<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:38:45.213468+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</id>
    <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T12:38:45.253914+00:00</updated>
    <content>certfr-2026-avi-0667</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</id>
    <title>Withdrawn: CLEANSTART-2026-CE10526 — Security fixes for CVE-2025-64756, CVE-2025-69873, CVE-2026-1525, CVE-2026-1526, CVE-2026-1527, CVE-2026-1528, CVE-2026…</title>
    <updated>2026-10-02T12:38:45.253999+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: renovate</p>
<p>Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366079</id>
    <title>EUVD-2026-366079</title>
    <updated>2026-10-02T12:38:45.254073+00:00</updated>
    <content>EUVD-2026-366079</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25896</id>
    <title>fkie_cve-2026-25896</title>
    <updated>2026-10-02T12:38:45.254102+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&amp;lt;, &amp;gt;, &amp;amp;, &amp;quot;, &amp;apos;) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25896"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m7jm-9gc2-mpf2</id>
    <title>GHSA-m7jm-9gc2-mpf2 — fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names</title>
    <updated>2026-10-02T12:38:45.254153+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: fast-xml-parser</p>
<p># Entity encoding bypass via regex injection in DOCTYPE entity names</p>
<p>## Summary</p>
<p>A dot (`.`) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (`&amp;lt;`, `&amp;gt;`, `&amp;amp;`, `&amp;quot;`, `&amp;apos;`) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered.</p>
<p>## Details</p>
<p>The fix for CVE-2023-34104 addressed some regex metacharacters in entity names but missed `.` (period), which is valid in XML names per the W3C spec.</p>
<p>In `DocTypeReader.js`, entity names are passed directly to `RegExp()`:</p>
<p>```js
entities[entityName] = {
    regx: RegExp(`&amp;${entityName};`, "g"),
    val: val
};
```</p>
<p>An entity named `l.` produces the regex `/&amp;l.;/g` where `.` matches **any character**, including the `t` in `&amp;lt;`. Since DOCTYPE entities are replaced before built-in entities, this shadows `&amp;lt;` entirely.</p>
<p>The same issue exists in `OrderedObjParser.js:81` (`addExternalEntities`), and in the v6 codebase - `EntitiesParser.js` has a `validateEntityName` function with a character blacklist, but `.` is not included:</p>
<p>```js
// v6 EntitiesParser.js line 96
const specialChar = "!?\\/[]$%{}^&amp;*()&lt;&gt;|+";  // no dot
```</p>
<p>## Shadowing all 5 built-in entities</p>
<p>| Entity name | Regex created | Shadows |
|---|---|---|
| `l.` | `/&amp;l.;/g` | `&amp;lt;` |
| `g.` | `/&amp;g.;/g` | `&amp;gt;` |
| `am.` | `/&amp;am.;/g` | `&amp;amp;` |
| `quo.` | `/&amp;quo.;/g` | `&amp;quot;` |
| `apo.` | `/&amp;apo.;/g` | `&amp;apos;` |</p>
<p>## PoC</p>
<p>```js…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m7jm-9gc2-mpf2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:40984</id>
    <title>RHSA-2026:40984 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.20.15 security, enhancement &amp; bug fix update</title>
    <updated>2026-10-02T12:38:45.254273+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-forge: node-forge ASN.1 Unbounded Recursion webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior ajv: ReDoS via $data reference lodash: lodash: Arbitrary code execution via untrusted input in template imports @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: g…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:40984"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25896</id>
    <title>UBUNTU-CVE-2026-25896</title>
    <updated>2026-10-02T12:38:45.254389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: node-webfont, Ubuntu:25.10: node-webfont, Ubuntu:26.04:LTS: node-webfont</p>
<p>fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&amp;lt;, &amp;gt;, &amp;amp;, &amp;quot;, &amp;apos;) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25896"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0772</id>
    <title>WID-SEC-W-2026-0772 — IBM App Connect Enterprise (fast-xml-parser): Mehrere Schwachstellen</title>
    <updated>2026-10-02T12:38:45.254443+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen oder Sicherheitsmaßnahmen zu umgehen, wodurch Cross-Site-Scripting-Angriffe ermöglicht werden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0772"/>
  </entry>
</feed>
