<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:18:57.525347+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933</id>
    <title>certfr-2026-avi-0933 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T06:18:57.917911+00:00</updated>
    <content>certfr-2026-avi-0933</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-324481</id>
    <title>EUVD-2026-324481</title>
    <updated>2026-10-03T06:18:57.917988+00:00</updated>
    <content>EUVD-2026-324481</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-324481"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33245</id>
    <title>fkie_cve-2026-33245</title>
    <updated>2026-10-03T06:18:57.918005+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33245"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8646-j5j9-6r62</id>
    <title>GHSA-8646-j5j9-6r62 — React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets</title>
    <updated>2026-10-03T06:18:57.918040+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: react-router</p>
<p>When using React Router v7's unstable RSC APIs, there exists a potential client-side XSS issue in the RSC redirect handling if redirects are coming from untrusted sources</p>
<p>&gt; [!NOTE]
&gt; This only impacts your application if you are using the unstable RSC APIs in React Router.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8646-j5j9-6r62"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1</id>
    <title>openSUSE-SU-2026:11680-1 — agama-web-ui-24+0.a836cced5-52.1 on GA media</title>
    <updated>2026-10-03T06:18:57.918069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>agama-web-ui-24+0.a836cced5-52.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:34456</id>
    <title>RHSA-2026:34456 — Red Hat Security Advisory: RHOAI 3.4.2 - Red Hat OpenShift AI</title>
    <updated>2026-10-03T06:18:57.918096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mlflow: mlflow: Arbitrary file read via bypassed source path validation python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() starlette: Starlette: Security restriction bypass via malformed HTTP Host header</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:34456"/>
  </entry>
</feed>
