<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:20:11 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0523 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0523</link>
      <description>certfr-2026-avi-0523</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0523</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CE10526 — Security fixes for CVE-2025-64756, CVE-2025-69873, CVE-2026-1525, CVE-2026-1526, CVE-2026-1527, CVE-2026-1528, CVE-2026…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: renovate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: renovate&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the renovate package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ce10526</guid>
    </item>
    <item>
      <title>EUVD-2026-366119</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366119</link>
      <description>EUVD-2026-366119</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366119</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26278</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26278</link>
      <description>&lt;p&gt;fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `processEntities: false` option.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `processEntities: false` option.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26278</guid>
    </item>
    <item>
      <title>GHSA-jmr7-xgp7-cmfj — fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jmr7-xgp7-cmfj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-xml-parser&lt;/p&gt;
&lt;p&gt;### Summary
The XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application.&lt;/p&gt;
&lt;p&gt;### Details
There is a check in `DocTypeReader.js` that tries to prevent entity expansion attacks by rejecting entities that reference other entities (it looks for &amp;amp; inside entity values). This does stop classic “Billion Laughs” payloads.&lt;/p&gt;
&lt;p&gt;However, it doesn’t stop a much simpler variant.&lt;/p&gt;
&lt;p&gt;If you define one large entity that contains only raw text (no &amp;amp; characters) and then reference it many times, the parser will happily expand it every time. There is no limit on how large the expanded result can become, or how many replacements are allowed.&lt;/p&gt;
&lt;p&gt;The problem is in `replaceEntitiesValue()` inside `OrderedObjParser.js`. It repeatedly runs `val.replace()` in a loop, without any checks on total output size or execution cost. As the entity grows or the number of references increases, parsing time explodes.&lt;/p&gt;
&lt;p&gt;Relevant code:&lt;/p&gt;
&lt;p&gt;`DocTypeReader.js` (lines 28–33): entity registration only checks for &amp;amp;&lt;/p&gt;
&lt;p&gt;`OrderedObjParser.js` (lines 439–458): entity replacement loop with no limits&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
const { XMLParser } = require(&amp;#39;fast-xml-parser&amp;#39;);&lt;/p&gt;
&lt;p&gt;const entity = &amp;#39;A&amp;#39;.repeat(1000);
const refs = &amp;#39;&amp;amp;big;&amp;#39;.repeat(100);
const xml = `&amp;lt;!DOCTYPE foo [&amp;lt;!ENTITY big &amp;#34;${entity}&amp;#34;&amp;gt;]&amp;gt;&amp;lt;root&amp;gt;${refs}&amp;lt;/root&amp;gt;`;&lt;/p&gt;
&lt;p&gt;console.time(&amp;#39;parse&amp;#39;);
new XMLParser().parse(xml); // ~4–8 se…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-xml-parser&lt;/p&gt;
&lt;p&gt;### Summary
The XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application.&lt;/p&gt;
&lt;p&gt;### Details
There is a check in `DocTypeReader.js` that tries to prevent entity expansion attacks by rejecting entities that reference other entities (it looks for &amp;amp; inside entity values). This does stop classic “Billion Laughs” payloads.&lt;/p&gt;
&lt;p&gt;However, it doesn’t stop a much simpler variant.&lt;/p&gt;
&lt;p&gt;If you define one large entity that contains only raw text (no &amp;amp; characters) and then reference it many times, the parser will happily expand it every time. There is no limit on how large the expanded result can become, or how many replacements are allowed.&lt;/p&gt;
&lt;p&gt;The problem is in `replaceEntitiesValue()` inside `OrderedObjParser.js`. It repeatedly runs `val.replace()` in a loop, without any checks on total output size or execution cost. As the entity grows or the number of references increases, parsing time explodes.&lt;/p&gt;
&lt;p&gt;Relevant code:&lt;/p&gt;
&lt;p&gt;`DocTypeReader.js` (lines 28–33): entity registration only checks for &amp;amp;&lt;/p&gt;
&lt;p&gt;`OrderedObjParser.js` (lines 439–458): entity replacement loop with no limits&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```js
const { XMLParser } = require(&amp;#39;fast-xml-parser&amp;#39;);&lt;/p&gt;
&lt;p&gt;const entity = &amp;#39;A&amp;#39;.repeat(1000);
const refs = &amp;#39;&amp;amp;big;&amp;#39;.repeat(100);
const xml = `&amp;lt;!DOCTYPE foo [&amp;lt;!ENTITY big &amp;#34;${entity}&amp;#34;&amp;gt;]&amp;gt;&amp;lt;root&amp;gt;${refs}&amp;lt;/root&amp;gt;`;&lt;/p&gt;
&lt;p&gt;console.time(&amp;#39;parse&amp;#39;);
new XMLParser().parse(xml); // ~4–8 se…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jmr7-xgp7-cmfj</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10236-1 — heroic-games-launcher-2.20.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10236-1</link>
      <description>&lt;p&gt;heroic-games-launcher-2.20.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;heroic-games-launcher-2.20.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10236-1</guid>
    </item>
    <item>
      <title>RHSA-2026:40984 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.20.15 security, enhancement &amp; bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:40984</link>
      <description>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-forge: node-forge ASN.1 Unbounded Recursion webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior ajv: ReDoS via $data reference lodash: lodash: Arbitrary code execution via untrusted input in template imports @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: g…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications lodash: prototype pollution in _.unset and _.omit functions qs: qs: Denial of Service via improper input validation in array parsing node-forge: node-forge ASN.1 Unbounded Recursion webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior ajv: ReDoS via $data reference lodash: lodash: Arbitrary code execution via untrusted input in template imports @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: g…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:40984</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-26278</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-26278</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-webfont, Ubuntu:25.10: node-webfont, Ubuntu:26.04:LTS: node-webfont&lt;/p&gt;
&lt;p&gt;fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `processEntities: false` option.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-webfont, Ubuntu:25.10: node-webfont, Ubuntu:26.04:LTS: node-webfont&lt;/p&gt;
&lt;p&gt;fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `processEntities: false` option.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-26278</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0772 — IBM App Connect Enterprise (fast-xml-parser): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0772</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen oder Sicherheitsmaßnahmen zu umgehen, wodurch Cross-Site-Scripting-Angriffe ermöglicht werden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen oder Sicherheitsmaßnahmen zu umgehen, wodurch Cross-Site-Scripting-Angriffe ermöglicht werden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0772</guid>
    </item>
  </channel>
</rss>
