<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:05:55.181859+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14132</id>
    <title>bdu:2026-14132</title>
    <updated>2026-10-03T15:05:55.262304+00:00</updated>
    <content>bdu:2026-14132</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362483</id>
    <title>EUVD-2026-362483</title>
    <updated>2026-10-03T15:05:55.262342+00:00</updated>
    <content>EUVD-2026-362483</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83606</id>
    <title>fkie_cve-2026-83606</title>
    <updated>2026-10-03T15:05:55.262359+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction production in lib/grammar.js lets the greedy S+ separator and lazy Char*? data group repeatedly repartition a long whitespace tail when the required closing ?&gt; is absent. Both parsePI and parseProcessingInstruction apply the expression to the entire remaining source, causing quadratic backtracking during DOMParser.parseFromString() under default options and allowing a small unauthenticated XML input to stall the Node.js event loop. This issue is fixed in @xmldom/xmldom version 0.9.11.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-83606"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g53g-w8rj-fmg7</id>
    <title>GHSA-g53g-w8rj-fmg7 — xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions</title>
    <updated>2026-10-03T15:05:55.262393+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @xmldom/xmldom</p>
<p>## Summary</p>
<p>`@xmldom/xmldom`'s processing-instruction (PI) grammar regex exhibits quadratic-time backtracking
(ReDoS) when parsing an **unterminated** processing instruction. A single small XML document
containing `&lt;?` + a target + a long run of whitespace and no closing `?&gt;` forces the regular
expression engine into O(n²) work, stalling the Node.js event loop. The input is parsed with
`DOMParser.parseFromString` under **default options**, so it is reachable from unauthenticated,
network-delivered XML (SOAP/SAML, webhooks, uploads, XML APIs).</p>
<p>## Details</p>
<p>The PI production in `lib/grammar.js` compiles (flags `mu`) to:</p>
<p>```
^&lt;\?(NameChars)(?:[\x20\x09\x0D\x0A]+([Char]*?))?\?&gt;
                     ^^^ S+ greedy       ^^^ Char*? lazy
```</p>
<p>- `lib/grammar.js` line 261: https://github.com/xmldom/xmldom/blob/bb7a085dc5ba1eea3212388509b97bb4b4af32b9/lib/grammar.js#L261</p>
<p>In the optional tail `(?:S+(Char*?))?`, both the greedy separator `S+` and the lazy data `Char*?`
match XML whitespace. When the required trailing `?&gt;` is absent, the engine must ultimately fail —
but first it tries every partition of the whitespace run between `S+` and `Char*?`, which is O(n²)
in the length of the trailing whitespace.</p>
<p>The regex is executed against the **entire remaining source string** in two places in `lib/sax.js`,
so the whole whitespace tail is scanned:</p>
<p>- `parsePI` — https://github.com/xmldom/xmldom/blob/bb7a085dc5ba1eea3212388509b97bb4b4af32b9/lib/sax.js#L680-L691
- `parseProcessingInstruction…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g53g-w8rj-fmg7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83606</id>
    <title>UBUNTU-CVE-2026-83606</title>
    <updated>2026-10-03T15:05:55.262479+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom</p>
<p>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction production in lib/grammar.js lets the greedy S+ separator and lazy Char*? data group repeatedly repartition a long whitespace tail when the required closing ?&gt; is absent. Both parsePI and parseProcessingInstruction apply the expression to the entire remaining source, causing quadratic backtracking during DOMParser.parseFromString() under default options and allowing a small unauthenticated XML input to stall the Node.js event loop. This issue is fixed in @xmldom/xmldom version 0.9.11.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83606"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</id>
    <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T15:05:55.262532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596"/>
  </entry>
</feed>
