<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:20:38 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AG43501 — Security fixes in sqlpad 7.5.7-r2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ag43501</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: sqlpad&lt;/p&gt;
&lt;p&gt;Package sqlpad version 7.5.7-r2 fixes 26 vulnerabilities: ghsa-2v35-w6hq-6mfw, ghsa-f6ww-3ggp-fr8h, ghsa-wh4c-j3r5-mjhp, ghsa-x6wf-f3px-wcqx, ghsa-j759-j44w-7fr8...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: sqlpad&lt;/p&gt;
&lt;p&gt;Package sqlpad version 7.5.7-r2 fixes 26 vulnerabilities: ghsa-2v35-w6hq-6mfw, ghsa-f6ww-3ggp-fr8h, ghsa-wh4c-j3r5-mjhp, ghsa-x6wf-f3px-wcqx, ghsa-j759-j44w-7fr8...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ag43501</guid>
    </item>
    <item>
      <title>EUVD-2026-366103</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366103</link>
      <description>EUVD-2026-366103</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366103</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41674</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41674</link>
      <description>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41674</guid>
    </item>
    <item>
      <title>GHSA-f6ww-3ggp-fr8h — xmldom has XML injection through unvalidated DocumentType serialization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f6ww-3ggp-fr8h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The package serializes `DocumentType` node fields (`internalSubset`, `publicId`, `systemId`) verbatim
without any escaping or validation. When these fields are set programmatically to attacker-controlled
strings, `XMLSerializer.serializeToString` can produce output where the DOCTYPE declaration is
terminated early and arbitrary markup appears outside it.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`DOMImplementation.createDocumentType(qualifiedName, publicId, systemId, internalSubset)` validates
only `qualifiedName` against the XML QName production. The remaining three arguments are stored
as-is with no validation.&lt;/p&gt;
&lt;p&gt;The XMLSerializer emits `DocumentType` nodes as:&lt;/p&gt;
&lt;p&gt;```
&amp;lt;!DOCTYPE name[ PUBLIC pubid][ SYSTEM sysid][ [internalSubset]]&amp;gt;
```&lt;/p&gt;
&lt;p&gt;All fields are pushed into the output buffer verbatim — no escaping, no quoting added.&lt;/p&gt;
&lt;p&gt;**`internalSubset` injection:** The serializer wraps `internalSubset` with ` [` and `]`. A value
containing `]&amp;gt;` closes the internal subset and the DOCTYPE declaration at the injection point.
Any content after `]&amp;gt;` in `internalSubset` appears outside the DOCTYPE in the serialized output as
raw XML markup. Reported by @TharVid (GHSA-f6ww-3ggp-fr8h). Affected: `@xmldom/xmldom` ≥ 0.9.0
via `createDocumentType` API; 0.8.x only via direct property write.&lt;/p&gt;
&lt;p&gt;**`publicId` injection:** The serializer emits `publicId` verbatim after `PUBLIC` with no
quoting added. A value containing an injected system identifier (e.g.,
`&amp;#34;pubid&amp;#34; SYSTEM &amp;#34;evil&amp;#34;`) breaks the intended quoting context,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The package serializes `DocumentType` node fields (`internalSubset`, `publicId`, `systemId`) verbatim
without any escaping or validation. When these fields are set programmatically to attacker-controlled
strings, `XMLSerializer.serializeToString` can produce output where the DOCTYPE declaration is
terminated early and arbitrary markup appears outside it.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`DOMImplementation.createDocumentType(qualifiedName, publicId, systemId, internalSubset)` validates
only `qualifiedName` against the XML QName production. The remaining three arguments are stored
as-is with no validation.&lt;/p&gt;
&lt;p&gt;The XMLSerializer emits `DocumentType` nodes as:&lt;/p&gt;
&lt;p&gt;```
&amp;lt;!DOCTYPE name[ PUBLIC pubid][ SYSTEM sysid][ [internalSubset]]&amp;gt;
```&lt;/p&gt;
&lt;p&gt;All fields are pushed into the output buffer verbatim — no escaping, no quoting added.&lt;/p&gt;
&lt;p&gt;**`internalSubset` injection:** The serializer wraps `internalSubset` with ` [` and `]`. A value
containing `]&amp;gt;` closes the internal subset and the DOCTYPE declaration at the injection point.
Any content after `]&amp;gt;` in `internalSubset` appears outside the DOCTYPE in the serialized output as
raw XML markup. Reported by @TharVid (GHSA-f6ww-3ggp-fr8h). Affected: `@xmldom/xmldom` ≥ 0.9.0
via `createDocumentType` API; 0.8.x only via direct property write.&lt;/p&gt;
&lt;p&gt;**`publicId` injection:** The serializer emits `publicId` verbatim after `PUBLIC` with no
quoting added. A value containing an injected system identifier (e.g.,
`&amp;#34;pubid&amp;#34; SYSTEM &amp;#34;evil&amp;#34;`) breaks the intended quoting context,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f6ww-3ggp-fr8h</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-41674 — xmldom: XML injection through unvalidated DocumentType serialization</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-41674</link>
      <description>msrc_CVE-2026-41674</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-41674</guid>
    </item>
    <item>
      <title>RHSA-2026:20034 — Red Hat Security Advisory: OpenShift Container Platform 4.21.17 bug fix and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:20034</link>
      <description>&lt;p&gt;golang: archive/tar: Unbounded allocation when parsing GNU sparse map immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code xmldom: xmldom: Arbitrary XML markup injection&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: archive/tar: Unbounded allocation when parsing GNU sparse map immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code xmldom: xmldom: Arbitrary XML markup injection&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:20034</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-41674</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41674</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:25.10: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:25.10: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-41674</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1833 — IBM App Connect Enterprise (basic-ftp, xmldom): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1833</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Dateien zu manipulieren oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1833</guid>
    </item>
  </channel>
</rss>
