<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:35:59.869236+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049</id>
    <title>certfr-2026-avi-1049 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Certaines d'entre elles permettent à un attaquant de…</title>
    <updated>2026-10-03T11:35:59.960302+00:00</updated>
    <content>certfr-2026-avi-1049</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339839</id>
    <title>EUVD-2026-339839</title>
    <updated>2026-10-03T11:35:59.960344+00:00</updated>
    <content>EUVD-2026-339839</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339839"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-65913</id>
    <title>fkie_cve-2026-65913</title>
    <updated>2026-10-03T11:35:59.960360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-65913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cj63-jhhr-wcxv</id>
    <title>GHSA-cj63-jhhr-wcxv — DOMPurify USE_PROFILES prototype pollution allows event handlers</title>
    <updated>2026-10-03T11:35:59.960389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: dompurify</p>
<p>## Summary
When `USE_PROFILES` is enabled, DOMPurify rebuilds `ALLOWED_ATTR` as a plain array before populating it with the requested allowlists. Because the sanitizer still looks up attributes via `ALLOWED_ATTR[lcName]`, any `Array.prototype` property that is polluted also counts as an allowlisted attribute. An attacker who can set `Array.prototype.onclick = true` (or a runtime already subject to prototype pollution) can thus force DOMPurify to keep event handlers such as `onclick` even when they are normally forbidden. The provided PoC sanitizes `&lt;img onclick=...&gt;` with `USE_PROFILES` and adds the sanitized output to the DOM; the polluted prototype allows the event handler to survive and execute, turning what should be a blocklist into a silent XSS vector.</p>
<p>## Impact
Prototype pollution makes DOMPurify accept dangerous event handler attributes, which bypasses the sanitizer and results in DOM-based XSS once the sanitized markup is rendered.</p>
<p>## Credits
Identified by Cantina’s Apex (https://www.cantina.security).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cj63-jhhr-wcxv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:54517</id>
    <title>RHSA-2026:54517 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T11:35:59.960425+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling DOMPurify: DOMPurify: Cross-Site Scripting via unsanitized DOM elements from different realms DOMPurify: DOMPurify: Cross-site scripting due to state leakage in sanitization. dompurify: DOMPurify: URI validation bypass leads to cross-site scripting dompurify: DOMPurify: Cross-Site Scripting (XSS) via prototype pollution in USE_PROFILES mode dompurify: DOMPurify: Cross-Site Scripting vulnerability allows arbitrary code execution browserslist: Browserslist: Prototype pollution leading to denial of service browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:54517"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-65913</id>
    <title>UBUNTU-CVE-2026-65913</title>
    <updated>2026-10-03T11:35:59.960460+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify</p>
<p>DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype properties. Attackers can set Array.prototype properties like onclick to true, causing DOMPurify to accept event handlers as allowlisted attributes and resulting in DOM-based XSS when sanitized markup is rendered.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-65913"/>
  </entry>
</feed>
