<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:03:44 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>EUVD-2026-341385</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341385</link>
      <description>EUVD-2026-341385</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341385</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45623</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45623</link>
      <description>&lt;p&gt;PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting JSON.parse SyntaxError message. The bug also yields a precise file-existence oracle and a controllable-read primitive that may be combined with large-file targets for DoS. The behaviour is triggered with PostCSS&amp;#39;s default options — no from, no map, no plugins required — and is therefore reachable from any pipeline that runs untrusted CSS through PostCSS (CMS themes, user-uploaded styles, browser-extension/userstyle processors, build pipelines for third-party packages, blog comment renderers, etc.). This issue has been fixed in version 8.5.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting JSON.parse SyntaxError message. The bug also yields a precise file-existence oracle and a controllable-read primitive that may be combined with large-file targets for DoS. The behaviour is triggered with PostCSS&amp;#39;s default options — no from, no map, no plugins required — and is therefore reachable from any pipeline that runs untrusted CSS through PostCSS (CMS themes, user-uploaded styles, browser-extension/userstyle processors, build pipelines for third-party packages, blog comment renderers, etc.). This issue has been fixed in version 8.5.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45623</guid>
    </item>
    <item>
      <title>GHSA-6g55-p6wh-862q — PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6g55-p6wh-862q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: postcss&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;PostCSS&amp;#39;s `PreviousMap` parses the `/*# sourceMappingURL=PATH */` comment from any CSS string passed to `process()` and dereferences `PATH` against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting `JSON.parse` `SyntaxError` message. The bug also yields a precise file-existence oracle and a controllable-read primitive that may be combined with large-file targets for DoS. The behaviour is triggered with PostCSS&amp;#39;s default options — no `from`, no `map`, no plugins required — and is therefore reachable from any pipeline that runs untrusted CSS through PostCSS (CMS themes, user-uploaded styles, browser-extension/userstyle processors, build pipelines for third-party packages, blog comment renderers, etc.).&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The dangerous chain lives in `lib/previous-map.js` and is wired into every `Input` construction at `lib/input.js:70-77`.&lt;/p&gt;
&lt;p&gt;`Input` constructor (`lib/input.js:70-77`):&lt;/p&gt;
&lt;p&gt;```js
if (pathAvailable &amp;amp;&amp;amp; sourceMapAvailable) {
  let map = new PreviousMap(this.css, opts)
  if (map.text) {
    this.map = map
    let file = map.consumer().file
    if (!this.file &amp;amp;&amp;amp; file) this.file = this.mapResolve(file)
  }
}
```&lt;/p&gt;
&lt;p&gt;`PreviousMap` constructor (`lib/previous-map.js:17-29`):&lt;/p&gt;
&lt;p&gt;```js
constructor(css, opts) {
  if (opts.map === false) return
  this.loadAnnotation(css)
  this.inline = this.start…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: postcss&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;PostCSS&amp;#39;s `PreviousMap` parses the `/*# sourceMappingURL=PATH */` comment from any CSS string passed to `process()` and dereferences `PATH` against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting `JSON.parse` `SyntaxError` message. The bug also yields a precise file-existence oracle and a controllable-read primitive that may be combined with large-file targets for DoS. The behaviour is triggered with PostCSS&amp;#39;s default options — no `from`, no `map`, no plugins required — and is therefore reachable from any pipeline that runs untrusted CSS through PostCSS (CMS themes, user-uploaded styles, browser-extension/userstyle processors, build pipelines for third-party packages, blog comment renderers, etc.).&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The dangerous chain lives in `lib/previous-map.js` and is wired into every `Input` construction at `lib/input.js:70-77`.&lt;/p&gt;
&lt;p&gt;`Input` constructor (`lib/input.js:70-77`):&lt;/p&gt;
&lt;p&gt;```js
if (pathAvailable &amp;amp;&amp;amp; sourceMapAvailable) {
  let map = new PreviousMap(this.css, opts)
  if (map.text) {
    this.map = map
    let file = map.consumer().file
    if (!this.file &amp;amp;&amp;amp; file) this.file = this.mapResolve(file)
  }
}
```&lt;/p&gt;
&lt;p&gt;`PreviousMap` constructor (`lib/previous-map.js:17-29`):&lt;/p&gt;
&lt;p&gt;```js
constructor(css, opts) {
  if (opts.map === false) return
  this.loadAnnotation(css)
  this.inline = this.start…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6g55-p6wh-862q</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-45623 — PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-45623</link>
      <description>msrc_CVE-2026-45623</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-45623</guid>
    </item>
    <item>
      <title>NCSC-2026-0325 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0325</link>
      <description>NCSC-2026-0325</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0325</guid>
    </item>
    <item>
      <title>RHSA-2026:54427 — Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.15.5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:54427</link>
      <description>&lt;p&gt;github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation postcss: PostCSS: Information disclosure and denial of service via crafted CSS input console: Stored DOM XSS via unescaped pod logs in document.write&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation postcss: PostCSS: Information disclosure and denial of service via crafted CSS input console: Stored DOM XSS via unescaped pod logs in document.write&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:54427</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-45623</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45623</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-postcss, Ubuntu:22.04:LTS: node-postcss, Ubuntu:24.04:LTS: node-postcss, Ubuntu:26.04:LTS: node-postcss&lt;/p&gt;
&lt;p&gt;PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting JSON.parse SyntaxError message. The bug also yields a precise file-existence oracle and a controllable-read primitive that may be combined with large-file targets for DoS. The behaviour is triggered with PostCSS&amp;#39;s default options — no from, no map, no plugins required — and is therefore reachable from any pipeline that runs untrusted CSS through PostCSS (CMS themes, user-uploaded styles, browser-extension/userstyle processors, build pipelines for third-party packages, blog comment renderers, etc.). This issue has been fixed in version 8.5.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-postcss, Ubuntu:22.04:LTS: node-postcss, Ubuntu:24.04:LTS: node-postcss, Ubuntu:26.04:LTS: node-postcss&lt;/p&gt;
&lt;p&gt;PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting JSON.parse SyntaxError message. The bug also yields a precise file-existence oracle and a controllable-read primitive that may be combined with large-file targets for DoS. The behaviour is triggered with PostCSS&amp;#39;s default options — no from, no map, no plugins required — and is therefore reachable from any pipeline that runs untrusted CSS through PostCSS (CMS themes, user-uploaded styles, browser-extension/userstyle processors, build pipelines for third-party packages, blog comment renderers, etc.). This issue has been fixed in version 8.5.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45623</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2923 — Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2923</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2923</guid>
    </item>
  </channel>
</rss>
