<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:07:09.798347+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366894</id>
    <title>EUVD-2026-366894</title>
    <updated>2026-10-02T11:07:09.872409+00:00</updated>
    <content>EUVD-2026-366894</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-88058</id>
    <title>fkie_cve-2026-88058</title>
    <updated>2026-10-02T11:07:09.872444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server serializes ProcessingInstruction DOM nodes inside fallback raw-content elements without escaping matching ancestor closing tags. ProcessingInstruction data escaped greater-than characters but left less-than characters untouched and did not inspect fallback ancestors, so data such as a matching closing tag prematurely terminates noscript, iframe, noembed, or noframes containers. The vulnerable nodes cannot be authored through standard Angular templates; reachability requires application or library code using inject(DOCUMENT).createProcessingInstruction with attacker-controlled data or Renderer2 DOM insertion inside a fallback container. In HTML5 RAWTEXT parsing, the premature close causes subsequent sibling elements to be interpreted as live HTML and enables arbitrary JavaScript execution in a victim's browser. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-88058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j3r3-mxqp-r2p4</id>
    <title>GHSA-j3r3-mxqp-r2p4 — Angular SSR: XSS via Unescaped Processing Instruction (&lt;?...?&gt;) Nodes in Fallback Raw-Content Elements</title>
    <updated>2026-10-02T11:07:09.872484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @angular/platform-server</p>
<p>### Summary
An XSS vulnerability exists in `@angular/platform-server` during server-side rendering (SSR) HTML serialization of `ProcessingInstruction` DOM nodes (`&lt;?target data?&gt;`, `nodeType === 7`) when nested inside fallback raw-content elements (`&lt;noscript&gt;`, `&lt;iframe&gt;`, `&lt;noembed&gt;`, `&lt;noframes&gt;`). While processing instruction data escaped `&gt;` to `&amp;gt;`, it did not check for or escape matching closing tags of ancestor fallback elements (e.g., `&lt;/noscript&gt;`). When rendered in a browser with scripting enabled, an unescaped closing tag sequence in a processing instruction prematurely closes the fallback raw-content tag and causes subsequent sibling elements to execute as live HTML.</p>
<p>### Technical Description
In HTML5 parsing, fallback raw-content elements (`&lt;noscript&gt;`, `&lt;iframe&gt;`, `&lt;noembed&gt;`, `&lt;noframes&gt;`) place the browser's HTML tokenizer into `RAWTEXT` mode. In `RAWTEXT` mode, processing instruction tokens (`&lt;?...?&gt;`) are treated as literal raw text rather than bogus comments, and the parser ignores `&gt;` or `?&gt;`. The only token sequence that terminates the container is an end tag matching the container tag name (`&lt;/noscript`, `&lt;/iframe`, etc.).</p>
<p>During server-side HTML serialization, processing instruction nodes previously only replaced `&gt;` with `&amp;gt;` (preventing bogus comment breakouts in normal HTML data states) but left `&lt;` untouched. Crucially, processing instruction serialization never inspected ancestor fallback raw-content tags. As a result, if a `ProcessingInstr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j3r3-mxqp-r2p4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-88058</id>
    <title>UBUNTU-CVE-2026-88058</title>
    <updated>2026-10-02T11:07:09.872538+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: angular.js, Ubuntu:Pro:18.04:LTS: angular.js, Ubuntu:Pro:20.04:LTS: angular.js, Ubuntu:22.04:LTS: angular.js, Ubuntu:24.04:LTS: angular.js, Ubuntu:26.04:LTS: angular.js</p>
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server serializes ProcessingInstruction DOM nodes inside fallback raw-content elements without escaping matching ancestor closing tags. ProcessingInstruction data escaped greater-than characters but left less-than characters untouched and did not inspect fallback ancestors, so data such as a matching closing tag prematurely terminates noscript, iframe, noembed, or noframes containers. The vulnerable nodes cannot be authored through standard Angular templates; reachability requires application or library code using inject(DOCUMENT).createProcessingInstruction with attacker-controlled data or Renderer2 DOM insertion inside a fallback container. In HTML5 RAWTEXT parsing, the premature close causes subsequent sibling elements to be interpreted as live HTML and enables arbitrary JavaScript execution in a victim's browser. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-88058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3318</id>
    <title>WID-SEC-W-2026-3318 — Angular: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:07:09.872574+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Angular ausnutzen, um Cross-Site-Scripting-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren und offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3318"/>
  </entry>
</feed>
