<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:53:46.665485+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</id>
    <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T19:53:46.670061+00:00</updated>
    <content>certfr-2026-avi-1165</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343773</id>
    <title>EUVD-2026-343773</title>
    <updated>2026-10-02T19:53:46.670099+00:00</updated>
    <content>EUVD-2026-343773</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343773"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-68945</id>
    <title>fkie_cve-2026-68945</title>
    <updated>2026-10-02T19:53:46.670114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-68945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jhpw-976m-542j</id>
    <title>GHSA-jhpw-976m-542j — Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning</title>
    <updated>2026-10-02T19:53:46.670143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @angular/common</p>
<p>Angular's `HttpTransferCache` caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during client-side hydration.</p>
<p>During SSR, `HttpTransferCache` previously generated identical key material for distinct request parameters when repeated values were present because repeated values were joined with commas:</p>
<p>```ts
new HttpParams().set('role', 'user,admin')
new HttpParams().append('role', 'user').append('role', 'admin')
```</p>
<p>Both requests previously serialized as `role=user,admin`, allowing distinct `HttpClient` requests to produce the same transfer-cache key material.</p>
<p>### Impact</p>
<p>In an SSR application, this cache-key ambiguity can make a later security-sensitive `HttpClient` request receive the response from an earlier semantically different request in the same render. For example, an attacker-influenced scalar-comma request can be cached and then replayed as the response for a trusted repeated-param authorization or data request to the same URL. As a result, Angular's server-rendered output can be based on the wrong backend response because the trusted request is not dispatched. This can lead to:</p>
<p>- **State Poisoning**: Using incorrect or attacker-influenced cached responses for subsequent application logic.
- **Cross-Request Response Reuse**: Reusing cached responses across requests with semantically different parameters.</p>
<p>### Patched Versions</p>
<p>- 22.0.2
- 21.2.19
- 20.3.27</p>
<p>### Workarounds</p>
<p>If you cannot upgrade immediately, configure your `…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jhpw-976m-542j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68945</id>
    <title>UBUNTU-CVE-2026-68945</title>
    <updated>2026-10-02T19:53:46.670190+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: angular.js, Ubuntu:Pro:18.04:LTS: angular.js, Ubuntu:Pro:20.04:LTS: angular.js, Ubuntu:22.04:LTS: angular.js, Ubuntu:24.04:LTS: angular.js, Ubuntu:26.04:LTS: angular.js</p>
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-68945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2632</id>
    <title>WID-SEC-W-2026-2632 — Angular: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:53:46.670217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Angular ausnutzen, um Dateien zu manipulieren und Cross-Site-Scripting-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2632"/>
  </entry>
</feed>
