<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:56:48.847804+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049</id>
    <title>certfr-2026-avi-1049 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Certaines d'entre elles permettent à un attaquant de…</title>
    <updated>2026-10-03T21:56:49.865047+00:00</updated>
    <content>certfr-2026-avi-1049</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339886</id>
    <title>EUVD-2026-339886</title>
    <updated>2026-10-03T21:56:49.865106+00:00</updated>
    <content>EUVD-2026-339886</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-65914</id>
    <title>fkie_cve-2026-65914</title>
    <updated>2026-10-03T21:56:49.865122+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-65914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h8r8-wccr-v5f2</id>
    <title>GHSA-h8r8-wccr-v5f2 — DOMPurify is vulnerable to mutation-XSS via Re-Contextualization</title>
    <updated>2026-10-03T21:56:49.865155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: dompurify</p>
<p>## Description</p>
<p>A mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using `innerHTML` and special wrappers. The vulnerable wrappers confirmed in browser behavior are `script`, `xmp`, `iframe`, `noembed`, `noframes`, and `noscript`. The payload remains seemingly benign after `DOMPurify.sanitize()`, but mutates during the second parse into executable markup with an event handler, enabling JavaScript execution in the client (`alert(1)` in the PoC).</p>
<p>## Vulnerability</p>
<p>The root cause is context switching after sanitization: sanitized output is treated as trusted and concatenated into a wrapper string (for example, `&lt;xmp&gt; ... &lt;/xmp&gt;` or other special wrappers) before being reparsed by the browser. In this flow, attacker-controlled text inside an attribute (for example `&lt;/xmp&gt;` or equivalent closing sequences for each wrapper) closes the special parsing context early and reintroduces attacker markup (`&lt;img ... onerror=...&gt;`) outside the original attribute context. DOMPurify sanitizes the original parse tree, but the application performs a second parse in a different context, reactivating dangerous tokens (classic mXSS pattern).</p>
<p>## PoC</p>
<p>1. Start the PoC app:
```bash
npm install
npm start
```</p>
<p>2. Open `http://localhost:3001`.
3. Set `Wrapper en sink` to `xmp`.
4. Use payload:
```html
 &lt;img src=x alt="&lt;/xmp&gt;&lt;img src=x onerror=alert('expoc')&gt;"&gt;
```</p>
<p>5. Click `Sanitize + Render`.
6. Observe:
- `Sanitized response` still contains t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h8r8-wccr-v5f2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0315</id>
    <title>NCSC-2026-0315 — Kwetsbaarheden verholpen in Oracle MySQL</title>
    <updated>2026-10-03T21:56:49.865236+00:00</updated>
    <content>NCSC-2026-0315</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0315"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:54517</id>
    <title>RHSA-2026:54517 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T21:56:49.865267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling DOMPurify: DOMPurify: Cross-Site Scripting via unsanitized DOM elements from different realms DOMPurify: DOMPurify: Cross-site scripting due to state leakage in sanitization. dompurify: DOMPurify: URI validation bypass leads to cross-site scripting dompurify: DOMPurify: Cross-Site Scripting (XSS) via prototype pollution in USE_PROFILES mode dompurify: DOMPurify: Cross-Site Scripting vulnerability allows arbitrary code execution browserslist: Browserslist: Prototype pollution leading to denial of service browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:54517"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-65914</id>
    <title>UBUNTU-CVE-2026-65914</title>
    <updated>2026-10-03T21:56:49.865300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify</p>
<p>DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-65914"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2903</id>
    <title>WID-SEC-W-2026-2903 — Oracle MySQL: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:56:49.865323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2903"/>
  </entry>
</feed>
