<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:22:38.869047+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049</id>
    <title>certfr-2026-avi-1049 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Certaines d'entre elles permettent à un attaquant de…</title>
    <updated>2026-10-03T11:22:38.984236+00:00</updated>
    <content>certfr-2026-avi-1049</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339840</id>
    <title>EUVD-2026-339840</title>
    <updated>2026-10-03T11:22:38.984280+00:00</updated>
    <content>EUVD-2026-339840</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339840"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-65901</id>
    <title>fkie_cve-2026-65901</title>
    <updated>2026-10-03T11:22:38.984295+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causing scripts to execute when the sanitized tree is inserted into a live document.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-65901"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x4vx-rjvf-j5p4</id>
    <title>GHSA-x4vx-rjvf-j5p4 — DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and…</title>
    <updated>2026-10-03T11:22:38.984326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: dompurify</p>
<p>## Summary</p>
<p>When `DOMPurify.sanitize(root, { IN_PLACE: true })` is called on an attacker-supplied live DOM node, `DOMPurify` still trusts `currentNode.nodeName` for non-`form` nodes in the main `_sanitizeElements` pipeline. A real `&lt;script&gt;` child node whose observable `nodeName` is attacker-controlled can therefore be misclassified as an allowed element and retained. When the sanitized tree is inserted into a live document, the script executes.</p>
<p>This affects current `3.4.6`. The recent `IN_PLACE` hardening work covers clobbered `form` handling and foreign-realm shadow/template traversal, but does not harden the main per-node element decision for hostile non-`form` live nodes.</p>
<p>## Affected</p>
<p>- DOMPurify `3.4.6`
- Any caller that does `DOMPurify.sanitize(node, { IN_PLACE: true })` on attacker-supplied live DOM nodes
- Verified attacker-controlled node sources:
  - same-origin `iframe` → live node passed by reference
  - same-origin `window.open()` popup → live node passed by reference
  - same-origin foreign node adopted into the host document via `document.adoptNode(node)` and then sanitized in-place</p>
<p>Not affected:</p>
<p>- String-input `DOMPurify.sanitize(dirtyString)`</p>
<p>## Vulnerability details</p>
<p>### Code paths</p>
<p>[A] — `_sanitizeElements` uses the instance-visible `nodeName` for the allow/forbid decision:</p>
<p>```ts
const _sanitizeElements = function (currentNode: any): boolean {
  ...
  if (_isClobbered(currentNode)) {
    _forceRemove(currentNode);
    return true;
  }</p>
<p>const tagNam…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x4vx-rjvf-j5p4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:58500</id>
    <title>RHSA-2026:58500 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T11:22:38.984402+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dompurify: DOMPurify: Cross-site scripting via permanent attribute allowlist pollution dompurify: DOMPurify: Client-side arbitrary code execution due to improper Trusted Types policy reset dompurify: DOMPurify: Cross-site scripting vulnerability via attacker-controlled nodeName dompurify: DOMPurify: Sanitization bypass via hook manipulation DOMPurify: DOMPurify: Cross-site scripting due to state leakage in sanitization. dompurify: DOMPurify: URI validation bypass leads to cross-site scripting dompurify: DOMPurify: Cross-Site Scripting (XSS) via prototype pollution in USE_PROFILES mode dompurify: DOMPurify: Cross-Site Scripting vulnerability allows arbitrary code execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:58500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-65901</id>
    <title>UBUNTU-CVE-2026-65901</title>
    <updated>2026-10-03T11:22:38.984434+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify, Ubuntu:26.04:LTS: node-dompurify</p>
<p>DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causing scripts to execute when the sanitized tree is inserted into a live document.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-65901"/>
  </entry>
</feed>
