<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:42:40 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</link>
      <description>certfr-2026-avi-0667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CE10526 — Security fixes for CVE-2025-64756, CVE-2025-69873, CVE-2026-1525, CVE-2026-1526, CVE-2026-1527, CVE-2026-1528, CVE-2026…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: renovate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: renovate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</guid>
    </item>
    <item>
      <title>EUVD-2026-366079</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366079</link>
      <description>EUVD-2026-366079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366079</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25896</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25896</link>
      <description>&lt;p&gt;fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&amp;amp;lt;, &amp;amp;gt;, &amp;amp;amp;, &amp;amp;quot;, &amp;amp;apos;) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&amp;amp;lt;, &amp;amp;gt;, &amp;amp;amp;, &amp;amp;quot;, &amp;amp;apos;) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25896</guid>
    </item>
    <item>
      <title>GHSA-m7jm-9gc2-mpf2 — fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m7jm-9gc2-mpf2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-xml-parser&lt;/p&gt;
&lt;p&gt;# Entity encoding bypass via regex injection in DOCTYPE entity names&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A dot (`.`) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (`&amp;amp;lt;`, `&amp;amp;gt;`, `&amp;amp;amp;`, `&amp;amp;quot;`, `&amp;amp;apos;`) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The fix for CVE-2023-34104 addressed some regex metacharacters in entity names but missed `.` (period), which is valid in XML names per the W3C spec.&lt;/p&gt;
&lt;p&gt;In `DocTypeReader.js`, entity names are passed directly to `RegExp()`:&lt;/p&gt;
&lt;p&gt;```js
entities[entityName] = {
    regx: RegExp(`&amp;amp;${entityName};`, &amp;#34;g&amp;#34;),
    val: val
};
```&lt;/p&gt;
&lt;p&gt;An entity named `l.` produces the regex `/&amp;amp;l.;/g` where `.` matches **any character**, including the `t` in `&amp;amp;lt;`. Since DOCTYPE entities are replaced before built-in entities, this shadows `&amp;amp;lt;` entirely.&lt;/p&gt;
&lt;p&gt;The same issue exists in `OrderedObjParser.js:81` (`addExternalEntities`), and in the v6 codebase - `EntitiesParser.js` has a `validateEntityName` function with a character blacklist, but `.` is not included:&lt;/p&gt;
&lt;p&gt;```js
// v6 EntitiesParser.js line 96
const specialChar = &amp;#34;!?\\/[]$%{}^&amp;amp;*()&amp;lt;&amp;gt;|+&amp;#34;;  // no dot
```&lt;/p&gt;
&lt;p&gt;## Shadowing all 5 built-in entities&lt;/p&gt;
&lt;p&gt;| Entity name | Regex created | Shadows |
|---|---|---|
| `l.` | `/&amp;amp;l.;/g` | `&amp;amp;lt;` |
| `g.` | `/&amp;amp;g.;/g` | `&amp;amp;gt;` |
| `am.` | `/&amp;amp;am.;/g` | `&amp;amp;amp;` |
| `quo.` | `/&amp;amp;quo.;/g` | `&amp;amp;quot;` |
| `apo.` | `/&amp;amp;apo.;/g` | `&amp;amp;apos;` |&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```js…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-xml-parser&lt;/p&gt;
&lt;p&gt;# Entity encoding bypass via regex injection in DOCTYPE entity names&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A dot (`.`) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (`&amp;amp;lt;`, `&amp;amp;gt;`, `&amp;amp;amp;`, `&amp;amp;quot;`, `&amp;amp;apos;`) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The fix for CVE-2023-34104 addressed some regex metacharacters in entity names but missed `.` (period), which is valid in XML names per the W3C spec.&lt;/p&gt;
&lt;p&gt;In `DocTypeReader.js`, entity names are passed directly to `RegExp()`:&lt;/p&gt;
&lt;p&gt;```js
entities[entityName] = {
    regx: RegExp(`&amp;amp;${entityName};`, &amp;#34;g&amp;#34;),
    val: val
};
```&lt;/p&gt;
&lt;p&gt;An entity named `l.` produces the regex `/&amp;amp;l.;/g` where `.` matches **any character**, including the `t` in `&amp;amp;lt;`. Since DOCTYPE entities are replaced before built-in entities, this shadows `&amp;amp;lt;` entirely.&lt;/p&gt;
&lt;p&gt;The same issue exists in `OrderedObjParser.js:81` (`addExternalEntities`), and in the v6 codebase - `EntitiesParser.js` has a `validateEntityName` function with a character blacklist, but `.` is not included:&lt;/p&gt;
&lt;p&gt;```js
// v6 EntitiesParser.js line 96
const specialChar = &amp;#34;!?\\/[]$%{}^&amp;amp;*()&amp;lt;&amp;gt;|+&amp;#34;;  // no dot
```&lt;/p&gt;
&lt;p&gt;## Shadowing all 5 built-in entities&lt;/p&gt;
&lt;p&gt;| Entity name | Regex created | Shadows |
|---|---|---|
| `l.` | `/&amp;amp;l.;/g` | `&amp;amp;lt;` |
| `g.` | `/&amp;amp;g.;/g` | `&amp;amp;gt;` |
| `am.` | `/&amp;amp;am.;/g` | `&amp;amp;amp;` |
| `quo.` | `/&amp;amp;quo.;/g` | `&amp;amp;quot;` |
| `apo.` | `/&amp;amp;apo.;/g` | `&amp;amp;apos;` |&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```js…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m7jm-9gc2-mpf2</guid>
    </item>
    <item>
      <title>RHSA-2026:40984 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.20.15 security, enhancement &amp; bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:40984</link>
      <description>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-forge: node-forge ASN.1 Unbounded Recursion webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior ajv: ReDoS via $data reference lodash: lodash: Arbitrary code execution via untrusted input in template imports @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: g…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-forge: node-forge ASN.1 Unbounded Recursion webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior ajv: ReDoS via $data reference lodash: lodash: Arbitrary code execution via untrusted input in template imports @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: g…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:40984</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-25896</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25896</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-webfont, Ubuntu:25.10: node-webfont, Ubuntu:26.04:LTS: node-webfont&lt;/p&gt;
&lt;p&gt;fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&amp;amp;lt;, &amp;amp;gt;, &amp;amp;amp;, &amp;amp;quot;, &amp;amp;apos;) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-webfont, Ubuntu:25.10: node-webfont, Ubuntu:26.04:LTS: node-webfont&lt;/p&gt;
&lt;p&gt;fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&amp;amp;lt;, &amp;amp;gt;, &amp;amp;amp;, &amp;amp;quot;, &amp;amp;apos;) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25896</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0772 — IBM App Connect Enterprise (fast-xml-parser): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0772</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen oder Sicherheitsmaßnahmen zu umgehen, wodurch Cross-Site-Scripting-Angriffe ermöglicht werden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen oder Sicherheitsmaßnahmen zu umgehen, wodurch Cross-Site-Scripting-Angriffe ermöglicht werden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0772</guid>
    </item>
  </channel>
</rss>
