<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:42:31 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-01281</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01281</link>
      <description>bdu:2026-01281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01281</guid>
    </item>
    <item>
      <title>EUVD-2026-337734</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337734</link>
      <description>EUVD-2026-337734</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337734</guid>
    </item>
    <item>
      <title>fkie_cve-2025-59057</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59057</link>
      <description>&lt;p&gt;React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router&amp;#39;s meta()/&amp;lt;Meta&amp;gt; APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag. There is no impact if the application is being used in Declarative Mode (&amp;lt;BrowserRouter&amp;gt;) or Data Mode (createBrowserRouter/&amp;lt;RouterProvider&amp;gt;). This issue has been patched in @remix-run/react version 2.17.1 and react-router version 7.9.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router&amp;#39;s meta()/&amp;lt;Meta&amp;gt; APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag. There is no impact if the application is being used in Declarative Mode (&amp;lt;BrowserRouter&amp;gt;) or Data Mode (createBrowserRouter/&amp;lt;RouterProvider&amp;gt;). This issue has been patched in @remix-run/react version 2.17.1 and react-router version 7.9.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-59057</guid>
    </item>
    <item>
      <title>GHSA-3cgp-3xvw-98x8 — React Router has XSS Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3cgp-3xvw-98x8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: react-router, npm: @remix-run/react&lt;/p&gt;
&lt;p&gt;A XSS vulnerability exists in in React Router&amp;#39;s `meta()`/`&amp;lt;Meta&amp;gt;` APIs in [Framework Mode](https://reactrouter.com/start/modes#framework) when generating `script:ld+json` tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; This does not impact applications using [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`&amp;lt;BrowserRouter&amp;gt;`) or [Data Mode](https://reactrouter.com/start/modes#data) (`createBrowserRouter`/`&amp;lt;RouterProvider&amp;gt;`).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: react-router, npm: @remix-run/react&lt;/p&gt;
&lt;p&gt;A XSS vulnerability exists in in React Router&amp;#39;s `meta()`/`&amp;lt;Meta&amp;gt;` APIs in [Framework Mode](https://reactrouter.com/start/modes#framework) when generating `script:ld+json` tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; This does not impact applications using [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`&amp;lt;BrowserRouter&amp;gt;`) or [Data Mode](https://reactrouter.com/start/modes#data) (`createBrowserRouter`/`&amp;lt;RouterProvider&amp;gt;`).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3cgp-3xvw-98x8</guid>
    </item>
    <item>
      <title>RHSA-2026:19712 — Red Hat Security Advisory: RHOAI 3.3.3 - Red Hat OpenShift AI</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:19712</link>
      <description>&lt;p&gt;vllm: Server Side request forgery (SSRF) in MediaConnector node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing react-router: @remix-run/router: React Router XSS Vulnerability golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate vllm: VLLM deserialization vulnerability leading to DoS and potential RCE axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization glob: glob: Command Injection Vulnerability via Malicious Filenames node-forge: node-forge ASN.1 Unbounded Recursion urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion vllm: vLLM: Remote Code Execution via malicious model configuration urllib3: urllib3 Streaming API improperly handles highly compressed data aiohttp: AIOHTTP&amp;#39;s HTTP Parser auto_decompress feature is vulnerable to zip bomb ajv: ReDoS via $data reference nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function nltk: NLTK: Arbitrary file read via path traversal vulnerability lodash: lodash: Arbitrary code execution via untrusted input in template imports urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming A…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vllm: Server Side request forgery (SSRF) in MediaConnector node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing react-router: @remix-run/router: React Router XSS Vulnerability golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate vllm: VLLM deserialization vulnerability leading to DoS and potential RCE axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization glob: glob: Command Injection Vulnerability via Malicious Filenames node-forge: node-forge ASN.1 Unbounded Recursion urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion vllm: vLLM: Remote Code Execution via malicious model configuration urllib3: urllib3 Streaming API improperly handles highly compressed data aiohttp: AIOHTTP&amp;#39;s HTTP Parser auto_decompress feature is vulnerable to zip bomb ajv: ReDoS via $data reference nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function nltk: NLTK: Arbitrary file read via path traversal vulnerability lodash: lodash: Arbitrary code execution via untrusted input in template imports urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming A…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:19712</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0752 — IBM SPSS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0752</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM SPSS ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM SPSS ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0752</guid>
    </item>
  </channel>
</rss>
