<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 10:26:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02116</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02116</link>
      <description>bdu:2024-02116</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02116</guid>
    </item>
    <item>
      <title>EUVD-2026-158388</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-158388</link>
      <description>EUVD-2026-158388</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-158388</guid>
    </item>
    <item>
      <title>fkie_cve-2024-27307</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-27307</link>
      <description>&lt;p&gt;JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions. This issue has been fixed in JSONata versions 1.8.7 and 2.0.4. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. As a workaround, one may apply the patch manually.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions. This issue has been fixed in JSONata versions 1.8.7 and 2.0.4. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. As a workaround, one may apply the patch manually.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-27307</guid>
    </item>
    <item>
      <title>GHSA-fqg8-vfv7-8fj8 — JSONata expression can pollute the "Object" prototype</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fqg8-vfv7-8fj8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jsonata&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In JSONata versions `&amp;gt;= 1.4.0, &amp;lt; 1.8.7` and `&amp;gt;= 2.0.0, &amp;lt; 2.0.4`, a malicious expression can use the [transform operator](https://docs.jsonata.org/other-operators#-------transform) to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions.&lt;/p&gt;
&lt;p&gt;### Patch&lt;/p&gt;
&lt;p&gt;This issue has been fixed in JSONata versions `&amp;gt;= 1.8.7` and `&amp;gt;= 2.0.4`. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. The following patch can be applied if updating is not possible.&lt;/p&gt;
&lt;p&gt;```patch
--- a/src/jsonata.js
+++ b/src/jsonata.js
@@ -1293,6 +1293,13 @@ var jsonata = (function() {
                 }
                 for(var ii = 0; ii &amp;lt; matches.length; ii++) {
                     var match = matches[ii];
+                    if (match &amp;amp;&amp;amp; (match.isPrototypeOf(result) || match instanceof Object.constructor)) {
+                        throw {
+                            code: &amp;#34;D1010&amp;#34;,
+                            stack: (new Error()).stack,
+                            position: expr.position
+                        };
+                    }
                     // evaluate the update value for each match
                     var update = await evaluate(expr.update, match, environment);
                     // update must be an object
@@ -1539,7 +1546,7 @@ var jsonata = (function() {
                 if (t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jsonata&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In JSONata versions `&amp;gt;= 1.4.0, &amp;lt; 1.8.7` and `&amp;gt;= 2.0.0, &amp;lt; 2.0.4`, a malicious expression can use the [transform operator](https://docs.jsonata.org/other-operators#-------transform) to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions.&lt;/p&gt;
&lt;p&gt;### Patch&lt;/p&gt;
&lt;p&gt;This issue has been fixed in JSONata versions `&amp;gt;= 1.8.7` and `&amp;gt;= 2.0.4`. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. The following patch can be applied if updating is not possible.&lt;/p&gt;
&lt;p&gt;```patch
--- a/src/jsonata.js
+++ b/src/jsonata.js
@@ -1293,6 +1293,13 @@ var jsonata = (function() {
                 }
                 for(var ii = 0; ii &amp;lt; matches.length; ii++) {
                     var match = matches[ii];
+                    if (match &amp;amp;&amp;amp; (match.isPrototypeOf(result) || match instanceof Object.constructor)) {
+                        throw {
+                            code: &amp;#34;D1010&amp;#34;,
+                            stack: (new Error()).stack,
+                            position: expr.position
+                        };
+                    }
                     // evaluate the update value for each match
                     var update = await evaluate(expr.update, match, environment);
                     // update must be an object
@@ -1539,7 +1546,7 @@ var jsonata = (function() {
                 if (t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fqg8-vfv7-8fj8</guid>
    </item>
    <item>
      <title>gsd-2024-27307</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-27307</link>
      <description>gsd-2024-27307</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-27307</guid>
    </item>
    <item>
      <title>RHEA-2024:4071 — Red Hat Enhancement Advisory: Red Hat Developer Hub 1.2 release</title>
      <link>https://cve.radiocsirt.org/vuln/rhea-2024:4071</link>
      <description>&lt;p&gt;pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools jsonata: malicious expression can pollute the &amp;#34;Object&amp;#34; prototype jinja2: accepts keys containing non-attribute characters requests: subsequent requests to the same host ignore cert verification&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools jsonata: malicious expression can pollute the &amp;#34;Object&amp;#34; prototype jinja2: accepts keys containing non-attribute characters requests: subsequent requests to the same host ignore cert verification&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhea-2024:4071</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0767 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0767</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0767</guid>
    </item>
  </channel>
</rss>
