<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:34:07 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10860</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10860</link>
      <description>bdu:2026-10860</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10860</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0500 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</link>
      <description>certfr-2026-avi-0500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BE61221 — Security fixes for CVE-2025-62718, CVE-2025-69873, CVE-2026-29045, CVE-2026-29085, CVE-2026-29086, CVE-2026-29087, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the opensearch-dashboards-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opensearch-dashboards-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the opensearch-dashboards-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-be61221</guid>
    </item>
    <item>
      <title>EUVD-2026-292982</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292982</link>
      <description>EUVD-2026-292982</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292982</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41239</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41239</link>
      <description>&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41239</guid>
    </item>
    <item>
      <title>GHSA-crv5-9vww-q3g8 — DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-crv5-9vww-q3g8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dompurify&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;| Field | Value |
|:------|:------|
| **Severity** | Medium |
| **Affected** | DOMPurify `main` at [`883ac15`](https://github.com/cure53/DOMPurify/tree/883ac15d47f907cb1a3b5a152fe90c4d8c10f9e6), introduced in v1.0.10 ([`7fc196db`](https://github.com/cure53/DOMPurify/commit/7fc196db0b42a0c360262dba0cc39c9c91bfe1ec)) |&lt;/p&gt;
&lt;p&gt;`SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;DOMPurify strips template expressions in two passes:&lt;/p&gt;
&lt;p&gt;1. **Per-node** — each text node is checked during the tree walk ([`purify.ts:1179-1191`](https://github.com/cure53/DOMPurify/blob/883ac15d47f907cb1a3b5a152fe90c4d8c10f9e6/src/purify.ts#L1179-L1191)):&lt;/p&gt;
&lt;p&gt;```js
// pass #1: runs on every text node during tree walk
if (SAFE_FOR_TEMPLATES &amp;amp;&amp;amp; currentNode.nodeType === NODE_TYPE.text) {
  content = currentNode.textContent;
  content = content.replace(MUSTACHE_EXPR, &amp;#39; &amp;#39;);  // {{...}} -&amp;gt; &amp;#39; &amp;#39;
  content = content.replace(ERB_EXPR, &amp;#39; &amp;#39;);        // &amp;lt;%...%&amp;gt; -&amp;gt; &amp;#39; &amp;#39;
  content = content.replace(TMPLIT_EXPR, &amp;#39; &amp;#39;);      // ${...  -&amp;gt; &amp;#39; &amp;#39;
  currentNode.textContent = content;
}
```&lt;/p&gt;
&lt;p&gt;2. **Final string scrub** — after serialization, the full HTML string is scrubbed again ([`purify.ts:1679-1683`](https://github.com/cure53/DOMPurify/blob/883ac15d47f907cb1a3b5a152fe90c4d8c10f9e6/src/purify.ts#L1679-L1683)). This is the safety net that catches expr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dompurify&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;| Field | Value |
|:------|:------|
| **Severity** | Medium |
| **Affected** | DOMPurify `main` at [`883ac15`](https://github.com/cure53/DOMPurify/tree/883ac15d47f907cb1a3b5a152fe90c4d8c10f9e6), introduced in v1.0.10 ([`7fc196db`](https://github.com/cure53/DOMPurify/commit/7fc196db0b42a0c360262dba0cc39c9c91bfe1ec)) |&lt;/p&gt;
&lt;p&gt;`SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;DOMPurify strips template expressions in two passes:&lt;/p&gt;
&lt;p&gt;1. **Per-node** — each text node is checked during the tree walk ([`purify.ts:1179-1191`](https://github.com/cure53/DOMPurify/blob/883ac15d47f907cb1a3b5a152fe90c4d8c10f9e6/src/purify.ts#L1179-L1191)):&lt;/p&gt;
&lt;p&gt;```js
// pass #1: runs on every text node during tree walk
if (SAFE_FOR_TEMPLATES &amp;amp;&amp;amp; currentNode.nodeType === NODE_TYPE.text) {
  content = currentNode.textContent;
  content = content.replace(MUSTACHE_EXPR, &amp;#39; &amp;#39;);  // {{...}} -&amp;gt; &amp;#39; &amp;#39;
  content = content.replace(ERB_EXPR, &amp;#39; &amp;#39;);        // &amp;lt;%...%&amp;gt; -&amp;gt; &amp;#39; &amp;#39;
  content = content.replace(TMPLIT_EXPR, &amp;#39; &amp;#39;);      // ${...  -&amp;gt; &amp;#39; &amp;#39;
  currentNode.textContent = content;
}
```&lt;/p&gt;
&lt;p&gt;2. **Final string scrub** — after serialization, the full HTML string is scrubbed again ([`purify.ts:1679-1683`](https://github.com/cure53/DOMPurify/blob/883ac15d47f907cb1a3b5a152fe90c4d8c10f9e6/src/purify.ts#L1679-L1683)). This is the safety net that catches expr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-crv5-9vww-q3g8</guid>
    </item>
    <item>
      <title>NCSC-2026-0375 — Kwetsbaarheden verholpen in Oracle Communications</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0375</link>
      <description>NCSC-2026-0375</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0375</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-41239</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41239</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify, Ubuntu:25.10: node-dompurify, Ubuntu:26.04:LTS: node-dompurify&lt;/p&gt;
&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify, Ubuntu:25.10: node-dompurify, Ubuntu:26.04:LTS: node-dompurify&lt;/p&gt;
&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS via template-evaluating frameworks like Vue 2. Version 3.4.0 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41239</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1407 — IBM App Connect Enterprise Certified Container: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise Certified Container ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1407</guid>
    </item>
  </channel>
</rss>
