<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:39:49.724086+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09337</id>
    <title>bdu:2026-09337</title>
    <updated>2026-10-02T19:39:49.874970+00:00</updated>
    <content>bdu:2026-09337</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0581</id>
    <title>certfr-2026-avi-0581 — De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de prov…</title>
    <updated>2026-10-02T19:39:49.875011+00:00</updated>
    <content>certfr-2026-avi-0581</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0581"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-qn62418</id>
    <title>Withdrawn: CLEANSTART-2026-QN62418 — Security fixes in opensearch-dashboards-fips 3.5.0-r0</title>
    <updated>2026-10-02T19:39:49.875031+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: opensearch-dashboards-fips</p>
<p>Package opensearch-dashboards-fips version 3.5.0-r0 fixes 30 vulnerabilities: ghsa-jg4p-7fhp-p32p, ghsa-2w6w-674q-4c4q, ghsa-9cx6-37pm-9jff, ghsa-r5fr-rjxr-66jc, ghsa-3v7f-55p6-f55p...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-qn62418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366767</id>
    <title>EUVD-2026-366767</title>
    <updated>2026-10-02T19:39:49.875063+00:00</updated>
    <content>EUVD-2026-366767</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366767"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33941</id>
    <title>fkie_cve-2026-33941</title>
    <updated>2026-10-02T19:39:49.875076+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser. Version 4.7.9 fixes the issue. Some workarounds are available. First, validate all CLI inputs before invoking the precompiler. Reject filenames and option values  that contain characters with JavaScript string-escaping significance (`"`, `'`, `;`, etc.). Second, use a fixed, trusted namespace string passed via a configuration file rather than  command-line arguments in automated pipelines. Third, run the precompiler in a sandboxed environment (container with no write access to sensitive  paths) to limit the impact of successful exploitation. Fourth, audit template filenames in any repository or package that is consumed by an automated  build pipeline.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33941"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xjpj-3mr7-gcpf</id>
    <title>GHSA-xjpj-3mr7-gcpf — Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options</title>
    <updated>2026-10-02T19:39:49.875111+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: handlebars</p>
<p>## Summary</p>
<p>The Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser.</p>
<p>## Description</p>
<p>`lib/precompiler.js` generates JavaScript source by string-interpolating several values directly into the output. Four distinct injection points exist:</p>
<p>### 1. Template name injection</p>
<p>```javascript
// Vulnerable code pattern
output += 'templates["' + template.name + '"] = template(...)';
```</p>
<p>`template.name` is derived from the file system path. A filename containing `"` or `'];` breaks out of the string literal and injects arbitrary JavaScript.</p>
<p>### 2. Namespace injection (`-n` / `--namespace`)</p>
<p>```javascript
// Vulnerable code pattern
output += 'var templates = ' + opts.namespace + ' = ' + opts.namespace + ' || {};';
```</p>
<p>`opts.namespace` is emitted as raw JavaScript. Anything after a `;` in the value becomes an additional JavaScript statement.</p>
<p>### 3. CommonJS path injection (`-c` / `--commonjs`)</p>
<p>```javascript
// Vulnerable code pattern
output += 'var Handlebars = require("' + opts.commonjs + '");';
```</p>
<p>`opts.commonjs` is interpolated inside double quotes with no escaping, allowing `"` to close the string and inject further code.</p>
<p>### 4. AM…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xjpj-3mr7-gcpf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-33941</id>
    <title>msrc_CVE-2026-33941 — Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options</title>
    <updated>2026-10-02T19:39:49.875165+00:00</updated>
    <content>msrc_CVE-2026-33941</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-33941"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10175</id>
    <title>RHSA-2026:10175 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.27.1 Release.</title>
    <updated>2026-10-02T19:39:49.875183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path net/url: Incorrect parsing of IPv6 host literals in net/url github.com/traefik/traefik: Traefik: Denial of Service due to incomplete TLS handshake crypto/x509: Incorrect enforcement of email constraints in crypto/x509 rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability github.com/traefik/traefik: Traefik: Information disclosure due to case-insensitive Connection header processing Traefik: github.com/traefik/traefik: Traefik: mTLS bypass allows unauthorized service access via fragmented ClientHello. github.com/traefik/traefik: Traefik: Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection @fastify/reply-from: @fastify/http-proxy: Fastify Reply From a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10175"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33941</id>
    <title>UBUNTU-CVE-2026-33941</title>
    <updated>2026-10-02T19:39:49.875273+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: node-handlebars, Ubuntu:20.04:LTS: node-handlebars, Ubuntu:22.04:LTS: node-handlebars, Ubuntu:24.04:LTS: node-handlebars, Ubuntu:25.10: node-handlebars, Ubuntu:26.04:LTS: node-handlebars</p>
<p>Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser. Version 4.7.9 fixes the issue. Some workarounds are available. First, validate all CLI inputs before invoking the precompiler. Reject filenames and option values  that contain characters with JavaScript string-escaping significance (`"`, `'`, `;`, etc.). Second, use a fixed, trusted namespace string passed via a configuration file rather than command-line arguments in automated pipelines. Third, run the precompiler in a sandboxed environment (container with no write access to sensitive paths) to limit the impact of successful exploitation. Fourth, audit template filenames in any repository or package that is consumed by an automated  build pipeline.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33941"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1434</id>
    <title>WID-SEC-W-2026-1434 — IBM App Connect Enterprise Certified Container: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:39:49.875312+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Programmcode auszuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Cross-Site-Scripting-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1434"/>
  </entry>
</feed>
