<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:51:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09337</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09337</link>
      <description>bdu:2026-09337</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09337</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0581 — De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0581</link>
      <description>certfr-2026-avi-0581</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0581</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-QN62418 — Security fixes in opensearch-dashboards-fips 3.5.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-qn62418</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Package opensearch-dashboards-fips version 3.5.0-r0 fixes 30 vulnerabilities: ghsa-jg4p-7fhp-p32p, ghsa-2w6w-674q-4c4q, ghsa-9cx6-37pm-9jff, ghsa-r5fr-rjxr-66jc, ghsa-3v7f-55p6-f55p...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Package opensearch-dashboards-fips version 3.5.0-r0 fixes 30 vulnerabilities: ghsa-jg4p-7fhp-p32p, ghsa-2w6w-674q-4c4q, ghsa-9cx6-37pm-9jff, ghsa-r5fr-rjxr-66jc, ghsa-3v7f-55p6-f55p...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-qn62418</guid>
    </item>
    <item>
      <title>EUVD-2026-366767</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366767</link>
      <description>EUVD-2026-366767</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366767</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33941</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33941</link>
      <description>&lt;p&gt;Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser. Version 4.7.9 fixes the issue. Some workarounds are available. First, validate all CLI inputs before invoking the precompiler. Reject filenames and option values  that contain characters with JavaScript string-escaping significance (`&amp;#34;`, `&amp;#39;`, `;`, etc.). Second, use a fixed, trusted namespace string passed via a configuration file rather than  command-line arguments in automated pipelines. Third, run the precompiler in a sandboxed environment (container with no write access to sensitive  paths) to limit the impact of successful exploitation. Fourth, audit template filenames in any repository or package that is consumed by an automated  build pipeline.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser. Version 4.7.9 fixes the issue. Some workarounds are available. First, validate all CLI inputs before invoking the precompiler. Reject filenames and option values  that contain characters with JavaScript string-escaping significance (`&amp;#34;`, `&amp;#39;`, `;`, etc.). Second, use a fixed, trusted namespace string passed via a configuration file rather than  command-line arguments in automated pipelines. Third, run the precompiler in a sandboxed environment (container with no write access to sensitive  paths) to limit the impact of successful exploitation. Fourth, audit template filenames in any repository or package that is consumed by an automated  build pipeline.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33941</guid>
    </item>
    <item>
      <title>GHSA-xjpj-3mr7-gcpf — Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xjpj-3mr7-gcpf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: handlebars&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;`lib/precompiler.js` generates JavaScript source by string-interpolating several values directly into the output. Four distinct injection points exist:&lt;/p&gt;
&lt;p&gt;### 1. Template name injection&lt;/p&gt;
&lt;p&gt;```javascript
// Vulnerable code pattern
output += &amp;#39;templates[&amp;#34;&amp;#39; + template.name + &amp;#39;&amp;#34;] = template(...)&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;`template.name` is derived from the file system path. A filename containing `&amp;#34;` or `&amp;#39;];` breaks out of the string literal and injects arbitrary JavaScript.&lt;/p&gt;
&lt;p&gt;### 2. Namespace injection (`-n` / `--namespace`)&lt;/p&gt;
&lt;p&gt;```javascript
// Vulnerable code pattern
output += &amp;#39;var templates = &amp;#39; + opts.namespace + &amp;#39; = &amp;#39; + opts.namespace + &amp;#39; || {};&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;`opts.namespace` is emitted as raw JavaScript. Anything after a `;` in the value becomes an additional JavaScript statement.&lt;/p&gt;
&lt;p&gt;### 3. CommonJS path injection (`-c` / `--commonjs`)&lt;/p&gt;
&lt;p&gt;```javascript
// Vulnerable code pattern
output += &amp;#39;var Handlebars = require(&amp;#34;&amp;#39; + opts.commonjs + &amp;#39;&amp;#34;);&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;`opts.commonjs` is interpolated inside double quotes with no escaping, allowing `&amp;#34;` to close the string and inject further code.&lt;/p&gt;
&lt;p&gt;### 4. AM…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: handlebars&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;`lib/precompiler.js` generates JavaScript source by string-interpolating several values directly into the output. Four distinct injection points exist:&lt;/p&gt;
&lt;p&gt;### 1. Template name injection&lt;/p&gt;
&lt;p&gt;```javascript
// Vulnerable code pattern
output += &amp;#39;templates[&amp;#34;&amp;#39; + template.name + &amp;#39;&amp;#34;] = template(...)&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;`template.name` is derived from the file system path. A filename containing `&amp;#34;` or `&amp;#39;];` breaks out of the string literal and injects arbitrary JavaScript.&lt;/p&gt;
&lt;p&gt;### 2. Namespace injection (`-n` / `--namespace`)&lt;/p&gt;
&lt;p&gt;```javascript
// Vulnerable code pattern
output += &amp;#39;var templates = &amp;#39; + opts.namespace + &amp;#39; = &amp;#39; + opts.namespace + &amp;#39; || {};&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;`opts.namespace` is emitted as raw JavaScript. Anything after a `;` in the value becomes an additional JavaScript statement.&lt;/p&gt;
&lt;p&gt;### 3. CommonJS path injection (`-c` / `--commonjs`)&lt;/p&gt;
&lt;p&gt;```javascript
// Vulnerable code pattern
output += &amp;#39;var Handlebars = require(&amp;#34;&amp;#39; + opts.commonjs + &amp;#39;&amp;#34;);&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;`opts.commonjs` is interpolated inside double quotes with no escaping, allowing `&amp;#34;` to close the string and inject further code.&lt;/p&gt;
&lt;p&gt;### 4. AM…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xjpj-3mr7-gcpf</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-33941 — Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-33941</link>
      <description>msrc_CVE-2026-33941</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-33941</guid>
    </item>
    <item>
      <title>RHSA-2026:10175 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.27.1 Release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10175</link>
      <description>&lt;p&gt;golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path net/url: Incorrect parsing of IPv6 host literals in net/url github.com/traefik/traefik: Traefik: Denial of Service due to incomplete TLS handshake crypto/x509: Incorrect enforcement of email constraints in crypto/x509 rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability github.com/traefik/traefik: Traefik: Information disclosure due to case-insensitive Connection header processing Traefik: github.com/traefik/traefik: Traefik: mTLS bypass allows unauthorized service access via fragmented ClientHello. github.com/traefik/traefik: Traefik: Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection @fastify/reply-from: @fastify/http-proxy: Fastify Reply From a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization org.eclipse.jetty/jetty-http: HTTP request smuggling via chunked extension quoted-string parsing lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions Spring Boot: Spring Boot: Authentication bypass via misconfigured Health Group additional path net/url: Incorrect parsing of IPv6 host literals in net/url github.com/traefik/traefik: Traefik: Denial of Service due to incomplete TLS handshake crypto/x509: Incorrect enforcement of email constraints in crypto/x509 rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability github.com/traefik/traefik: Traefik: Information disclosure due to case-insensitive Connection header processing Traefik: github.com/traefik/traefik: Traefik: mTLS bypass allows unauthorized service access via fragmented ClientHello. github.com/traefik/traefik: Traefik: Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection @fastify/reply-from: @fastify/http-proxy: Fastify Reply From a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10175</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-33941</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33941</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-handlebars, Ubuntu:20.04:LTS: node-handlebars, Ubuntu:22.04:LTS: node-handlebars, Ubuntu:24.04:LTS: node-handlebars, Ubuntu:25.10: node-handlebars, Ubuntu:26.04:LTS: node-handlebars&lt;/p&gt;
&lt;p&gt;Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser. Version 4.7.9 fixes the issue. Some workarounds are available. First, validate all CLI inputs before invoking the precompiler. Reject filenames and option values  that contain characters with JavaScript string-escaping significance (`&amp;#34;`, `&amp;#39;`, `;`, etc.). Second, use a fixed, trusted namespace string passed via a configuration file rather than command-line arguments in automated pipelines. Third, run the precompiler in a sandboxed environment (container with no write access to sensitive paths) to limit the impact of successful exploitation. Fourth, audit template filenames in any repository or package that is consumed by an automated  build pipeline.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: node-handlebars, Ubuntu:20.04:LTS: node-handlebars, Ubuntu:22.04:LTS: node-handlebars, Ubuntu:24.04:LTS: node-handlebars, Ubuntu:25.10: node-handlebars, Ubuntu:26.04:LTS: node-handlebars&lt;/p&gt;
&lt;p&gt;Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file names and several CLI options — directly into the JavaScript it emits, without any escaping or sanitization. An attacker who can influence template filenames or CLI arguments can inject arbitrary JavaScript that executes when the generated bundle is loaded in Node.js or a browser. Version 4.7.9 fixes the issue. Some workarounds are available. First, validate all CLI inputs before invoking the precompiler. Reject filenames and option values  that contain characters with JavaScript string-escaping significance (`&amp;#34;`, `&amp;#39;`, `;`, etc.). Second, use a fixed, trusted namespace string passed via a configuration file rather than command-line arguments in automated pipelines. Third, run the precompiler in a sandboxed environment (container with no write access to sensitive paths) to limit the impact of successful exploitation. Fourth, audit template filenames in any repository or package that is consumed by an automated  build pipeline.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33941</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1434 — IBM App Connect Enterprise Certified Container: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1434</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Programmcode auszuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Programmcode auszuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1434</guid>
    </item>
  </channel>
</rss>
