<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:47:44.498215+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-13725</id>
    <title>bdu:2026-13725</title>
    <updated>2026-10-03T12:47:44.622508+00:00</updated>
    <content>bdu:2026-13725</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-13725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362525</id>
    <title>EUVD-2026-362525</title>
    <updated>2026-10-03T12:47:44.622555+00:00</updated>
    <content>EUVD-2026-362525</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362525"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83616</id>
    <title>fkie_cve-2026-83616</title>
    <updated>2026-10-03T12:47:44.622570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createProcessingInstruction(target, data) in lib/dom.js accepts an unvalidated target, while the requireWellFormed: true serializer checks only for a colon and the reserved case-insensitive xml name on 0.9.x and performs no target check on 0.8.x. Because serialization emits &lt;?target data?&gt;, a target containing &gt;, ?, whitespace, or another invalid XML-name character can break the processing-instruction boundary and inject XML structure. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-83616"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c7q8-3ch8-vqpv</id>
    <title>GHSA-c7q8-3ch8-vqpv — xmldom: Processing Instruction Target Injection Bypasses requireWellFormed</title>
    <updated>2026-10-03T12:47:44.622614+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @xmldom/xmldom, npm: xmldom</p>
<p>## Summary</p>
<p>`Document.createProcessingInstruction()` in `@xmldom/xmldom` performs no validation on the `target` parameter. The `requireWellFormed: true` serializer option validates only for `:` in the target and a case-insensitive `xml` prefix, but does not check for `&gt;` characters. A `&gt;` in the target breaks the processing instruction boundary (`&lt;?...?&gt;`), allowing injection of arbitrary content into the serialized XML output.</p>
<p>## Details</p>
<p>`Document.createProcessingInstruction(target, data)` at `lib/dom.js` around line 2413 accepts any string as the `target` parameter and stores it on the PI node without validation.</p>
<p>During serialization, the `requireWellFormed` code path (around line 3286) performs two checks on PI targets:</p>
<p>1. Rejects targets containing `:` (namespace prefix check)
2. Rejects targets matching `xml` case-insensitively (reserved prefix)</p>
<p>However, it does NOT validate that the target conforms to the XML Name production, and critically does NOT check for `&gt;` characters. Since processing instructions are serialized as `&lt;?target data?&gt;`, a `&gt;` in the target prematurely closes the PI, causing the remaining content to be interpreted as document content by any downstream XML parser.</p>
<p>### Root Cause</p>
<p>1. `createProcessingInstruction()` performs no validation on `target`
2. The serializer's `requireWellFormed` check is incomplete -- it only checks for `:` and `xml`, missing characters that break PI syntax (`&gt;`, `?`, whitespace)
3. The serializer emits the target verb…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c7q8-3ch8-vqpv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-83616</id>
    <title>msrc_CVE-2026-83616 — xmldom: Processing Instruction Target Injection Bypasses requireWellFormed</title>
    <updated>2026-10-03T12:47:44.622809+00:00</updated>
    <content>msrc_CVE-2026-83616</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-83616"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:69248</id>
    <title>RHSA-2026:69248 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.9 release.</title>
    <updated>2026-10-03T12:47:44.622837+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici: undici: Denial of Service via unrequested WebSocket subprotocol encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification urllib: urllib: Credential leakage via cross-origin redirects net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages nanoid: nanoid: Denial of Service via negative size input in non-secure module functions axios: axios: Denial of Service via uncontrolled recursion in form data processing pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass nanoid: nanoid: Predictable ID generation due to integer overflow fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:69248"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83616</id>
    <title>UBUNTU-CVE-2026-83616</title>
    <updated>2026-10-03T12:47:44.622957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom</p>
<p>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createProcessingInstruction(target, data) in lib/dom.js accepts an unvalidated target, while the requireWellFormed: true serializer checks only for a colon and the reserved case-insensitive xml name on 0.9.x and performs no target check on 0.8.x. Because serialization emits &lt;?target data?&gt;, a target containing &gt;, ?, whitespace, or another invalid XML-name character can break the processing-instruction boundary and inject XML structure. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83616"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</id>
    <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:47:44.623012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596"/>
  </entry>
</feed>
