<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:44:50 +0000</lastBuildDate>
    <item>
      <title>certfr-2023-avi-0705 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0705</link>
      <description>certfr-2023-avi-0705</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0705</guid>
    </item>
    <item>
      <title>EUVD-2026-8690</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-8690</link>
      <description>EUVD-2026-8690</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-8690</guid>
    </item>
    <item>
      <title>fkie_cve-2023-34104</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-34104</link>
      <description>&lt;p&gt;fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sanitized. Since the entity name is used for creating a regex for searching and replacing entities in the XML body, an attacker can abuse it for denial of service (DoS) attacks. By crafting an entity name that results in an intentionally bad performing regex and utilizing it in the entity replacement step of the parser, this can cause the parser to stall for an indefinite amount of time. This problem has been resolved in v4.2.4. Users are advised to upgrade. Users unable to upgrade should avoid using DOCTYPE parsing by setting the `processEntities: false` option.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sanitized. Since the entity name is used for creating a regex for searching and replacing entities in the XML body, an attacker can abuse it for denial of service (DoS) attacks. By crafting an entity name that results in an intentionally bad performing regex and utilizing it in the entity replacement step of the parser, this can cause the parser to stall for an indefinite amount of time. This problem has been resolved in v4.2.4. Users are advised to upgrade. Users unable to upgrade should avoid using DOCTYPE parsing by setting the `processEntities: false` option.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-34104</guid>
    </item>
    <item>
      <title>GHSA-6w63-h3fj-q4vw — fast-xml-parser vulnerable to Regex Injection via Doctype Entities</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6w63-h3fj-q4vw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-xml-parser&lt;/p&gt;
&lt;p&gt;### Impact
&amp;#34;fast-xml-parser&amp;#34; allows special characters in entity names, which are not escaped or sanitized. Since the entity name is used for creating a regex for searching and replacing entities in the XML body, an attacker can abuse it for DoS attacks. By crafting an entity name that results in an intentionally bad performing regex and utilizing it in the entity replacement step of the parser, this can cause the parser to stall for an indefinite amount of time.&lt;/p&gt;
&lt;p&gt;### Patches
The problem has been resolved in v4.2.4&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid using DOCTYPE parsing by `processEntities: false` option.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-xml-parser&lt;/p&gt;
&lt;p&gt;### Impact
&amp;#34;fast-xml-parser&amp;#34; allows special characters in entity names, which are not escaped or sanitized. Since the entity name is used for creating a regex for searching and replacing entities in the XML body, an attacker can abuse it for DoS attacks. By crafting an entity name that results in an intentionally bad performing regex and utilizing it in the entity replacement step of the parser, this can cause the parser to stall for an indefinite amount of time.&lt;/p&gt;
&lt;p&gt;### Patches
The problem has been resolved in v4.2.4&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid using DOCTYPE parsing by `processEntities: false` option.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6w63-h3fj-q4vw</guid>
    </item>
    <item>
      <title>gsd-2023-34104</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-34104</link>
      <description>gsd-2023-34104</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-34104</guid>
    </item>
    <item>
      <title>RHSA-2023:4627 — Red Hat Security Advisory: Migration Toolkit for Applications security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:4627</link>
      <description>&lt;p&gt;jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode undertow: Server identity in https connection is not checked by the undertow client x/net/http2/h2c: request smuggling golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption dev-java/snakeyaml: DoS via stack overflow codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS htmlUnit: Stack overflow crash causes Denial of Service (DoS) zip4j: does not always check the MAC when decrypting a ZIP archive golang: crypto/internal/nistec: specific unreduced P-256 scalars produce incorrect results golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values golang: html/template: improper handling of JavaScript whitespace golang-github-gin-gonic-gin: Improper Input Validation golang: html/template: improper handling of empty HTML attributes fast-xml-parser: Regex Injection via Doctype Entities&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jackson-databind: Possible DoS if using JDK serialization to serialize JsonNode undertow: Server identity in https connection is not checked by the undertow client x/net/http2/h2c: request smuggling golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption dev-java/snakeyaml: DoS via stack overflow codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS htmlUnit: Stack overflow crash causes Denial of Service (DoS) zip4j: does not always check the MAC when decrypting a ZIP archive golang: crypto/internal/nistec: specific unreduced P-256 scalars produce incorrect results golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values golang: html/template: improper handling of JavaScript whitespace golang-github-gin-gonic-gin: Improper Input Validation golang: html/template: improper handling of empty HTML attributes fast-xml-parser: Regex Injection via Doctype Entities&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:4627</guid>
    </item>
  </channel>
</rss>
