<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:05:24.897894+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ag43501</id>
    <title>Withdrawn: CLEANSTART-2026-AG43501 — Security fixes in sqlpad 7.5.7-r2</title>
    <updated>2026-10-03T05:05:25.195657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: sqlpad</p>
<p>Package sqlpad version 7.5.7-r2 fixes 26 vulnerabilities: ghsa-2v35-w6hq-6mfw, ghsa-f6ww-3ggp-fr8h, ghsa-wh4c-j3r5-mjhp, ghsa-x6wf-f3px-wcqx, ghsa-j759-j44w-7fr8...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ag43501"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-361080</id>
    <title>EUVD-2026-361080</title>
    <updated>2026-10-03T05:05:25.195758+00:00</updated>
    <content>EUVD-2026-361080</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-361080"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41672</id>
    <title>fkie_cve-2026-41672</title>
    <updated>2026-10-03T05:05:25.195777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j759-j44w-7fr8</id>
    <title>GHSA-j759-j44w-7fr8 — xmldom has XML node injection through unvalidated comment serialization</title>
    <updated>2026-10-03T05:05:25.195806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @xmldom/xmldom, npm: xmldom</p>
<p>## Summary</p>
<p>The package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output.</p>
<p>---</p>
<p>## Details</p>
<p>The issue is in the DOM construction and serialization flow for comment nodes.</p>
<p>When `createComment(data)` is called, the supplied string is stored as comment data through the generic character-data handling path. That content is kept as-is. Later, when the document is serialized, the serializer writes comment nodes by concatenating the XML comment delimiters with the stored `node.data` value directly.</p>
<p>That behavior is unsafe because XML comments are a syntax-sensitive context. If attacker-controlled input contains a sequence that closes the comment, the serializer does not preserve it as literal comment text. Instead, it emits output where the remainder of the payload is treated as live XML markup.</p>
<p>This is a real injection bug, not a formatting issue. The serializer already applies context-aware handling in other places, such as escaping text nodes and rewriting unsafe CDATA terminators. Comment content does not receive equivalent treatment. Because of that gap, untrusted data can break out of the comment boundary and modify the structure of the final XML document.</p>
<p>---</p>
<p>## PoC</p>
<p>```js
const { DOMImplementation, DOMParser, XMLSerializer } = require('@xmldom/xmldom');</p>
<p>const doc = new DOMI…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j759-j44w-7fr8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-41672</id>
    <title>msrc_CVE-2026-41672 — xmldom: XML node injection through unvalidated comment serialization</title>
    <updated>2026-10-03T05:05:25.195885+00:00</updated>
    <content>msrc_CVE-2026-41672</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-41672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:26234</id>
    <title>RHSA-2026:26234 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.5 release.</title>
    <updated>2026-10-03T05:05:25.195905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri: fast-uri: URI authority bypass due to improper delimiter handling vm2: vm2: Arbitrary code execution via sandbox breakout through inspect function crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields xmldom: @xmldom/xmldom: xmldom: Arbitrary XML Node Injection @xmldom/xmldom: xmldom: xmldom: Denial of Service via deeply nested XML documents xmldom: xmldom: Arbitrary XML markup injection xmldom: xmldom: Arbitrary XML node injection via crafted processing instructions protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:26234"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41672</id>
    <title>UBUNTU-CVE-2026-41672</title>
    <updated>2026-10-03T05:05:25.195939+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:25.10: node-xmldom, Ubuntu:26.04:LTS: node-xmldom</p>
<p>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1833</id>
    <title>WID-SEC-W-2026-1833 — IBM App Connect Enterprise (basic-ftp, xmldom): Mehrere Schwachstellen</title>
    <updated>2026-10-03T05:05:25.195968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1833"/>
  </entry>
</feed>
