<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:43:24 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AG43501 — Security fixes in sqlpad 7.5.7-r2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ag43501</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: sqlpad&lt;/p&gt;
&lt;p&gt;Package sqlpad version 7.5.7-r2 fixes 26 vulnerabilities: ghsa-2v35-w6hq-6mfw, ghsa-f6ww-3ggp-fr8h, ghsa-wh4c-j3r5-mjhp, ghsa-x6wf-f3px-wcqx, ghsa-j759-j44w-7fr8...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: sqlpad&lt;/p&gt;
&lt;p&gt;Package sqlpad version 7.5.7-r2 fixes 26 vulnerabilities: ghsa-2v35-w6hq-6mfw, ghsa-f6ww-3ggp-fr8h, ghsa-wh4c-j3r5-mjhp, ghsa-x6wf-f3px-wcqx, ghsa-j759-j44w-7fr8...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ag43501</guid>
    </item>
    <item>
      <title>EUVD-2026-361080</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361080</link>
      <description>EUVD-2026-361080</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361080</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41672</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41672</link>
      <description>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41672</guid>
    </item>
    <item>
      <title>GHSA-j759-j44w-7fr8 — xmldom has XML node injection through unvalidated comment serialization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j759-j44w-7fr8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The issue is in the DOM construction and serialization flow for comment nodes.&lt;/p&gt;
&lt;p&gt;When `createComment(data)` is called, the supplied string is stored as comment data through the generic character-data handling path. That content is kept as-is. Later, when the document is serialized, the serializer writes comment nodes by concatenating the XML comment delimiters with the stored `node.data` value directly.&lt;/p&gt;
&lt;p&gt;That behavior is unsafe because XML comments are a syntax-sensitive context. If attacker-controlled input contains a sequence that closes the comment, the serializer does not preserve it as literal comment text. Instead, it emits output where the remainder of the payload is treated as live XML markup.&lt;/p&gt;
&lt;p&gt;This is a real injection bug, not a formatting issue. The serializer already applies context-aware handling in other places, such as escaping text nodes and rewriting unsafe CDATA terminators. Comment content does not receive equivalent treatment. Because of that gap, untrusted data can break out of the comment boundary and modify the structure of the final XML document.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```js
const { DOMImplementation, DOMParser, XMLSerializer } = require(&amp;#39;@xmldom/xmldom&amp;#39;);&lt;/p&gt;
&lt;p&gt;const doc = new DOMI…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The issue is in the DOM construction and serialization flow for comment nodes.&lt;/p&gt;
&lt;p&gt;When `createComment(data)` is called, the supplied string is stored as comment data through the generic character-data handling path. That content is kept as-is. Later, when the document is serialized, the serializer writes comment nodes by concatenating the XML comment delimiters with the stored `node.data` value directly.&lt;/p&gt;
&lt;p&gt;That behavior is unsafe because XML comments are a syntax-sensitive context. If attacker-controlled input contains a sequence that closes the comment, the serializer does not preserve it as literal comment text. Instead, it emits output where the remainder of the payload is treated as live XML markup.&lt;/p&gt;
&lt;p&gt;This is a real injection bug, not a formatting issue. The serializer already applies context-aware handling in other places, such as escaping text nodes and rewriting unsafe CDATA terminators. Comment content does not receive equivalent treatment. Because of that gap, untrusted data can break out of the comment boundary and modify the structure of the final XML document.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;```js
const { DOMImplementation, DOMParser, XMLSerializer } = require(&amp;#39;@xmldom/xmldom&amp;#39;);&lt;/p&gt;
&lt;p&gt;const doc = new DOMI…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j759-j44w-7fr8</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-41672 — xmldom: XML node injection through unvalidated comment serialization</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-41672</link>
      <description>msrc_CVE-2026-41672</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-41672</guid>
    </item>
    <item>
      <title>RHSA-2026:26234 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.5 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:26234</link>
      <description>&lt;p&gt;fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri: fast-uri: URI authority bypass due to improper delimiter handling vm2: vm2: Arbitrary code execution via sandbox breakout through inspect function crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields xmldom: @xmldom/xmldom: xmldom: Arbitrary XML Node Injection @xmldom/xmldom: xmldom: xmldom: Denial of Service via deeply nested XML documents xmldom: xmldom: Arbitrary XML markup injection xmldom: xmldom: Arbitrary XML node injection via crafted processing instructions protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri: fast-uri: URI authority bypass due to improper delimiter handling vm2: vm2: Arbitrary code execution via sandbox breakout through inspect function crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields xmldom: @xmldom/xmldom: xmldom: Arbitrary XML Node Injection @xmldom/xmldom: xmldom: xmldom: Denial of Service via deeply nested XML documents xmldom: xmldom: Arbitrary XML markup injection xmldom: xmldom: Arbitrary XML node injection via crafted processing instructions protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:26234</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-41672</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41672</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:25.10: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:25.10: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment-breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41672</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1833 — IBM App Connect Enterprise (basic-ftp, xmldom): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1833</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1833</guid>
    </item>
  </channel>
</rss>
