<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T11:31:01.002169+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-309185</id>
    <title>EUVD-2026-309185</title>
    <updated>2026-10-08T11:31:01.004468+00:00</updated>
    <content>EUVD-2026-309185</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-309185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41885</id>
    <title>fkie_cve-2026-41885</title>
    <updated>2026-10-08T11:31:01.004500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for Deno. Prior to version 9.0.2, i18next-locize-backend interpolates lng, ns, projectId, and version directly into the configured loadPath / privatePath / addPath / updatePath / getLanguagesPath URL templates with no path-component validation and no encoding. When an application exposes any of these values to user-controlled input (?lng= / ?ns= query parameters via i18next-browser-languagedetector, cookies, request headers, or a URL-derived projectId), a crafted value can change the structure of the outgoing request URL. Affected call sites in lib/index.js (pre-patch): the interpolate() helper is used at the five URL-build sites — _readAny/read (line 415 for private, 426 for public), getLanguages (lines 271 and 296), and writePage (lines 616 and 622) for the missing-key and update POST paths. The helper interpolate in lib/utils.js substitutes raw values with no encoding. This issue has been patched in version 9.0.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mgcp-mfp8-3q45</id>
    <title>GHSA-mgcp-mfp8-3q45 — i18next-locize-backend has URL Injection via Unsanitized Path Parameters</title>
    <updated>2026-10-08T11:31:01.004539+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: i18next-locize-backend</p>
<p>### Summary</p>
<p>Versions of `i18next-locize-backend` prior to 9.0.2 interpolate `lng`, `ns`, `projectId`, and `version` directly into the configured `loadPath` / `privatePath` / `addPath` / `updatePath` / `getLanguagesPath` URL templates with no path-component validation and no encoding. When an application exposes any of these values to user-controlled input (`?lng=` / `?ns=` query parameters via `i18next-browser-languagedetector`, cookies, request headers, or a URL-derived `projectId`), a crafted value can change the structure of the outgoing request URL.</p>
<p>Affected call sites in `lib/index.js` (pre-patch): the `interpolate()` helper is used at the five URL-build sites — `_readAny`/`read` (line 415 for private, 426 for public), `getLanguages` (lines 271 and 296), and `writePage` (lines 616 and 622) for the missing-key and update POST paths. The helper `interpolate` in `lib/utils.js` substitutes raw values with no encoding.</p>
<p>### Impact</p>
<p>An attacker who can influence `lng`, `ns`, `projectId`, or `version` can:</p>
<p>- **Path traversal** — `lng = '../../admin'` against `https://api.locize.app/{{projectId}}/{{version}}/{{lng}}/{{ns}}` changes the request URL path segment that reaches the locize CDN / API.
- **Query-string injection** — `lng = 'en?x=y'` appends an attacker-chosen query to the URL.
- **Fragment truncation** — `lng = 'en#x'` silently truncates the path in browser fetches.
- **URL-encoded bypass** — `lng = 'en%2F..'` leverages server-side decoding to reintroduce `/..`.</p>
<p>Th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mgcp-mfp8-3q45"/>
  </entry>
</feed>
