<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:07:03.323818+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366633</id>
    <title>EUVD-2026-366633</title>
    <updated>2026-10-02T11:07:03.406427+00:00</updated>
    <content>EUVD-2026-366633</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366633"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-88060</id>
    <title>fkie_cve-2026-88060</title>
    <updated>2026-10-02T11:07:03.406465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server serializes untrusted input inside template content nested in fallback raw-content elements such as noscript, iframe, noembed, and noframes. The Domino serializer's fallbackRawContentTags traversal stopped at the DocumentFragment used by template.content, so matching closing tags in xmp, style, script, comments, or text nodes were not escaped. Standard interpolation with comments or text nodes is reachable without relaxed schemas; literal xmp or style requires CUSTOM_ELEMENTS_SCHEMA or NO_ERRORS_SCHEMA, while Renderer2 imperative DOM construction is unconditionally affected. When HTML5 RAWTEXT browser parsing encounters the unescaped closing tag, it exits the fallback container and interprets trailing markup as active DOM elements, enabling arbitrary JavaScript execution. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-88060"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v3p8-whq6-r5jg</id>
    <title>GHSA-v3p8-whq6-r5jg — Angular: SSR XSS via Unescaped &lt;template&gt; Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements</title>
    <updated>2026-10-02T11:07:03.406505+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @angular/platform-server</p>
<p>### Summary
An XSS vulnerability exists in `@angular/platform-server` during server-side rendering (SSR) HTML serialization when traversing ancestor tags across `&lt;template&gt;` element boundaries. When an application renders untrusted user input within raw-text tags (`&lt;xmp&gt;`, `&lt;style&gt;`, `&lt;script&gt;`), comments, or text nodes inside a `&lt;template&gt;` that is nested within a fallback raw-content element (`&lt;noscript&gt;`, `&lt;iframe&gt;`, `&lt;noembed&gt;`, `&lt;noframes&gt;`), matching closing tags (e.g., `&lt;/noscript&gt;`) are not escaped during HTML serialization. When rendered in a browser, this unescaped closing tag prematurely terminates the fallback container and executes trailing markup as active DOM elements.</p>
<p>### Technical Description
In HTML5 parsing, fallback raw-content elements (`&lt;noscript&gt;`, `&lt;iframe&gt;`, `&lt;noembed&gt;`, `&lt;noframes&gt;`) place the browser's tokenizer into `RAWTEXT` mode. In this mode, inner content is parsed as literal text until an end tag matching the container tag name (e.g., `&lt;/noscript&gt;`) is encountered.</p>
<p>To prevent XSS breakout vectors during SSR serialization, the DOM serializer inspects a node's ancestors to escape any matching fallback closing tags (`&lt;/tag` -&gt; `&amp;lt;/tag`). However:
1. Per DOM specifications, the children of a `&lt;template&gt;` element reside in a separate `DocumentFragment` (`template.content`), whose own `parentNode` is `null`.
2. The serializer's ancestor traversal previously only inspected element nodes. When traversing upward from a node inside `template.conten…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v3p8-whq6-r5jg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-88060</id>
    <title>UBUNTU-CVE-2026-88060</title>
    <updated>2026-10-02T11:07:03.406559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: angular.js, Ubuntu:Pro:18.04:LTS: angular.js, Ubuntu:Pro:20.04:LTS: angular.js, Ubuntu:22.04:LTS: angular.js, Ubuntu:24.04:LTS: angular.js, Ubuntu:26.04:LTS: angular.js</p>
<p>Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server serializes untrusted input inside template content nested in fallback raw-content elements such as noscript, iframe, noembed, and noframes. The Domino serializer's fallbackRawContentTags traversal stopped at the DocumentFragment used by template.content, so matching closing tags in xmp, style, script, comments, or text nodes were not escaped. Standard interpolation with comments or text nodes is reachable without relaxed schemas; literal xmp or style requires CUSTOM_ELEMENTS_SCHEMA or NO_ERRORS_SCHEMA, while Renderer2 imperative DOM construction is unconditionally affected. When HTML5 RAWTEXT browser parsing encounters the unescaped closing tag, it exits the fallback container and interprets trailing markup as active DOM elements, enabling arbitrary JavaScript execution. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-88060"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3318</id>
    <title>WID-SEC-W-2026-3318 — Angular: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:07:03.406610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Angular ausnutzen, um Cross-Site-Scripting-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren und offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3318"/>
  </entry>
</feed>
