<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:05:48 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09394</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09394</link>
      <description>bdu:2026-09394</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09394</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0581 — De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0581</link>
      <description>certfr-2026-avi-0581</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0581</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD27625 — Security fixes for CVE-2022-25881, CVE-2022-33987, CVE-2025-25285, CVE-2025-62718, CVE-2025-69873, CVE-2026-21637, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</guid>
    </item>
    <item>
      <title>EUVD-2026-278137</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278137</link>
      <description>EUVD-2026-278137</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278137</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33916</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33916</link>
      <description>&lt;p&gt;Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS. Version 4.7.9 fixes the issue. Some workarounds are available. Apply `Object.freeze(Object.prototype)` early in application startup to prevent prototype  pollution. Note: this may break other libraries, and/or use the Handlebars runtime-only build (`handlebars/runtime`), which does not compile templates  and reduces the attack surface.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS. Version 4.7.9 fixes the issue. Some workarounds are available. Apply `Object.freeze(Object.prototype)` early in application startup to prevent prototype  pollution. Note: this may break other libraries, and/or use the Handlebars runtime-only build (`handlebars/runtime`), which does not compile templates  and reduces the attack surface.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33916</guid>
    </item>
    <item>
      <title>GHSA-2qvq-rjwj-gvw9 — Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2qvq-rjwj-gvw9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: handlebars&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered **without HTML escaping**, resulting in reflected or stored XSS.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;The root cause is in `lib/handlebars/runtime.js` inside `resolvePartial()` and `invokePartial()`:&lt;/p&gt;
&lt;p&gt;```javascript
// Vulnerable: plain bracket access traverses Object.prototype
partial = options.partials[options.name];
```&lt;/p&gt;
&lt;p&gt;`hasOwnProperty` is never checked, so if `Object.prototype` has been seeded with a key whose name matches a partial reference in the template (e.g. `widget`), the lookup succeeds and the polluted string is returned. The runtime emits a prototype-access warning, but the partial is still resolved and its content is inserted into the rendered output unescaped. This contradicts the documented security model and is distinct from CVE-2021-23369 and CVE-2021-23383, which addressed data property access rather than partial template resolution.&lt;/p&gt;
&lt;p&gt;**Prerequisites for exploitation:**
1. The target application must be vulnerable to prototype pollution (e.g. via `qs`, `minimist`, or
   any querystring/JSON merge sink).
2. The attacker must know or guess the name of a partial reference used in a template.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```javascript…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: handlebars&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered **without HTML escaping**, resulting in reflected or stored XSS.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;The root cause is in `lib/handlebars/runtime.js` inside `resolvePartial()` and `invokePartial()`:&lt;/p&gt;
&lt;p&gt;```javascript
// Vulnerable: plain bracket access traverses Object.prototype
partial = options.partials[options.name];
```&lt;/p&gt;
&lt;p&gt;`hasOwnProperty` is never checked, so if `Object.prototype` has been seeded with a key whose name matches a partial reference in the template (e.g. `widget`), the lookup succeeds and the polluted string is returned. The runtime emits a prototype-access warning, but the partial is still resolved and its content is inserted into the rendered output unescaped. This contradicts the documented security model and is distinct from CVE-2021-23369 and CVE-2021-23383, which addressed data property access rather than partial template resolution.&lt;/p&gt;
&lt;p&gt;**Prerequisites for exploitation:**
1. The target application must be vulnerable to prototype pollution (e.g. via `qs`, `minimist`, or
   any querystring/JSON merge sink).
2. The attacker must know or guess the name of a partial reference used in a template.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```javascript…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2qvq-rjwj-gvw9</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-33916 — Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-33916</link>
      <description>msrc_CVE-2026-33916</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-33916</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-33916</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33916</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-handlebars, Ubuntu:20.04:LTS: node-handlebars, Ubuntu:22.04:LTS: node-handlebars, Ubuntu:24.04:LTS: node-handlebars, Ubuntu:25.10: node-handlebars, Ubuntu:26.04:LTS: node-handlebars&lt;/p&gt;
&lt;p&gt;Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS. Version 4.7.9 fixes the issue. Some workarounds are available. Apply `Object.freeze(Object.prototype)` early in application startup to prevent prototype  pollution. Note: this may break other libraries, and/or use the Handlebars runtime-only build (`handlebars/runtime`), which does not compile templates  and reduces the attack surface.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-handlebars, Ubuntu:20.04:LTS: node-handlebars, Ubuntu:22.04:LTS: node-handlebars, Ubuntu:24.04:LTS: node-handlebars, Ubuntu:25.10: node-handlebars, Ubuntu:26.04:LTS: node-handlebars&lt;/p&gt;
&lt;p&gt;Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prototype` has been polluted with a string value whose key matches a partial reference in a template, the polluted string is used as the partial body and rendered without HTML escaping, resulting in reflected or stored XSS. Version 4.7.9 fixes the issue. Some workarounds are available. Apply `Object.freeze(Object.prototype)` early in application startup to prevent prototype  pollution. Note: this may break other libraries, and/or use the Handlebars runtime-only build (`handlebars/runtime`), which does not compile templates  and reduces the attack surface.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33916</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1407 — IBM App Connect Enterprise Certified Container: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</guid>
    </item>
  </channel>
</rss>
