<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:06:27 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0424 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0424</link>
      <description>certfr-2026-avi-0424</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0424</guid>
    </item>
    <item>
      <title>EUVD-2026-366097</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366097</link>
      <description>EUVD-2026-366097</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366097</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22029</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22029</link>
      <description>&lt;p&gt;React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (&amp;lt;BrowserRouter&amp;gt;) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (&amp;lt;BrowserRouter&amp;gt;) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22029</guid>
    </item>
    <item>
      <title>GHSA-2w69-qvjg-hvjx — React Router vulnerable to XSS via Open Redirects</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2w69-qvjg-hvjx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: react-router, npm: @remix-run/router&lt;/p&gt;
&lt;p&gt;React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in [Framework Mode](https://reactrouter.com/start/modes#framework), [Data Mode](https://reactrouter.com/start/modes#data), or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if developers are creating redirect paths from untrusted content or via an open redirect.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; This does not impact applications that use [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`&amp;lt;BrowserRouter&amp;gt;`).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: react-router, npm: @remix-run/router&lt;/p&gt;
&lt;p&gt;React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in [Framework Mode](https://reactrouter.com/start/modes#framework), [Data Mode](https://reactrouter.com/start/modes#data), or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if developers are creating redirect paths from untrusted content or via an open redirect.&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; This does not impact applications that use [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`&amp;lt;BrowserRouter&amp;gt;`).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2w69-qvjg-hvjx</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10069-1 — heroic-games-launcher-2.18.1-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10069-1</link>
      <description>&lt;p&gt;heroic-games-launcher-2.18.1-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;heroic-games-launcher-2.18.1-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10069-1</guid>
    </item>
    <item>
      <title>RHSA-2026:13542 — Red Hat Security Advisory: multicluster engine for Kubernetes v2.10.2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13542</link>
      <description>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions golang: archive/tar: Unbounded allocation when parsing GNU sparse map golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption rhacm: Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution axios: Axios: Remote Code Execution via Prototype Pollution escalation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions golang: archive/tar: Unbounded allocation when parsing GNU sparse map golang: net/url: Memory exhaustion in query parameter parsing in net/url crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption rhacm: Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution axios: Axios: Remote Code Execution via Prototype Pollution escalation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13542</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0553 — HCL BigFix: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0553</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um Informationen offenzulegen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um Informationen offenzulegen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0553</guid>
    </item>
  </channel>
</rss>
