<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T04:17:33.778940+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-239848</id>
    <title>EUVD-2026-239848</title>
    <updated>2026-10-06T04:17:33.826766+00:00</updated>
    <content>EUVD-2026-239848</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-239848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-4759</id>
    <title>fkie_cve-2025-4759</title>
    <updated>2026-10-06T04:17:33.826804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-4759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7cfr-5cjf-32p4</id>
    <title>GHSA-7cfr-5cjf-32p4 — lockfile-lint-api Vulnerable to Incorrect Behavior Order</title>
    <updated>2026-10-06T04:17:33.826836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: lockfile-lint-api</p>
<p>Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7cfr-5cjf-32p4"/>
  </entry>
</feed>
