<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T09:49:39.053218+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292775</id>
    <title>EUVD-2026-292775</title>
    <updated>2026-10-02T09:49:39.055855+00:00</updated>
    <content>EUVD-2026-292775</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40472</id>
    <title>fkie_cve-2026-40472</title>
    <updated>2026-10-02T09:49:39.055892+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In hackage-server, user-controlled metadata from .cabal files are rendered into HTML
href attributes without proper sanitization, enabling stored
Cross-Site Scripting (XSS) attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8fw8-47cx-j4q4</id>
    <title>GHSA-8fw8-47cx-j4q4</title>
    <updated>2026-10-02T09:49:39.055933+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In hackage-server, user-controlled metadata from .cabal files are rendered into HTML
href attributes without proper sanitization, enabling stored
Cross-Site Scripting (XSS) attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8fw8-47cx-j4q4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/hsec-2026-0004</id>
    <title>HSEC-2026-0004 — Hackage package metadata stored XSS vulnerability</title>
    <updated>2026-10-02T09:49:39.055960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Hackage: hackage-server</p>
<p># Hackage package metadata stored XSS vulnerability</p>
<p>User-controlled metadata from `.cabal` files are rendered into HTML
`href` attributes without proper sanitization, enabling stored
Cross-Site Scripting (XSS) attacks.  The specific fields affected
are:</p>
<p>- `homepage`
- `bug-reports`
- `source-repository.location`
- `description` (Haddock hyperlinks)</p>
<p>The Haskell Security Response Team audited the entire corpus of
**published** packages on `hackage.haskell.org`—all published
package versions but *not* candidates.  No exploitation attempts
were detected.</p>
<p>To fix the issue, *hackage-server* now inspects target URIs and only
produces a hyperlink when the URI has an approved scheme: `http`,
`https`, and (only for some fields) `mailto`.</p>
<p>The fix has been [committed][commit] and deployed on
`hackage.haskell.org`.  Other operations of *hackage-server*
instances should update as soon as possible to commit
`2de3ae45082f8f3f29a41f6aff620d09d0e74058` or later.</p>
<p>## Acknowledgements</p>
<p>- **Joshua Rogers** (https://joshua.hu/) of AISLE
  (https://aisle.com/) reported the issue to the Haskell Security
  Response Team.
- **Fraser Tweedale** implemented the fix.
- **Gershom Bazerman** merged the fix and deployed it to
  `hackage.haskell.org`.</p>
<p>[commit]: https://github.com/haskell/hackage-server/commit/2de3ae45082f8f3f29a41f6aff620d09d0e74058</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/hsec-2026-0004"/>
  </entry>
</feed>
