<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T17:58:49.797107+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-382444</id>
    <title>EUVD-2026-382444</title>
    <updated>2026-10-06T17:58:49.849145+00:00</updated>
    <content>EUVD-2026-382444</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-382444"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-104871</id>
    <title>fkie_cve-2026-104871</title>
    <updated>2026-10-06T17:58:49.849186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Angular SSR is a server-rise rendering tool for Angular applications. Prior to versions 20.3.36, 21.2.23, and 22.1.7, the CommonEngine retrieveSSGPage prerendered-page retrieval logic in @angular/ssr/node, and in @angular/ssr for versions 17 through 18, accepts a relative request URL containing a backslash parent-traversal segment on Windows. The non-special resolve:// URL base preserves the backslash, path.join interprets it as a Windows separator, and the pagePath.startsWith(normalize(publicPath)) check incorrectly accepts a sibling output directory whose name shares the configured public-directory prefix. An unauthenticated requester can therefore retrieve a sibling prerendered HTML page when that page contains the Angular SSG marker. The issue is limited to Windows deployments that pass relative request URLs to CommonEngine.render, have a prefix-sharing sibling output directory, and contain qualifying prerendered Angular HTML; it does not provide arbitrary file read. This issue is fixed in versions 20.3.36, 21.2.23, and 22.1.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-104871"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7g7c-h8rr-7p6q</id>
    <title>GHSA-7g7c-h8rr-7p6q — Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows</title>
    <updated>2026-10-06T17:58:49.849223+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @angular/ssr</p>
<p>A Path Traversal vulnerability exists in the prerendered (SSG) page retrieval logic of `CommonEngine` in `@angular/ssr/node` (and `@angular/ssr` in earlier versions). When deployed on Windows, an attacker can craft a request path with backslash directory traversal sequences that causes `CommonEngine` to serve prerendered pages from sibling output directories.</p>
<p>The vulnerability occurs due to how relative URLs and Windows file paths are resolved and validated:</p>
<p>1. A request URL containing a backslash parent traversal segment (e.g., `/..\app-admin`) is passed to `CommonEngine.render({ url })`.
2. The engine parses the URL using `new URL(url, 'resolve://')`. Because `resolve://` is a non-special scheme under the WHATWG URL standard, backslashes are not normalized to forward slashes, leaving the `pathname` unnormalized as `/..\app-admin`.
3. The engine constructs the candidate file path using `join(publicPath, pathname, 'index.html')`. On Windows, `path.join` treats `\` as a path delimiter, resolving the parent segment (`..\`) out of `publicPath` (e.g., `dist\app`) into a sibling directory (e.g., `dist\app-admin\index.html`).
4. The containment check (`pagePath.startsWith(normalize(publicPath))`) performs a prefix match without a trailing path delimiter. Because the sibling folder name starts with the configured public folder name (e.g., `dist\app-admin` starts with `dist\app`), the check erroneously succeeds.
5. If the target file exists and contains the Angular SSG marker (`ng…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7g7c-h8rr-7p6q"/>
  </entry>
</feed>
