<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:14:47.709686+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</id>
    <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T21:14:47.821626+00:00</updated>
    <content>certfr-2026-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-gj99967</id>
    <title>Withdrawn: CLEANSTART-2026-GJ99967 — Security fixes in npm 11.14.0-r3</title>
    <updated>2026-10-02T21:14:47.821675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: npm</p>
<p>Package npm version 11.14.0-r3 fixes 2 vulnerabilities: CVE-2026-53655, CVE-2026-9358</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-gj99967"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-327219</id>
    <title>EUVD-2026-327219</title>
    <updated>2026-10-02T21:14:47.821706+00:00</updated>
    <content>EUVD-2026-327219</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-327219"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9358</id>
    <title>fkie_cve-2026-9358</title>
    <updated>2026-10-02T21:14:47.821720+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 6.1.3 and 7.1.3 is able to address this issue. This patch is called 5bc698cef66f8abd12610dc623e5d67cbc0f869d. It is suggested to upgrade the affected component. The vendor explains, that according to his definition "DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS)." The commits were backported to 6.x branch, which was the most downloaded version.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-9358"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w9m9-85wc-3x92</id>
    <title>GHSA-w9m9-85wc-3x92 — postcss-selector-parser allows denial of service through uncontrolled AST recursion</title>
    <updated>2026-10-02T21:14:47.821746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: postcss-selector-parser</p>
<p>A vulnerability was determined in postcss-selector-parser before 6.1.3 and 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains, that according to his definition "DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS)."</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w9m9-85wc-3x92"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:22934</id>
    <title>RHSA-2026:22934 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T21:14:47.821771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing postcss-selector-parser: Postcss: Denial of Service via uncontrolled recursion in AST Serialization undici: undici WebSocket client vulnerable to denial of service via cumulative fragment bypass undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy urllib3: urllib3: Denial of Service due to excessive HTTP response decompression brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:22934"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9358</id>
    <title>UBUNTU-CVE-2026-9358</title>
    <updated>2026-10-02T21:14:47.821797+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-css-loader, Ubuntu:22.04:LTS: node-css-loader, Ubuntu:24.04:LTS: node-css-loader, Ubuntu:25.10: node-css-loader, Ubuntu:26.04:LTS: node-css-loader</p>
<p>A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 6.1.3 and 7.1.3 is able to address this issue. This patch is called 5bc698cef66f8abd12610dc623e5d67cbc0f869d. It is suggested to upgrade the affected component. The vendor explains, that according to his definition "DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS)." The commits were backported to 6.x branch, which was the most downloaded version.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9358"/>
  </entry>
</feed>
