<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:59:42.620396+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:10710</id>
    <title>ALSA-2026:10710 — Important: pcs security update</title>
    <updated>2026-10-02T10:59:43.739340+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: pcs, AlmaLinux:9: pcs-snmp</p>
<p>The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.</p>
<p>Security Fix(es):</p>
<p>* lodash: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:10710"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09406</id>
    <title>bdu:2026-09406</title>
    <updated>2026-10-02T10:59:43.739436+00:00</updated>
    <content>bdu:2026-09406</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09406"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</id>
    <title>certfr-2026-avi-0500 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
    <updated>2026-10-02T10:59:43.739456+00:00</updated>
    <content>certfr-2026-avi-0500</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</id>
    <title>Withdrawn: CLEANSTART-2026-AD27625 — Security fixes for CVE-2022-25881, CVE-2022-33987, CVE-2025-25285, CVE-2025-62718, CVE-2025-69873, CVE-2026-21637, CVE-…</title>
    <updated>2026-10-02T10:59:43.739473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: mongosh</p>
<p>Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/esea-2026:0136</id>
    <title>ESEA-2026:0136 — Important: cockpit-image-builder security update</title>
    <updated>2026-10-02T10:59:43.739499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: cockpit-image-builder security update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/esea-2026:0136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-367741</id>
    <title>EUVD-2026-367741</title>
    <updated>2026-10-02T10:59:43.739519+00:00</updated>
    <content>EUVD-2026-367741</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-367741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4800</id>
    <title>fkie_cve-2026-4800</title>
    <updated>2026-10-02T10:59:43.739531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Impact:</p>
<p>The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.</p>
<p>When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.</p>
<p>Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().</p>
<p>Patches:</p>
<p>Users should upgrade to version 4.18.0.</p>
<p>Workarounds:</p>
<p>Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-4800"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r5fr-rjxr-66jc</id>
    <title>GHSA-r5fr-rjxr-66jc — lodash vulnerable to Code Injection via `_.template` imports key names</title>
    <updated>2026-10-02T10:59:43.739562+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: lodash, npm: lodash-es, npm: lodash-amd, npm: lodash.template</p>
<p>### Impact</p>
<p>The fix for [CVE-2021-23337](https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the `variable` option in `_.template` but did not apply the same validation to `options.imports` key names. Both paths flow into the same `Function()` constructor sink.</p>
<p>When an application passes untrusted input as `options.imports` key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.</p>
<p>Additionally, `_.template` uses `assignInWith` to merge imports, which enumerates inherited properties via `for..in`. If `Object.prototype` has been polluted by any other vector, the polluted keys are copied into the imports object and passed to `Function()`.</p>
<p>### Patches</p>
<p>Users should upgrade to version 4.18.0.</p>
<p>The fix applies two changes:
1. Validate `importsKeys` against the existing `reForbiddenIdentifierChars` regex (same check already used for the `variable` option)
2. Replace `assignInWith` with `assignWith` when merging imports, so only own properties are enumerated</p>
<p>### Workarounds</p>
<p>Do not pass untrusted input as key names in `options.imports`. Only use developer-controlled, static key names.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r5fr-rjxr-66jc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0256</id>
    <title>NCSC-2026-0256 — Kwetsbaarheden verholpen in Oracle Communications</title>
    <updated>2026-10-02T10:59:43.739597+00:00</updated>
    <content>NCSC-2026-0256</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2026:21387</id>
    <title>RHBA-2026:21387 — Red Hat Bug Fix Advisory: cockpit bug fix and enhancement update</title>
    <updated>2026-10-02T10:59:43.739627+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>lodash: lodash: Arbitrary code execution via untrusted input in template imports</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2026:21387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:24331</id>
    <title>RLSA-2026:24331 — Important: cockpit-image-builder security update</title>
    <updated>2026-10-02T10:59:43.739645+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: cockpit-image-builder</p>
<p>The image-builder-frontend generates custom images suitable for deploying systems or uploading to the cloud. It integrates into Cockpit as a frontend for osbuild.</p>
<p>Security Fix(es):</p>
<p>* lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)</p>
<p>* lodash: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:24331"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4800</id>
    <title>UBUNTU-CVE-2026-4800</title>
    <updated>2026-10-02T10:59:43.739668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: node-lodash, Ubuntu:Pro:18.04:LTS: node-lodash, Ubuntu:Pro:20.04:LTS: node-lodash, Ubuntu:Pro:22.04:LTS: node-lodash, Ubuntu:Pro:24.04:LTS: node-lodash, Ubuntu:25.10: node-lodash, Ubuntu:Pro:26.04:LTS: node-lodash</p>
<p>Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4800"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-088</id>
    <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
    <updated>2026-10-02T10:59:43.739700+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.</p>
<p>The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25</p>
<p>All other vulnerabilities are to be fixed in the upcoming releases.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1160</id>
    <title>WID-SEC-W-2026-1160 — Red Hat Enterprise Linux und Satellite (satellite/iop-remediations-rhel9 container image): Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:59:43.739742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Red Hat Satellite ausnutzen, um Informationen offenzulegen oder beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1160"/>
  </entry>
</feed>
