<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:12:05 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</link>
      <description>certfr-2026-avi-0667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD27625 — Security fixes for CVE-2022-25881, CVE-2022-33987, CVE-2025-25285, CVE-2025-62718, CVE-2025-69873, CVE-2026-21637, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</guid>
    </item>
    <item>
      <title>EUVD-2026-277417</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277417</link>
      <description>EUVD-2026-277417</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277417</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33349</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33349</link>
      <description>&lt;p&gt;fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a developer explicitly sets either limit to 0 — intending to disallow all entities or restrict entity size to zero bytes — the falsy nature of 0 in JavaScript causes the guard conditions to short-circuit, completely bypassing the limits. An attacker who can supply XML input to such an application can trigger unbounded entity expansion, leading to memory exhaustion and denial of service. This issue has been patched in version 5.5.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a developer explicitly sets either limit to 0 — intending to disallow all entities or restrict entity size to zero bytes — the falsy nature of 0 in JavaScript causes the guard conditions to short-circuit, completely bypassing the limits. An attacker who can supply XML input to such an application can trigger unbounded entity expansion, leading to memory exhaustion and denial of service. This issue has been patched in version 5.5.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33349</guid>
    </item>
    <item>
      <title>GHSA-jp2q-39xq-3w4g — Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jp2q-39xq-3w4g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-xml-parser&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `DocTypeReader` in fast-xml-parser uses JavaScript truthy checks to evaluate `maxEntityCount` and `maxEntitySize` configuration limits. When a developer explicitly sets either limit to `0` — intending to disallow all entities or restrict entity size to zero bytes — the falsy nature of `0` in JavaScript causes the guard conditions to short-circuit, completely bypassing the limits. An attacker who can supply XML input to such an application can trigger unbounded entity expansion, leading to memory exhaustion and denial of service.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `OptionsBuilder.js` correctly preserves a user-supplied value of `0` using nullish coalescing (`??`):&lt;/p&gt;
&lt;p&gt;```js
// src/xmlparser/OptionsBuilder.js:111
maxEntityCount: value.maxEntityCount ?? 100,
// src/xmlparser/OptionsBuilder.js:107
maxEntitySize: value.maxEntitySize ?? 10000,
```&lt;/p&gt;
&lt;p&gt;However, `DocTypeReader.js` uses truthy evaluation to check these limits. Because `0` is falsy in JavaScript, the entire guard expression short-circuits to `false`, and the limit is never enforced:&lt;/p&gt;
&lt;p&gt;```js
// src/xmlparser/DocTypeReader.js:30-32
if (this.options.enabled !== false &amp;amp;&amp;amp;
    this.options.maxEntityCount &amp;amp;&amp;amp;          // ← 0 is falsy, skips check
    entityCount &amp;gt;= this.options.maxEntityCount) {
    throw new Error(`Entity count ...`);
}
```&lt;/p&gt;
&lt;p&gt;```js
// src/xmlparser/DocTypeReader.js:128-130
if (this.options.enabled !== false &amp;amp;&amp;amp;
    this.options.maxEntitySize &amp;amp;&amp;amp;            // ← 0 is falsy, skips check
    entityValue.length &amp;gt; this.optio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-xml-parser&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `DocTypeReader` in fast-xml-parser uses JavaScript truthy checks to evaluate `maxEntityCount` and `maxEntitySize` configuration limits. When a developer explicitly sets either limit to `0` — intending to disallow all entities or restrict entity size to zero bytes — the falsy nature of `0` in JavaScript causes the guard conditions to short-circuit, completely bypassing the limits. An attacker who can supply XML input to such an application can trigger unbounded entity expansion, leading to memory exhaustion and denial of service.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `OptionsBuilder.js` correctly preserves a user-supplied value of `0` using nullish coalescing (`??`):&lt;/p&gt;
&lt;p&gt;```js
// src/xmlparser/OptionsBuilder.js:111
maxEntityCount: value.maxEntityCount ?? 100,
// src/xmlparser/OptionsBuilder.js:107
maxEntitySize: value.maxEntitySize ?? 10000,
```&lt;/p&gt;
&lt;p&gt;However, `DocTypeReader.js` uses truthy evaluation to check these limits. Because `0` is falsy in JavaScript, the entire guard expression short-circuits to `false`, and the limit is never enforced:&lt;/p&gt;
&lt;p&gt;```js
// src/xmlparser/DocTypeReader.js:30-32
if (this.options.enabled !== false &amp;amp;&amp;amp;
    this.options.maxEntityCount &amp;amp;&amp;amp;          // ← 0 is falsy, skips check
    entityCount &amp;gt;= this.options.maxEntityCount) {
    throw new Error(`Entity count ...`);
}
```&lt;/p&gt;
&lt;p&gt;```js
// src/xmlparser/DocTypeReader.js:128-130
if (this.options.enabled !== false &amp;amp;&amp;amp;
    this.options.maxEntitySize &amp;amp;&amp;amp;            // ← 0 is falsy, skips check
    entityValue.length &amp;gt; this.optio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jp2q-39xq-3w4g</guid>
    </item>
    <item>
      <title>RHSA-2026:24841 — Red Hat Security Advisory: Red Hat Developer Hub 1.10.0 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:24841</link>
      <description>&lt;p&gt;lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards undici: Undici: Denial of Service via excessive decompression steps Underscore.js: Underscore.js: Denial of Service via recursive data structures in flatten and isEqual functions yauzl: yauzl: Denial of Service vulnerability in zip file processing @backstage/plugin-auth-backend: @backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass fast-xml-parser: fast-xml-parser: Denial of Service via unbounded entity expansion due to incorrect configuration limit handling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards undici: Undici: Denial of Service via excessive decompression steps Underscore.js: Underscore.js: Denial of Service via recursive data structures in flatten and isEqual functions yauzl: yauzl: Denial of Service vulnerability in zip file processing @backstage/plugin-auth-backend: @backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass fast-xml-parser: fast-xml-parser: Denial of Service via unbounded entity expansion due to incorrect configuration limit handling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:24841</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-33349</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33349</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-webfont, Ubuntu:25.10: node-webfont, Ubuntu:26.04:LTS: node-webfont&lt;/p&gt;
&lt;p&gt;fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a developer explicitly sets either limit to 0 — intending to disallow all entities or restrict entity size to zero bytes — the falsy nature of 0 in JavaScript causes the guard conditions to short-circuit, completely bypassing the limits. An attacker who can supply XML input to such an application can trigger unbounded entity expansion, leading to memory exhaustion and denial of service. This issue has been patched in version 5.5.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: node-webfont, Ubuntu:25.10: node-webfont, Ubuntu:26.04:LTS: node-webfont&lt;/p&gt;
&lt;p&gt;fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a developer explicitly sets either limit to 0 — intending to disallow all entities or restrict entity size to zero bytes — the falsy nature of 0 in JavaScript causes the guard conditions to short-circuit, completely bypassing the limits. An attacker who can supply XML input to such an application can trigger unbounded entity expansion, leading to memory exhaustion and denial of service. This issue has been patched in version 5.5.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33349</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1407 — IBM App Connect Enterprise Certified Container: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</guid>
    </item>
  </channel>
</rss>
