<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:50:46.164578+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ul03599</id>
    <title>CLEANSTART-2026-UL03599 — Caddy is an extensible server platform that uses TLS by default</title>
    <updated>2026-10-02T15:50:46.167746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: caddy</p>
<p>Security vulnerability affects the caddy package. Caddy is an extensible server platform that uses TLS by default.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ul03599"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330141</id>
    <title>EUVD-2026-330141</title>
    <updated>2026-10-02T15:50:46.167794+00:00</updated>
    <content>EUVD-2026-330141</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330141"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52846</id>
    <title>fkie_cve-2026-52846</title>
    <updated>2026-10-02T15:50:46.167811+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as &lt;&lt;&gt;img src=x onerror=alert()&gt;, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely. This vulnerability is fixed in 2.11.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-52846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vcc4-2c75-vc9v</id>
    <title>GHSA-vcc4-2c75-vc9v — Caddy: stripHTML template function bypass</title>
    <updated>2026-10-02T15:50:46.167839+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/caddyserver/caddy/v2, Go: github.com/caddyserver/caddy</p>
<p>### Summary
Caddy’s `stripHTML` template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as `&lt;&lt;&gt;img src=x onerror=alert()&gt;`, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely.</p>
<p>---</p>
<p>### Details
The vulnerability originates from `funcStripHTML` in:</p>
<p>[caddy/caddy/caddyhttp/templates/tplcontext.go](https://github.com/caddyserver/caddy/blob/77e9ce7404c4a76853e101a9f5687a929ee56654/modules/caddyhttp/templates/tplcontext.go)</p>
<p>```go
func (TemplateContext) funcStripHTML(s string) string {
    var buf bytes.Buffer
    var inTag, inQuotes bool
    var tagStart int
    for i, ch := range s {
        if inTag {
            if ch == '&gt;' &amp;&amp; !inQuotes {
                inTag = false
            } else if ch == '&lt;' &amp;&amp; !inQuotes {
                // false start
                buf.WriteString(s[tagStart:i])
                tagStart = i
            } else if ch == '"' {
                inQuotes = !inQuotes
            }
            continue
        }
        if ch == '&lt;' {
            inTag = true
            tagStart = i
            continue
        }
        buf.WriteRune(ch)
    }
    if inTag {
        // false start
        buf.WriteString(s[tagStart:])
    }
    return buf.String()
}
```</p>
<p>### POC</p>
<p>Caddyfile setup</p>
<p>```
:8080 {
    root * ./site
    file_server
    templates
}
```</p>
<p>Templa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vcc4-2c75-vc9v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52846</id>
    <title>UBUNTU-CVE-2026-52846</title>
    <updated>2026-10-02T15:50:46.167893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:24.04:LTS: caddy, Ubuntu:25.10: caddy, Ubuntu:Pro:26.04:LTS: caddy</p>
<p>Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as &lt;&lt;&gt;img src=x onerror=alert()&gt;, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely. This vulnerability is fixed in 2.11.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52846"/>
  </entry>
</feed>
