<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:38:03.574904+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-91765</id>
    <title>BELL-CVE-2026-91765</title>
    <updated>2026-10-02T22:38:03.773841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: php83, Alpaquita:stream: php83</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-91765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-libphp-2026-91765</id>
    <title>BIT-libphp-2026-91765 — SOAP: Unbounded Recursion in Server-Side cleanup_xml_node</title>
    <updated>2026-10-02T22:38:03.773894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: libphp</p>
<p>cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-libphp-2026-91765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1227</id>
    <title>certfr-2026-avi-1227 — De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-02T22:38:03.773923+00:00</updated>
    <content>certfr-2026-avi-1227</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1227"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-377582</id>
    <title>EUVD-2026-377582</title>
    <updated>2026-10-02T22:38:03.773943+00:00</updated>
    <content>EUVD-2026-377582</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-377582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-91765</id>
    <title>fkie_cve-2026-91765</title>
    <updated>2026-10-02T22:38:03.773956+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-91765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-91765</id>
    <title>msrc_CVE-2026-91765 — SOAP: Unbounded Recursion in Server-Side cleanup_xml_node</title>
    <updated>2026-10-02T22:38:03.773978+00:00</updated>
    <content>msrc_CVE-2026-91765</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-91765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11901-1</id>
    <title>openSUSE-SU-2026:11901-1 — php8-8.5.11-1.1 on GA media</title>
    <updated>2026-10-02T22:38:03.773996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>php8-8.5.11-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11901-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:70720</id>
    <title>RHSA-2026:70720 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T22:38:03.774019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>php: php: Denial of Service via out-of-bounds read in mysqlnd wire protocol parser php: PHP: Denial of Service via heap buffer overflow in SOAP client php: PHP: Archive entry injection via integer overflow in TAR parser php: PHP: Denial of Service via reserved device names on Windows php: php: Denial of Service via unbounded recursion in SOAP parser php: php: Credential disclosure via cross-origin HTTP redirects php: php: Information disclosure via crafted TLS server certificate php: php: Access control bypass via partial IPv6 address comparison php: php: Server impersonation via Common Name fallback in TLS verification php: php: Information disclosure via out-of-bounds read in stream filters php: php: Out-of-bounds read via empty HTTP redirect Location header</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:70720"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-91765</id>
    <title>UBUNTU-CVE-2026-91765</title>
    <updated>2026-10-02T22:38:03.774052+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: php5, Ubuntu:Pro:16.04:LTS: php7.0, Ubuntu:Pro:18.04:LTS: php7.2, Ubuntu:Pro:20.04:LTS: php7.4, Ubuntu:22.04:LTS: php8.1, Ubuntu:24.04:LTS: php8.3, Ubuntu:26.04:LTS: php8.5</p>
<p>cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exists in the SOAP value decoder and in the WSDL node search helper.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-91765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3585</id>
    <title>WID-SEC-W-2026-3585 — PHP: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:38:03.774084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in PHP ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen oder die Integrität zu verletzen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3585"/>
  </entry>
</feed>
