<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:29:29.438300+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-363539</id>
    <title>EUVD-2026-363539</title>
    <updated>2026-10-02T14:29:29.554804+00:00</updated>
    <content>EUVD-2026-363539</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-363539"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83610</id>
    <title>fkie_cve-2026-83610</title>
    <updated>2026-10-02T14:29:29.554840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &amp;name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-83610"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6gmq-8vp8-gcm6</id>
    <title>GHSA-6gmq-8vp8-gcm6 — xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization</title>
    <updated>2026-10-02T14:29:29.554879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @xmldom/xmldom, npm: xmldom</p>
<p>## Summary</p>
<p>An `EntityReference` node can be created with an invalid, attacker-controlled name through `Document.createEntityReference(name)`. When this node is serialized directly with:</p>
<p>```js
serializer.serializeToString(ref, { requireWellFormed: true })
```</p>
<p>the invalid `nodeName` is emitted into the serialized XML fragment without validation or escaping.</p>
<p>This can produce real XML markup in the serialized output. In the proof of concept below, the serialized fragment contains `&lt;injected/&gt;`, and reparsing the fragment creates a real `injected` element.</p>
<p>---</p>
<p>## Details</p>
<p>The issue appears to be in the serialization path for `ENTITY_REFERENCE_NODE`.</p>
<p>For several other node types, `requireWellFormed: true` performs specific validation checks before serialization. For example, comments, processing instructions, document types, and some character data cases are checked before being emitted.</p>
<p>However, for `ENTITY_REFERENCE_NODE`, the serializer appears to emit the node name directly in entity reference form:</p>
<p>```js
case ENTITY_REFERENCE_NODE:
  buf.push('&amp;', n.nodeName, ';');
  return null;
```</p>
<p>As a result, if `nodeName` contains characters that break out of the intended `&amp;name;` structure, the serializer can emit additional XML markup.</p>
<p>For example, an entity reference created with the name:</p>
<p>```text
safe; &lt;injected/&gt; &amp;x
```</p>
<p>is serialized as:</p>
<p>```xml
&amp;safe; &lt;injected/&gt; &amp;x;
```</p>
<p>When this fragment is later parsed in an XML context, `&lt;injected/&gt;` becomes a real element.</p>
<p>This…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6gmq-8vp8-gcm6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-83610</id>
    <title>msrc_CVE-2026-83610 — xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization</title>
    <updated>2026-10-02T14:29:29.554961+00:00</updated>
    <content>msrc_CVE-2026-83610</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-83610"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83610</id>
    <title>UBUNTU-CVE-2026-83610</title>
    <updated>2026-10-02T14:29:29.554980+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom</p>
<p>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &amp;name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83610"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</id>
    <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:29:29.555015+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596"/>
  </entry>
</feed>
