<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:23:19.326497+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-13732</id>
    <title>bdu:2026-13732</title>
    <updated>2026-10-03T16:23:19.402673+00:00</updated>
    <content>bdu:2026-13732</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-13732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362540</id>
    <title>EUVD-2026-362540</title>
    <updated>2026-10-03T16:23:19.402710+00:00</updated>
    <content>EUVD-2026-362540</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83612</id>
    <title>fkie_cve-2026-83612</title>
    <updated>2026-10-03T16:23:19.402725+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.1 until 0.9.12, HTML-mode parsing through DOMParser.parseFromString() mishandles a mixed-case closing tag for the script, style, textarea, or title raw-text elements. parseHtmlSpecialContent, selected by isHTMLRawTextElement or isHTMLEscapableRawTextElement, uses a case-sensitive indexOf() and then calls substring() with a missing-close result of negative one, causing unstable parser progression and quadratic output amplification. A small untrusted text/html document can consequently consume disproportionate CPU and memory when parsed and serialized. This issue is fixed in @xmldom/xmldom version 0.9.12.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-83612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6mj3-qw4j-hgrw</id>
    <title>GHSA-6mj3-qw4j-hgrw — xmldom: HTML raw-text closing-tag case mismatch causes output amplification</title>
    <updated>2026-10-03T16:23:19.402759+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @xmldom/xmldom</p>
<p>## Summary</p>
<p>In HTML mode (`text/html`), a raw-text element (`script`, `style`, `textarea`, `title`) whose closing
tag differs in case from its opening tag (e.g. `&lt;/ScRiPt&gt;` for `&lt;script&gt;`) is mishandled by the
parser, producing quadratic (O(n²)) output growth — a small crafted document parses and serializes
into output orders of magnitude larger, exhausting CPU and memory. A modest input of tens of KB can
therefore cause a denial of service in any service that parses untrusted HTML with xmldom. Only HTML
mode is affected.</p>
<p>## Details</p>
<p>The parser calls `parseHtmlSpecialContent` for each raw-text element in HTML mode, matched via
`isHTMLRawTextElement` / `isHTMLEscapableRawTextElement` (so all four types — `script`, `style`,
`textarea`, `title` — are in scope). It searches for the element's closing tag with
`source.indexOf('&lt;/' + tagName + '&gt;', elStartEnd)`, a byte-for-byte case-sensitive match. A
mixed-case closing tag never matches, so the search returns `-1`, and the following
`source.substring(elStartEnd + 1, -1)` extracts text backwards from the start of the document
instead of the element's content. The function then returns `-1` to the parse loop, which cannot
advance normally and falls back to character-by-character reprocessing. Every raw-text element
re-captures all source text preceding it, so output grows as O(n²) in the number of such elements.</p>
<p>### Root Cause</p>
<p>1. **Case-sensitive close-tag search** (`lib/sax.js:549`): `source.indexOf('&lt;/' + tagName + '&gt;',
   elSt…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6mj3-qw4j-hgrw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83612</id>
    <title>UBUNTU-CVE-2026-83612</title>
    <updated>2026-10-03T16:23:19.402820+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom</p>
<p>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.1 until 0.9.12, HTML-mode parsing through DOMParser.parseFromString() mishandles a mixed-case closing tag for the script, style, textarea, or title raw-text elements. parseHtmlSpecialContent, selected by isHTMLRawTextElement or isHTMLEscapableRawTextElement, uses a case-sensitive indexOf() and then calls substring() with a missing-close result of negative one, causing unstable parser progression and quadratic output amplification. A small untrusted text/html document can consequently consume disproportionate CPU and memory when parsed and serialized. This issue is fixed in @xmldom/xmldom version 0.9.12.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</id>
    <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T16:23:19.402849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596"/>
  </entry>
</feed>
