<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:40:45.772732+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-8829</id>
    <title>BELL-CVE-2026-8829</title>
    <updated>2026-10-02T18:40:45.963966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: perl-html-parser, Alpaquita:25: perl-html-parser, Alpaquita:stream: perl-html-parser</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-8829"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-extract_url-cve-2026-8829</id>
    <title>BREW-extract_url-CVE-2026-8829 — HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities</title>
    <updated>2026-10-02T18:40:45.964015+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: extract_url</p>
<p>HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.</p>
<p>The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.</p>
<p>The read may disclose adjacent heap contents into the destination SV.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-extract_url-cve-2026-8829"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0737</id>
    <title>certfr-2026-avi-0737 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T18:40:45.964046+00:00</updated>
    <content>certfr-2026-avi-0737</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330909</id>
    <title>EUVD-2026-330909</title>
    <updated>2026-10-02T18:40:45.964064+00:00</updated>
    <content>EUVD-2026-330909</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330909"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8829</id>
    <title>fkie_cve-2026-8829</title>
    <updated>2026-10-02T18:40:45.964075+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.</p>
<p>The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.</p>
<p>The read may disclose adjacent heap contents into the destination SV.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-8829"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9p7j-9995-m88w</id>
    <title>GHSA-9p7j-9995-m88w</title>
    <updated>2026-10-02T18:40:45.964100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.</p>
<p>The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.</p>
<p>The read may disclose adjacent heap contents into the destination SV.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9p7j-9995-m88w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-8829</id>
    <title>msrc_CVE-2026-8829 — HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities</title>
    <updated>2026-10-02T18:40:45.964118+00:00</updated>
    <content>msrc_CVE-2026-8829</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-8829"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0321</id>
    <title>NCSC-2026-0321 — Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS</title>
    <updated>2026-10-02T18:40:45.964133+00:00</updated>
    <content>NCSC-2026-0321</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0321"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2672</id>
    <title>OESA-2026-2672 — perl-HTML-Parser security update</title>
    <updated>2026-10-02T18:40:45.964311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: perl-HTML-Parser, openEuler:24.03-LTS-SP3: perl-HTML-Parser, openEuler:20.03-LTS-SP4: perl-HTML-Parser, openEuler:22.03-LTS-SP4: perl-HTML-Parser</p>
<p>Objects of the HTML::Parser class will recognize markup and separate it from plain text (alias data content) in HTML documents. As different kinds of markup and text are recognized, the corresponding event handlers are invoked.

Security Fix(es):</p>
<p>HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.</p>
<p>The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV&amp;apos;s PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.</p>
<p>The read may disclose adjacent heap contents into the destination SV.(CVE-2026-8829)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10957-1</id>
    <title>openSUSE-SU-2026:10957-1 — perl-HTML-Parser-3.850.0-1.1 on GA media</title>
    <updated>2026-10-02T18:40:45.964346+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl-HTML-Parser-3.850.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10957-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22189-1</id>
    <title>SUSE-SU-2026:22189-1 — Security update for perl-HTML-Parser</title>
    <updated>2026-10-02T18:40:45.964363+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for perl-HTML-Parser</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22189-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8829</id>
    <title>UBUNTU-CVE-2026-8829</title>
    <updated>2026-10-02T18:40:45.964377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: libhtml-parser-perl, Ubuntu:16.04:LTS: libhtml-parser-perl, Ubuntu:18.04:LTS: libhtml-parser-perl, Ubuntu:20.04:LTS: libhtml-parser-perl, Ubuntu:22.04:LTS: libhtml-parser-perl, Ubuntu:24.04:LTS: libhtml-parser-perl, Ubuntu:25.10: libhtml-parser-perl, Ubuntu:26.04:LTS: libhtml-parser-perl</p>
<p>HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV's PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation. The read may disclose adjacent heap contents into the destination SV.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8829"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2858</id>
    <title>WID-SEC-W-2026-2858 — IBM AIX und VIOS: Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:40:45.964409+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM AIX und IBM VIOS ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2858"/>
  </entry>
</feed>
