<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:03:55.716344+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352280</id>
    <title>EUVD-2026-352280</title>
    <updated>2026-10-03T19:03:55.795764+00:00</updated>
    <content>EUVD-2026-352280</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352280"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73648</id>
    <title>fkie_cve-2026-73648</title>
    <updated>2026-10-03T19:03:55.795816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default allowed tags that included SVG use or feImage elements could therefore permit external references; a same-origin external SVG referenced by use could execute scripts in the sanitized document's context, while feImage could load external images for tracking. Applications using the default allowed tags are not affected. This issue is fixed in version 1.7.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cj75-f6xr-r4g7</id>
    <title>GHSA-cj75-f6xr-r4g7 — Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations</title>
    <updated>2026-10-03T19:03:55.795868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: rails-html-sanitizer</p>
<p>## Summary</p>
<p>There is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG reference element such as `&lt;use&gt;`. See related [GHSA-9wjq-cp2p-hrgf](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf) in Loofah, whose SVG local-reference logic rails-html-sanitizer mirrors.</p>
<p>- Versions affected: `&gt;= 1.0.3, &lt; 1.7.1`
- Not affected: `&lt; 1.0.3`
- Fixed versions: `1.7.1`</p>
<p>## Impact</p>
<p>`Rails::HTML::PermitScrubber` restricts SVG reference elements in the `SVG_ALLOW_LOCAL_HREF` collection to local, same-document references, but that restriction covered only the `xlink:href` attribute. Browsers also accept a plain `href` attribute per the SVG 2 spec, and it was not restricted, so those elements could reference arbitrary external documents. SVG `&lt;use&gt;` can load and render external SVG content by reference, and if the referenced document is same-origin and contains scripts, it could execute in the context of the sanitized document. `&lt;feImage&gt;` can load external images, which can be used for tracking.</p>
<p>Applications are impacted only when the allowed tags are overridden to include one of these SVG reference elements, for example `&lt;use&gt;` or `&lt;feImage&gt;`. The default allowed tags do not include these SVG elements, so applications using the default configuration are not affected.</p>
<p>## Workarounds</p>
<p>Remove the SVG reference elements (such as `use` and `feImage`) from the overridden allowed tags. Applications us…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cj75-f6xr-r4g7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73648</id>
    <title>UBUNTU-CVE-2026-73648</title>
    <updated>2026-10-03T19:03:55.795943+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: ruby-rails-html-sanitizer, Ubuntu:18.04:LTS: ruby-rails-html-sanitizer, Ubuntu:20.04:LTS: ruby-rails-html-sanitizer, Ubuntu:22.04:LTS: ruby-rails-html-sanitizer, Ubuntu:24.04:LTS: ruby-rails-html-sanitizer, Ubuntu:26.04:LTS: ruby-rails-html-sanitizer</p>
<p>rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default allowed tags that included SVG use or feImage elements could therefore permit external references; a same-origin external SVG referenced by use could execute scripts in the sanitized document's context, while feImage could load external images for tracking. Applications using the default allowed tags are not affected. This issue is fixed in version 1.7.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73648"/>
  </entry>
</feed>
