<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T21:43:41.736224+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02116</id>
    <title>bdu:2024-02116</title>
    <updated>2026-10-08T21:43:41.824972+00:00</updated>
    <content>bdu:2024-02116</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02116"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-158388</id>
    <title>EUVD-2026-158388</title>
    <updated>2026-10-08T21:43:41.825074+00:00</updated>
    <content>EUVD-2026-158388</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-158388"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-27307</id>
    <title>fkie_cve-2024-27307</title>
    <updated>2026-10-08T21:43:41.825089+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions. This issue has been fixed in JSONata versions 1.8.7 and 2.0.4. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. As a workaround, one may apply the patch manually.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-27307"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fqg8-vfv7-8fj8</id>
    <title>GHSA-fqg8-vfv7-8fj8 — JSONata expression can pollute the "Object" prototype</title>
    <updated>2026-10-08T21:43:41.825123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: jsonata</p>
<p>### Impact</p>
<p>In JSONata versions `&gt;= 1.4.0, &lt; 1.8.7` and `&gt;= 2.0.0, &lt; 2.0.4`, a malicious expression can use the [transform operator](https://docs.jsonata.org/other-operators#-------transform) to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions.</p>
<p>### Patch</p>
<p>This issue has been fixed in JSONata versions `&gt;= 1.8.7` and `&gt;= 2.0.4`. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. The following patch can be applied if updating is not possible.</p>
<p>```patch
--- a/src/jsonata.js
+++ b/src/jsonata.js
@@ -1293,6 +1293,13 @@ var jsonata = (function() {
                 }
                 for(var ii = 0; ii &lt; matches.length; ii++) {
                     var match = matches[ii];
+                    if (match &amp;&amp; (match.isPrototypeOf(result) || match instanceof Object.constructor)) {
+                        throw {
+                            code: "D1010",
+                            stack: (new Error()).stack,
+                            position: expr.position
+                        };
+                    }
                     // evaluate the update value for each match
                     var update = await evaluate(expr.update, match, environment);
                     // update must be an object
@@ -1539,7 +1546,7 @@ var jsonata = (function() {
                 if (t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fqg8-vfv7-8fj8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-27307</id>
    <title>gsd-2024-27307</title>
    <updated>2026-10-08T21:43:41.825175+00:00</updated>
    <content>gsd-2024-27307</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-27307"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhea-2024:4071</id>
    <title>RHEA-2024:4071 — Red Hat Enhancement Advisory: Red Hat Developer Hub 1.2 release</title>
    <updated>2026-10-08T21:43:41.825188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools jsonata: malicious expression can pollute the "Object" prototype jinja2: accepts keys containing non-attribute characters requests: subsequent requests to the same host ignore cert verification</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhea-2024:4071"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0767</id>
    <title>WID-SEC-W-2024-0767 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-08T21:43:41.825212+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0767"/>
  </entry>
</feed>
