15:55:18.283054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points (e.g., `&amp;#9999999;` or `&amp;#xFFFFFF;`). This causes the parser to throw an uncaught exception, crashing any application that processes untrusted XML input. Version 5.3.4 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-37qj-frw5-hhjh</id>
    <title>GHSA-37qj-frw5-hhjh — fast-xml-parser has RangeError DoS Numeric Entities Bug</title>
    <updated>2026-10-03T15:55:18.283101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: fast-xml-parser</p>
<p>### Summary
A RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points (e.g., `&amp;#9999999;` or `&amp;#xFFFFFF;`). This causes the parser to throw an uncaught exception, crashing any application that processes untrusted XML input.</p>
<p>### Details
The vulnerability exists in `/src/xmlparser/OrderedObjParser.js` at lines 44-45:</p>
<p>```javascript
"num_dec": { regex: /&amp;#([0-9]{1,7});/g, val : (_, str) =&gt; String.fromCodePoint(Number.parseInt(str, 10)) },
"num_hex": { regex: /&amp;#x([0-9a-fA-F]{1,6});/g, val : (_, str) =&gt; String.fromCodePoint(Number.parseInt(str, 16)) },
```</p>
<p>The `String.fromCodePoint()` method throws a `RangeError` when the code point exceeds the valid Unicode range (0 to 0x10FFFF / 1114111). The regex patterns can capture values far exceeding this:
- `[0-9]{1,7}` matches up to 9,999,999
- `[0-9a-fA-F]{1,6}` matches up to 0xFFFFFF (16,777,215)</p>
<p>The entity replacement in `replaceEntitiesValue()` (line 452) has no try-catch:</p>
<p>```javascript
val = val.replace(entity.regex, entity.val);
```</p>
<p>This causes the RangeError to propagate uncaught, crashing the parser and any application using it.
### PoC
#### Setup</p>
<p>Create a directory with these files:</p>
<p>```
poc/
├── package.json
├── server.js
```</p>
<p>**package.json**
```json
{ "dependencies": { "fast-xml-parser": "^5.3.3" } }
```</p>
<p>**server.js**
```javascript
const http = require('http');
const { XMLParser } = require('fast-xml-parser');</p>
<p>const parser = new XMLPar…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-37qj-frw5-hhjh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11126-1</id>
    <title>openSUSE-SU-2026:11126-1 — velociraptor-0.7.0.4.git185.a5708584-2.1 on GA media</title>
    <updated>2026-10-03T15:55:18.283155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>velociraptor-0.7.0.4.git185.a5708584-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11126-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:26420</id>
    <title>RHSA-2026:26420 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.24 security, enhancement &amp; bug fix update</title>
    <updated>2026-10-03T15:55:18.283198+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: archive/tar: Unbounded allocation when parsing GNU sparse map golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:26420"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25128</id>
    <title>UBUNTU-CVE-2026-25128</title>
    <updated>2026-10-03T15:55:18.283226+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-webfont, Ubuntu:25.10: node-webfont, Ubuntu:26.04:LTS: node-webfont</p>
<p>fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points (e.g., `&amp;#9999999;` or `&amp;#xFFFFFF;`). This causes the parser to throw an uncaught exception, crashing any application that processes untrusted XML input. Version 5.3.4 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0526</id>
    <title>WID-SEC-W-2026-0526 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T15:55:18.283339+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Daten zu manipulieren, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0526"/>
  </entry>
</feed>
