<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:09:47 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-319278</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319278</link>
      <description>EUVD-2026-319278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319278</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44665</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44665</link>
      <description>&lt;p&gt;fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML. This vulnerability is fixed in 1.1.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML. This vulnerability is fixed in 1.1.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44665</guid>
    </item>
    <item>
      <title>GHSA-5wm8-gmm8-39j9 — fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5wm8-gmm8-39j9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-xml-builder&lt;/p&gt;
&lt;p&gt;# Summary
When an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML.&lt;/p&gt;
&lt;p&gt;## Detail&lt;/p&gt;
&lt;p&gt;Malicious Input
```
{
      a: {
        &amp;#34;@_attr&amp;#34;: &amp;#39;&amp;#34; onClick=&amp;#34;alert(1)&amp;#39;
      }
}
```&lt;/p&gt;
&lt;p&gt;Output
```xml
&amp;lt;a attr=&amp;#34;&amp;#34; onClick=&amp;#34;alert(1)&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;
```&lt;/p&gt;
&lt;p&gt;### Workarounds
If you&amp;#39;re not ignoring attributes then keep processEntities flag true.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: fast-xml-builder&lt;/p&gt;
&lt;p&gt;# Summary
When an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML.&lt;/p&gt;
&lt;p&gt;## Detail&lt;/p&gt;
&lt;p&gt;Malicious Input
```
{
      a: {
        &amp;#34;@_attr&amp;#34;: &amp;#39;&amp;#34; onClick=&amp;#34;alert(1)&amp;#39;
      }
}
```&lt;/p&gt;
&lt;p&gt;Output
```xml
&amp;lt;a attr=&amp;#34;&amp;#34; onClick=&amp;#34;alert(1)&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;
```&lt;/p&gt;
&lt;p&gt;### Workarounds
If you&amp;#39;re not ignoring attributes then keep processEntities flag true.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5wm8-gmm8-39j9</guid>
    </item>
    <item>
      <title>RHSA-2026:56928 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.2 security, enhancement &amp; bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:56928</link>
      <description>&lt;p&gt;fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri: fast-uri: URI authority bypass due to improper delimiter handling postcss-selector-parser: Postcss: Denial of Service via uncontrolled recursion in AST Serialization picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern react-router: React Router: Open redirect vulnerability via specially crafted URLs postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags fast-xml-parser: fast-xml-parser: XML injection via improper escaping of comment and CDATA sequences uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input fast-xml-builder: fast-xml-builder: Attribute injection leading to information disclosure or content manipulation brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies fast-uri: fast-uri: URI authority bypass due to improper delimiter handling postcss-selector-parser: Postcss: Denial of Service via uncontrolled recursion in AST Serialization picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern react-router: React Router: Open redirect vulnerability via specially crafted URLs postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags fast-xml-parser: fast-xml-parser: XML injection via improper escaping of comment and CDATA sequences uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input fast-xml-builder: fast-xml-builder: Attribute injection leading to information disclosure or content manipulation brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:56928</guid>
    </item>
  </channel>
</rss>
