<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:46:46 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10872</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10872</link>
      <description>bdu:2026-10872</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10872</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0917 — De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Elles permettent à un attaquant de provoquer un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0917</link>
      <description>certfr-2026-avi-0917</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0917</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-FR63847 — yawkat LZ4 Java provides LZ4 compression for Java</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fr63847</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: elasticsearch&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the elasticsearch package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: elasticsearch&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the elasticsearch package. yawkat LZ4 Java provides LZ4 compression for Java. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fr63847</guid>
    </item>
    <item>
      <title>EUVD-2026-261937</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261937</link>
      <description>EUVD-2026-261937</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261937</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66021</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66021</link>
      <description>&lt;p&gt;OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against XSS. In version 20240325.1,  OWASP java html sanitizer is vulnerable to XSS if HtmlPolicyBuilder allows noscript and style tags with allowTextIn inside the style tag. This could lead to XSS if the payload is crafted in such a way that it does not sanitise the CSS and allows tags which is not mentioned in HTML policy. At time of publication no known patch is available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against XSS. In version 20240325.1,  OWASP java html sanitizer is vulnerable to XSS if HtmlPolicyBuilder allows noscript and style tags with allowTextIn inside the style tag. This could lead to XSS if the payload is crafted in such a way that it does not sanitise the CSS and allows tags which is not mentioned in HTML policy. At time of publication no known patch is available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66021</guid>
    </item>
    <item>
      <title>GHSA-g9gq-3pfx-2gw2 — OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g9gq-3pfx-2gw2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer&lt;/p&gt;
&lt;p&gt;### Summary
It is observed that OWASP java html sanitizer is vulnerable to XSS if HtmlPolicyBuilder allows `noscript` and `style` tags with `allowTextIn` inside the style tag. This could lead to XSS if the payload is crafted in such a way that it does not sanitise the CSS and allows tags which is not mentioned in HTML policy.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The OWASP java HTML sanitizer is vulnerable to XSS. This only happens when HtmlPolicyBuilder allows `noscript` &amp;amp; `style` tag with `allowTextIn` inside style tags.&lt;/p&gt;
&lt;p&gt;The following condition is very edge case but if users combine a HtmlPolicyBuilder with any other tags except `noscript` and allow `style` tag with `allowTextIn` inside the style tag then In this case sanitizer would be safe from XSS. This happens because how the browser also perceives `noscript` tags post sanitization.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1.  Lets create a `HtmlPolicyBuilder` which allows `p, noscript, style` html tags and allows `.allowTextIn(&amp;#34;style&amp;#34;)`.
2.  There are two XSS payloads which very identical and only difference is one has p tag and other has noscript tag.
These payload have script tags that could be vulnerable to XSS and should be stripped out after sanitisation.&lt;/p&gt;
&lt;p&gt;```HTML
1. &amp;lt;noscript&amp;gt;&amp;lt;style&amp;gt;&amp;lt;/noscript&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;
2. &amp;lt;p&amp;gt;&amp;lt;style&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;
```&lt;/p&gt;
&lt;p&gt;3. Run the following piece of code which sanitizes the payload.&lt;/p&gt;
&lt;p&gt;```java
public class main {
	private static final String ALLOWED_HTML_TAGS = &amp;#34;p, noscript, style&amp;#34;;&lt;/p&gt;
&lt;p&gt;/**
	 * Description of vulnerabil…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer&lt;/p&gt;
&lt;p&gt;### Summary
It is observed that OWASP java html sanitizer is vulnerable to XSS if HtmlPolicyBuilder allows `noscript` and `style` tags with `allowTextIn` inside the style tag. This could lead to XSS if the payload is crafted in such a way that it does not sanitise the CSS and allows tags which is not mentioned in HTML policy.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The OWASP java HTML sanitizer is vulnerable to XSS. This only happens when HtmlPolicyBuilder allows `noscript` &amp;amp; `style` tag with `allowTextIn` inside style tags.&lt;/p&gt;
&lt;p&gt;The following condition is very edge case but if users combine a HtmlPolicyBuilder with any other tags except `noscript` and allow `style` tag with `allowTextIn` inside the style tag then In this case sanitizer would be safe from XSS. This happens because how the browser also perceives `noscript` tags post sanitization.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1.  Lets create a `HtmlPolicyBuilder` which allows `p, noscript, style` html tags and allows `.allowTextIn(&amp;#34;style&amp;#34;)`.
2.  There are two XSS payloads which very identical and only difference is one has p tag and other has noscript tag.
These payload have script tags that could be vulnerable to XSS and should be stripped out after sanitisation.&lt;/p&gt;
&lt;p&gt;```HTML
1. &amp;lt;noscript&amp;gt;&amp;lt;style&amp;gt;&amp;lt;/noscript&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;
2. &amp;lt;p&amp;gt;&amp;lt;style&amp;gt;&amp;lt;/p&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;
```&lt;/p&gt;
&lt;p&gt;3. Run the following piece of code which sanitizes the payload.&lt;/p&gt;
&lt;p&gt;```java
public class main {
	private static final String ALLOWED_HTML_TAGS = &amp;#34;p, noscript, style&amp;#34;;&lt;/p&gt;
&lt;p&gt;/**
	 * Description of vulnerabil…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g9gq-3pfx-2gw2</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0438 — Atlassian Bamboo und Confluence (Data Center und Server): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0438</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Atlassian Bamboo und Atlassian Confluence ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Atlassian Bamboo und Atlassian Confluence ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0438</guid>
    </item>
  </channel>
</rss>
