<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T04:43:10.892821+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319278</id>
    <title>EUVD-2026-319278</title>
    <updated>2026-10-04T04:43:10.955876+00:00</updated>
    <content>EUVD-2026-319278</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319278"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44665</id>
    <title>fkie_cve-2026-44665</title>
    <updated>2026-10-04T04:43:10.955921+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML. This vulnerability is fixed in 1.1.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44665"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5wm8-gmm8-39j9</id>
    <title>GHSA-5wm8-gmm8-39j9 — fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes</title>
    <updated>2026-10-04T04:43:10.955957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: fast-xml-builder</p>
<p># Summary
When an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML.</p>
<p>## Detail</p>
<p>Malicious Input
```
{
      a: {
        "@_attr": '" onClick="alert(1)'
      }
}
```</p>
<p>Output
```xml
&lt;a attr="" onClick="alert(1)"&gt;&lt;/a&gt;
```</p>
<p>### Workarounds
If you're not ignoring attributes then keep processEntities flag true.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5wm8-gmm8-39j9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:56928</id>
    <title>RHSA-2026:56928 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.2 security, enhancement &amp; bug fix update</title>
    <updated>2026-10-04T04:43:10.955992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri: fast-uri: URI authority bypass due to improper delimiter handling postcss-selector-parser: Postcss: Denial of Service via uncontrolled recursion in AST Serialization picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern react-router: React Router: Open redirect vulnerability via specially crafted URLs postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags fast-xml-parser: fast-xml-parser: XML injection via improper escaping of comment and CDATA sequences uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input fast-xml-builder: fast-xml-builder: Attribute injection leading to information disclosure or content manipulation brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:56928"/>
  </entry>
</feed>
