<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:26:24.167440+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</id>
    <title>certfr-2026-avi-1256 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T23:26:24.174313+00:00</updated>
    <content>certfr-2026-avi-1256</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-355121</id>
    <title>EUVD-2026-355121</title>
    <updated>2026-10-03T23:26:24.174370+00:00</updated>
    <content>EUVD-2026-355121</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-355121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63670</id>
    <title>fkie_cve-2026-63670</title>
    <updated>2026-10-03T23:26:24.174395+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as text by htmlparser2 and the ontext handler emits that content without escaping, while a browser parses the following img onerror markup as active HTML. This issue is fixed in version 2.17.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63670"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jxwj-j7wr-gfrw</id>
    <title>GHSA-jxwj-j7wr-gfrw — ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `&lt;/textarea/&gt;` solidus close</title>
    <updated>2026-10-03T23:26:24.174442+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: sanitize-html</p>
<p>### Summary
A mutation-XSS / allowedTags bypass: when `textarea` (or `xmp`) is included in `allowedTags`, an input containing a literal `&lt;/textarea/&gt;` (a solidus right after the RCDATA end-tag name) lets non-allowed markup such as `&lt;img src=x onerror=…&gt;` pass through `sanitizeHtml()` **live and unescaped**, even though `img`/`onerror` are not in the allowlist. A spec-compliant browser executes the surviving handler — XSS. This is a literal-solidus variant that bypasses the two most recent fixes in this code area (CVE-2026-40186, CVE-2026-44990), both already applied in 2.17.5. The default configuration is not affected.</p>
<p>### Details
`sanitize-html` emits the text content of HTML raw-text elements (`textarea`, `xmp`) without escaping. Two things combine:
- **Parser differential:** on input, htmlparser2 does NOT recognize `&lt;/textarea/&gt;` (solidus after the RCDATA
  end-tag name) as a close tag; it emits `&lt;/textarea/&gt;&lt;img …&gt;` as a single raw-text node.
- **Unescaped passthrough:** the `ontext` handler (`index.js` ~575-583) appends `textarea`/`xmp` content with
`result += text` (no `escapeHtml`), assuming it is "already properly encoded" — true for entity-decoded
  content (what CVE-2026-40186 fixed) but false for this mis-tokenized literal close tag.
A spec browser treats `&lt;/textarea/&gt;` as a valid `textarea` close, so the following `&lt;img onerror&gt;` is parsed as a live element. The recent fixes addressed entity-encoding (CVE-2026-40186) and the `xmp` default (CVE-2026-44990); neith…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jxwj-j7wr-gfrw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</id>
    <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T23:26:24.174526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596"/>
  </entry>
</feed>
