<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:49:43 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0834 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0834</link>
      <description>certfr-2026-avi-0834</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0834</guid>
    </item>
    <item>
      <title>EUVD-2026-267131</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267131</link>
      <description>EUVD-2026-267131</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267131</guid>
    </item>
    <item>
      <title>fkie_cve-2026-24040</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24040</link>
      <description>&lt;p&gt;jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes a shared module-scoped variable (text) to store JavaScript content. When used in a concurrent environment (e.g., a Node.js web server), this variable is shared across all requests. If multiple requests generate PDFs simultaneously, the JavaScript content intended for one user may be overwritten by a subsequent request before the document is generated. This results in Cross-User Data Leakage, where the PDF generated for User A contains the JavaScript payload (and any embedded sensitive data) intended for User B. Typically, this only affects server-side environments, although the same race conditions might occur if jsPDF runs client-side. The vulnerability has been fixed in jsPDF@4.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes a shared module-scoped variable (text) to store JavaScript content. When used in a concurrent environment (e.g., a Node.js web server), this variable is shared across all requests. If multiple requests generate PDFs simultaneously, the JavaScript content intended for one user may be overwritten by a subsequent request before the document is generated. This results in Cross-User Data Leakage, where the PDF generated for User A contains the JavaScript payload (and any embedded sensitive data) intended for User B. Typically, this only affects server-side environments, although the same race conditions might occur if jsPDF runs client-side. The vulnerability has been fixed in jsPDF@4.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-24040</guid>
    </item>
    <item>
      <title>GHSA-cjw8-79x6-5cj4 — jsPDF has Shared State Race Condition in addJS Plugin</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cjw8-79x6-5cj4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jspdf&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The addJS method in the jspdf Node.js build utilizes a shared module-scoped variable (text) to store JavaScript content. When used in a concurrent environment (e.g., a Node.js web server), this variable is shared across all requests.&lt;/p&gt;
&lt;p&gt;If multiple requests generate PDFs simultaneously, the JavaScript content intended for one user may be overwritten by a subsequent request before the document is generated. This results in Cross-User Data Leakage, where the PDF generated for User A contains the JavaScript payload (and any embedded sensitive data) intended for User B.&lt;/p&gt;
&lt;p&gt;Typically, this only affects server-side environments, although the same race conditions might occur if jsPDF runs client-side.&lt;/p&gt;
&lt;p&gt;```js
import { jsPDF } from &amp;#34;jspdf&amp;#34;;&lt;/p&gt;
&lt;p&gt;const docA = new jsPDF();
const docB = new jsPDF();&lt;/p&gt;
&lt;p&gt;// 1. User A sets their script (stored in shared &amp;#39;text&amp;#39; variable)
docA.addJS(&amp;#39;console.log(&amp;#34;Secret A&amp;#34;);&amp;#39;);&lt;/p&gt;
&lt;p&gt;// 2. User B sets their script (overwrites shared &amp;#39;text&amp;#39; variable)
docB.addJS(&amp;#39;console.log(&amp;#34;Secret B&amp;#34;);&amp;#39;);&lt;/p&gt;
&lt;p&gt;// 3. User A saves their PDF (reads current &amp;#39;text&amp;#39; variable)
docA.save(&amp;#34;userA.pdf&amp;#34;);&lt;/p&gt;
&lt;p&gt;// Result: userA.pdf contains &amp;#34;Secret B&amp;#34; instead of &amp;#34;Secret A&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### Patches
The vulnerability has been fixed in jspdf@4.0.1. The fix moves the shared variable into the function scope, ensuring isolation between instances.&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid using the addJS method in concurrent server-side environments. If usage is required, ensure requests are processed sequentially (e.g., using a qu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jspdf&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The addJS method in the jspdf Node.js build utilizes a shared module-scoped variable (text) to store JavaScript content. When used in a concurrent environment (e.g., a Node.js web server), this variable is shared across all requests.&lt;/p&gt;
&lt;p&gt;If multiple requests generate PDFs simultaneously, the JavaScript content intended for one user may be overwritten by a subsequent request before the document is generated. This results in Cross-User Data Leakage, where the PDF generated for User A contains the JavaScript payload (and any embedded sensitive data) intended for User B.&lt;/p&gt;
&lt;p&gt;Typically, this only affects server-side environments, although the same race conditions might occur if jsPDF runs client-side.&lt;/p&gt;
&lt;p&gt;```js
import { jsPDF } from &amp;#34;jspdf&amp;#34;;&lt;/p&gt;
&lt;p&gt;const docA = new jsPDF();
const docB = new jsPDF();&lt;/p&gt;
&lt;p&gt;// 1. User A sets their script (stored in shared &amp;#39;text&amp;#39; variable)
docA.addJS(&amp;#39;console.log(&amp;#34;Secret A&amp;#34;);&amp;#39;);&lt;/p&gt;
&lt;p&gt;// 2. User B sets their script (overwrites shared &amp;#39;text&amp;#39; variable)
docB.addJS(&amp;#39;console.log(&amp;#34;Secret B&amp;#34;);&amp;#39;);&lt;/p&gt;
&lt;p&gt;// 3. User A saves their PDF (reads current &amp;#39;text&amp;#39; variable)
docA.save(&amp;#34;userA.pdf&amp;#34;);&lt;/p&gt;
&lt;p&gt;// Result: userA.pdf contains &amp;#34;Secret B&amp;#34; instead of &amp;#34;Secret A&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### Patches
The vulnerability has been fixed in jspdf@4.0.1. The fix moves the shared variable into the function scope, ensuring isolation between instances.&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid using the addJS method in concurrent server-side environments. If usage is required, ensure requests are processed sequentially (e.g., using a qu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cjw8-79x6-5cj4</guid>
    </item>
    <item>
      <title>RHSA-2026:4466 — Red Hat Security Advisory: RHACS 4.8.9 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:4466</link>
      <description>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) jsPDF: jsPDF: Cross-User Data Leakage via race condition in addJS method jsPDF: jsPDF: Arbitrary code execution via unsanitized input in Acroform module&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) jsPDF: jsPDF: Cross-User Data Leakage via race condition in addJS method jsPDF: jsPDF: Arbitrary code execution via unsanitized input in Acroform module&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:4466</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0553 — HCL BigFix: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0553</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um Informationen offenzulegen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um Informationen offenzulegen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0553</guid>
    </item>
  </channel>
</rss>
