<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:58:21.225834+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-376432</id>
    <title>EUVD-2026-376432</title>
    <updated>2026-10-02T19:58:21.230065+00:00</updated>
    <content>EUVD-2026-376432</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-376432"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-96889</id>
    <title>fkie_cve-2026-96889</title>
    <updated>2026-10-02T19:58:21.230105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-96889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-96889</id>
    <title>msrc_CVE-2026-96889 — Librsvg: use-after-free when xml includes have duplicated entities</title>
    <updated>2026-10-02T19:58:21.230160+00:00</updated>
    <content>msrc_CVE-2026-96889</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-96889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2026-0305</id>
    <title>RUSTSEC-2026-0305 — Use-after-free when XML includes have duplicated entities</title>
    <updated>2026-10-02T19:58:21.230188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: librsvg</p>
<p>Librsvg uses libxml2, a C library, to parse XML.  When librsvg parses
an SVG document which has a nested Xinclude, an XML entity declaration
with a duplicate name as an existing one can cause a use-after-free error.</p>
<p>While libxml2 is expanding an internal entity, a recursive XInclude
can parse another document that declares an entity with the same
name. Both parses use the same `XmlState` entity
map on the librsvg side. `entity_insert()` replaces the first entry, whose `Drop`
implementation calls `xmlFreeNode()`. The outer `xmlCtxtParseEntity()`
then keeps using the freed 144-byte `xmlEntity`.</p>
<p>The included parse should not free an entity that the outer parser is still using.</p>
<p>The fix is in commit 8a1b0cd319e9af2d1e9cf878081dd77f227a0504, where
librsvg will no longer free xmlEntity pointers that libxml2 is still
using.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2026-0305"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-96889</id>
    <title>UBUNTU-CVE-2026-96889</title>
    <updated>2026-10-02T19:58:21.230243+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: librsvg, Ubuntu:18.04:LTS: librsvg, Ubuntu:20.04:LTS: librsvg, Ubuntu:22.04:LTS: librsvg, Ubuntu:24.04:LTS: librsvg, Ubuntu:26.04:LTS: librsvg</p>
<p>A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-96889"/>
  </entry>
</feed>
