<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:53:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-05314</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05314</link>
      <description>bdu:2022-05314</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05314</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0276 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à un attaquant d…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276</link>
      <description>certfr-2023-avi-0276</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0276</guid>
    </item>
    <item>
      <title>EUVD-2026-232647</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232647</link>
      <description>EUVD-2026-232647</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232647</guid>
    </item>
    <item>
      <title>fkie_cve-2022-36033</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36033</link>
      <description>&lt;p&gt;jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-36033</guid>
    </item>
    <item>
      <title>GHSA-gp7f-rwcx-9369 — jsoup may not sanitize code injection XSS attempts if SafeList.preserveRelativeLinks is enabled</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gp7f-rwcx-9369</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jsoup:jsoup&lt;/p&gt;
&lt;p&gt;jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow cross-site scripting (XSS) attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible.&lt;/p&gt;
&lt;p&gt;### Impact
Sites that accept input HTML from users and use jsoup to sanitize that HTML, may be vulnerable to cross-site scripting (XSS) attacks, if they have enabled `SafeList.preserveRelativeLinks` and do not set an appropriate Content Security Policy.&lt;/p&gt;
&lt;p&gt;### Patches
This issue is patched in jsoup 1.15.3.&lt;/p&gt;
&lt;p&gt;Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version.&lt;/p&gt;
&lt;p&gt;### Workarounds
To remediate this issue without immediately upgrading:&lt;/p&gt;
&lt;p&gt;- disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs
- ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)&lt;/p&gt;
&lt;p&gt;### Background and root cause
jsoup includes a [Cleaner](https://jsoup.org/apidocs/org/jsoup/safety/Cleaner.html) component, which is designed to [sanitize input HTML](https://jsoup.org/cookbook/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.jsoup:jsoup&lt;/p&gt;
&lt;p&gt;jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow cross-site scripting (XSS) attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible.&lt;/p&gt;
&lt;p&gt;### Impact
Sites that accept input HTML from users and use jsoup to sanitize that HTML, may be vulnerable to cross-site scripting (XSS) attacks, if they have enabled `SafeList.preserveRelativeLinks` and do not set an appropriate Content Security Policy.&lt;/p&gt;
&lt;p&gt;### Patches
This issue is patched in jsoup 1.15.3.&lt;/p&gt;
&lt;p&gt;Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version.&lt;/p&gt;
&lt;p&gt;### Workarounds
To remediate this issue without immediately upgrading:&lt;/p&gt;
&lt;p&gt;- disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs
- ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)&lt;/p&gt;
&lt;p&gt;### Background and root cause
jsoup includes a [Cleaner](https://jsoup.org/apidocs/org/jsoup/safety/Cleaner.html) component, which is designed to [sanitize input HTML](https://jsoup.org/cookbook/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gp7f-rwcx-9369</guid>
    </item>
    <item>
      <title>gsd-2022-36033</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-36033</link>
      <description>gsd-2022-36033</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-36033</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-36033 — jsoup may not sanitize Cross-Site Scripting (XSS) attempts if SafeList.preserveRelativeLinks is enabled</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-36033</link>
      <description>msrc_CVE-2022-36033</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-36033</guid>
    </item>
    <item>
      <title>OESA-2024-1255 — jsoup security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1255</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: jsoup, openEuler:20.03-LTS-SP4: jsoup, openEuler:22.03-LTS: jsoup, openEuler:22.03-LTS-SP1: jsoup, openEuler:22.03-LTS-SP2: jsoup, openEuler:22.03-LTS-SP3: jsoup&lt;/p&gt;
&lt;p&gt;jsoup is a Java library for working with real-world HTML. It provides a very convenient API for extracting and manipulating data, using the best of DOM, CSS, and jquery-like methods.&#13;
&#13;
Security Fix(es):&#13;
&#13;
jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)(CVE-2022-36033)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: jsoup, openEuler:20.03-LTS-SP4: jsoup, openEuler:22.03-LTS: jsoup, openEuler:22.03-LTS-SP1: jsoup, openEuler:22.03-LTS-SP2: jsoup, openEuler:22.03-LTS-SP3: jsoup&lt;/p&gt;
&lt;p&gt;jsoup is a Java library for working with real-world HTML. It provides a very convenient API for extracting and manipulating data, using the best of DOM, CSS, and jquery-like methods.&#13;
&#13;
Security Fix(es):&#13;
&#13;
jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)(CVE-2022-36033)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1255</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12413-1 — jsoup-1.15.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12413-1</link>
      <description>&lt;p&gt;jsoup-1.15.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jsoup-1.15.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12413-1</guid>
    </item>
    <item>
      <title>RHSA-2024:6656 — Red Hat Security Advisory: Migration Toolkit for Runtimes security, bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:6656</link>
      <description>&lt;p&gt;jsoup: The jsoup cleaner may incorrectly sanitize crafted XSS attempts if SafeList.preserveRelativeLinks is enabled&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jsoup: The jsoup cleaner may incorrectly sanitize crafted XSS attempts if SafeList.preserveRelativeLinks is enabled&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:6656</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-36033</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36033</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jsoup, Ubuntu:16.04:LTS: jsoup, Ubuntu:18.04:LTS: jsoup, Ubuntu:20.04:LTS: jsoup, Ubuntu:22.04:LTS: jsoup, Ubuntu:24.04:LTS: jsoup, Ubuntu:25.10: jsoup, Ubuntu:26.04:LTS: jsoup&lt;/p&gt;
&lt;p&gt;jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jsoup, Ubuntu:16.04:LTS: jsoup, Ubuntu:18.04:LTS: jsoup, Ubuntu:20.04:LTS: jsoup, Ubuntu:22.04:LTS: jsoup, Ubuntu:24.04:LTS: jsoup, Ubuntu:25.10: jsoup, Ubuntu:26.04:LTS: jsoup&lt;/p&gt;
&lt;p&gt;jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36033</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0133 — Oracle Financial Services Applications: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0133</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0133</guid>
    </item>
  </channel>
</rss>
