<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:30:46 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>EUVD-2026-366121</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366121</link>
      <description>EUVD-2026-366121</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366121</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44990</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44990</link>
      <description>&lt;p&gt;ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: &amp;#39;discard&amp;#39;` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: &amp;#39;discard&amp;#39;` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44990</guid>
    </item>
    <item>
      <title>GHSA-rpr9-rxv7-x643 — Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rpr9-rxv7-x643</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sanitize-html&lt;/p&gt;
&lt;p&gt;### Summary
Under the default configuration, `sanitize-html` can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: &amp;#39;discard&amp;#39;` path and can lead to stored XSS in applications that render sanitized output back to users.&lt;/p&gt;
&lt;p&gt;### Details
In `sanitize-html@2.17.3`, the default `nonTextTags` list includes only `script`, `style`, `textarea`, and `option` in `index.js` lines 138-142. That means disallowed `xmp` tags are not treated as &amp;#34;drop the entire contents&amp;#34; tags.&lt;/p&gt;
&lt;p&gt;Later, in the `ontext` handler at `index.js` lines 569-577, the code special-cases `textarea` and `xmp` and appends their text content directly to the output without escaping:&lt;/p&gt;
&lt;p&gt;```js
} else if ((options.disallowedTagsMode === &amp;#39;discard&amp;#39; || options.disallowedTagsMode === &amp;#39;completelyDiscard&amp;#39;) &amp;amp;&amp;amp; (tag === &amp;#39;textarea&amp;#39; || tag === &amp;#39;xmp&amp;#39;)) {
  result += text;
}
```&lt;/p&gt;
&lt;p&gt;Because `htmlparser2` treats `xmp` as a raw-text element, markup inside `xmp` is parsed as text on input but becomes live markup again once it is appended unescaped to the sanitized output.&lt;/p&gt;
&lt;p&gt;This creates a default sanitizer bypass. For example, a disallowed `&amp;lt;xmp&amp;gt;` wrapper can be used to smuggle `&amp;lt;script&amp;gt;` or event-handler payloads through sanitization.&lt;/p&gt;
&lt;p&gt;The README also appears to contradict the implementation. In the &amp;#34;Discarding the entire contents of a disallowed tag&amp;#34; section, the documented exception list names only `style`, `script`, `textarea`, and `option…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sanitize-html&lt;/p&gt;
&lt;p&gt;### Summary
Under the default configuration, `sanitize-html` can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: &amp;#39;discard&amp;#39;` path and can lead to stored XSS in applications that render sanitized output back to users.&lt;/p&gt;
&lt;p&gt;### Details
In `sanitize-html@2.17.3`, the default `nonTextTags` list includes only `script`, `style`, `textarea`, and `option` in `index.js` lines 138-142. That means disallowed `xmp` tags are not treated as &amp;#34;drop the entire contents&amp;#34; tags.&lt;/p&gt;
&lt;p&gt;Later, in the `ontext` handler at `index.js` lines 569-577, the code special-cases `textarea` and `xmp` and appends their text content directly to the output without escaping:&lt;/p&gt;
&lt;p&gt;```js
} else if ((options.disallowedTagsMode === &amp;#39;discard&amp;#39; || options.disallowedTagsMode === &amp;#39;completelyDiscard&amp;#39;) &amp;amp;&amp;amp; (tag === &amp;#39;textarea&amp;#39; || tag === &amp;#39;xmp&amp;#39;)) {
  result += text;
}
```&lt;/p&gt;
&lt;p&gt;Because `htmlparser2` treats `xmp` as a raw-text element, markup inside `xmp` is parsed as text on input but becomes live markup again once it is appended unescaped to the sanitized output.&lt;/p&gt;
&lt;p&gt;This creates a default sanitizer bypass. For example, a disallowed `&amp;lt;xmp&amp;gt;` wrapper can be used to smuggle `&amp;lt;script&amp;gt;` or event-handler payloads through sanitization.&lt;/p&gt;
&lt;p&gt;The README also appears to contradict the implementation. In the &amp;#34;Discarding the entire contents of a disallowed tag&amp;#34; section, the documented exception list names only `style`, `script`, `textarea`, and `option…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rpr9-rxv7-x643</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11436-1 — golang-github-prometheus-prometheus-3.13.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11436-1</link>
      <description>&lt;p&gt;golang-github-prometheus-prometheus-3.13.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang-github-prometheus-prometheus-3.13.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11436-1</guid>
    </item>
    <item>
      <title>RHSA-2026:36882 — Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.14.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:36882</link>
      <description>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions database/sql: Postgres Scan Race Condition Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects angular: Angular: Cross-site scripting vulnerability in Template Compiler axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/russellhaering/goxmldsig: goxmlsig: Integrity bypass due to incorrect XML Digital Signature validation via loop variable capture issue axios: Axios: Remote Code Execution via Prototype Pollution escalation OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions database/sql: Postgres Scan Race Condition Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects angular: Angular: Cross-site scripting vulnerability in Template Compiler axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/russellhaering/goxmldsig: goxmlsig: Integrity bypass due to incorrect XML Digital Signature validation via loop variable capture issue axios: Axios: Remote Code Execution via Prototype Pollution escalation OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:36882</guid>
    </item>
  </channel>
</rss>
