<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:18:23 +0000</lastBuildDate>
    <item>
      <title>certfr-2023-avi-0428 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;Splunk&lt;/span&gt;. Certaines d'entre…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0428</link>
      <description>certfr-2023-avi-0428</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0428</guid>
    </item>
    <item>
      <title>EUVD-2026-18859</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-18859</link>
      <description>EUVD-2026-18859</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-18859</guid>
    </item>
    <item>
      <title>fkie_cve-2022-37616</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-37616</link>
      <description>&lt;p&gt;A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states &amp;#34;we are in the process of marking this report as invalid&amp;#34;; however, some third parties takes the position that &amp;#34;A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states &amp;#34;we are in the process of marking this report as invalid&amp;#34;; however, some third parties takes the position that &amp;#34;A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-37616</guid>
    </item>
    <item>
      <title>Withdrawn: GHSA-9pgh-qqpf-7wqj — Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9pgh-qqpf-7wqj</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Withdrawn&lt;/p&gt;
&lt;p&gt;This advisory has been withdrawn because the maintainers of `@xmldom/xmldom` and multiple third parties disputed the validity of the issue. Attempts to create or replicate a proof of concept have been unsuccessful.&lt;/p&gt;
&lt;p&gt;## Original Description&lt;/p&gt;
&lt;p&gt;### Impact
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package.&lt;/p&gt;
&lt;p&gt;### Patches
Update to `@xmldom/xmldom@~0.7.6`, `@xmldom/xmldom@~0.8.3` (dist-tag `latest`) or `@xmldom/xmldom@&amp;gt;=0.9.0-beta.2` (dist-tag `next`).&lt;/p&gt;
&lt;p&gt;### Workarounds
None&lt;/p&gt;
&lt;p&gt;### References
https://github.com/xmldom/xmldom/pull/437&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Email us at security@xmldom.org
* Add information to https://github.com/xmldom/xmldom/issues/436&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Withdrawn&lt;/p&gt;
&lt;p&gt;This advisory has been withdrawn because the maintainers of `@xmldom/xmldom` and multiple third parties disputed the validity of the issue. Attempts to create or replicate a proof of concept have been unsuccessful.&lt;/p&gt;
&lt;p&gt;## Original Description&lt;/p&gt;
&lt;p&gt;### Impact
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package.&lt;/p&gt;
&lt;p&gt;### Patches
Update to `@xmldom/xmldom@~0.7.6`, `@xmldom/xmldom@~0.8.3` (dist-tag `latest`) or `@xmldom/xmldom@&amp;gt;=0.9.0-beta.2` (dist-tag `next`).&lt;/p&gt;
&lt;p&gt;### Workarounds
None&lt;/p&gt;
&lt;p&gt;### References
https://github.com/xmldom/xmldom/pull/437&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:
* Email us at security@xmldom.org
* Add information to https://github.com/xmldom/xmldom/issues/436&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9pgh-qqpf-7wqj</guid>
    </item>
    <item>
      <title>gsd-2022-37616</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-37616</link>
      <description>gsd-2022-37616</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-37616</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-37616 — A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) p…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-37616</link>
      <description>msrc_CVE-2022-37616</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-37616</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-37616</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-37616</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states &amp;#34;we are in the process of marking this report as invalid&amp;#34;; however, some third parties takes the position that &amp;#34;A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted.&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states &amp;#34;we are in the process of marking this report as invalid&amp;#34;; however, some third parties takes the position that &amp;#34;A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted.&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-37616</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2368 — HCL BigFix: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2368</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um die Verfügbarkeit, die Vertraulichkeit und die Integrität zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um die Verfügbarkeit, die Vertraulichkeit und die Integrität zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2368</guid>
    </item>
  </channel>
</rss>
