<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:56:26 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:10710 — Important: pcs security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:10710</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: pcs, AlmaLinux:9: pcs-snmp&lt;/p&gt;
&lt;p&gt;The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lodash: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: pcs, AlmaLinux:9: pcs-snmp&lt;/p&gt;
&lt;p&gt;The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lodash: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:10710</guid>
    </item>
    <item>
      <title>bdu:2026-09406</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09406</link>
      <description>bdu:2026-09406</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09406</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0500 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</link>
      <description>certfr-2026-avi-0500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD27625 — Security fixes for CVE-2022-25881, CVE-2022-33987, CVE-2025-25285, CVE-2025-62718, CVE-2025-69873, CVE-2026-21637, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: mongosh&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the mongosh package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad27625</guid>
    </item>
    <item>
      <title>ESEA-2026:0136 — Important: cockpit-image-builder security update</title>
      <link>https://cve.radiocsirt.org/vuln/esea-2026:0136</link>
      <description>&lt;p&gt;Important: cockpit-image-builder security update&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Important: cockpit-image-builder security update&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/esea-2026:0136</guid>
    </item>
    <item>
      <title>EUVD-2026-367741</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-367741</link>
      <description>EUVD-2026-367741</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-367741</guid>
    </item>
    <item>
      <title>fkie_cve-2026-4800</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4800</link>
      <description>&lt;p&gt;Impact:&lt;/p&gt;
&lt;p&gt;The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.&lt;/p&gt;
&lt;p&gt;When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.&lt;/p&gt;
&lt;p&gt;Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().&lt;/p&gt;
&lt;p&gt;Patches:&lt;/p&gt;
&lt;p&gt;Users should upgrade to version 4.18.0.&lt;/p&gt;
&lt;p&gt;Workarounds:&lt;/p&gt;
&lt;p&gt;Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Impact:&lt;/p&gt;
&lt;p&gt;The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.&lt;/p&gt;
&lt;p&gt;When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.&lt;/p&gt;
&lt;p&gt;Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().&lt;/p&gt;
&lt;p&gt;Patches:&lt;/p&gt;
&lt;p&gt;Users should upgrade to version 4.18.0.&lt;/p&gt;
&lt;p&gt;Workarounds:&lt;/p&gt;
&lt;p&gt;Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-4800</guid>
    </item>
    <item>
      <title>GHSA-r5fr-rjxr-66jc — lodash vulnerable to Code Injection via `_.template` imports key names</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r5fr-rjxr-66jc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: lodash, npm: lodash-es, npm: lodash-amd, npm: lodash.template&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The fix for [CVE-2021-23337](https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the `variable` option in `_.template` but did not apply the same validation to `options.imports` key names. Both paths flow into the same `Function()` constructor sink.&lt;/p&gt;
&lt;p&gt;When an application passes untrusted input as `options.imports` key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.&lt;/p&gt;
&lt;p&gt;Additionally, `_.template` uses `assignInWith` to merge imports, which enumerates inherited properties via `for..in`. If `Object.prototype` has been polluted by any other vector, the polluted keys are copied into the imports object and passed to `Function()`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Users should upgrade to version 4.18.0.&lt;/p&gt;
&lt;p&gt;The fix applies two changes:
1. Validate `importsKeys` against the existing `reForbiddenIdentifierChars` regex (same check already used for the `variable` option)
2. Replace `assignInWith` with `assignWith` when merging imports, so only own properties are enumerated&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Do not pass untrusted input as key names in `options.imports`. Only use developer-controlled, static key names.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: lodash, npm: lodash-es, npm: lodash-amd, npm: lodash.template&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The fix for [CVE-2021-23337](https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the `variable` option in `_.template` but did not apply the same validation to `options.imports` key names. Both paths flow into the same `Function()` constructor sink.&lt;/p&gt;
&lt;p&gt;When an application passes untrusted input as `options.imports` key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.&lt;/p&gt;
&lt;p&gt;Additionally, `_.template` uses `assignInWith` to merge imports, which enumerates inherited properties via `for..in`. If `Object.prototype` has been polluted by any other vector, the polluted keys are copied into the imports object and passed to `Function()`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Users should upgrade to version 4.18.0.&lt;/p&gt;
&lt;p&gt;The fix applies two changes:
1. Validate `importsKeys` against the existing `reForbiddenIdentifierChars` regex (same check already used for the `variable` option)
2. Replace `assignInWith` with `assignWith` when merging imports, so only own properties are enumerated&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Do not pass untrusted input as key names in `options.imports`. Only use developer-controlled, static key names.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r5fr-rjxr-66jc</guid>
    </item>
    <item>
      <title>NCSC-2026-0256 — Kwetsbaarheden verholpen in Oracle Communications</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0256</link>
      <description>NCSC-2026-0256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0256</guid>
    </item>
    <item>
      <title>RHBA-2026:21387 — Red Hat Bug Fix Advisory: cockpit bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2026:21387</link>
      <description>&lt;p&gt;lodash: lodash: Arbitrary code execution via untrusted input in template imports&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lodash: lodash: Arbitrary code execution via untrusted input in template imports&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2026:21387</guid>
    </item>
    <item>
      <title>RLSA-2026:24331 — Important: cockpit-image-builder security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:24331</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: cockpit-image-builder&lt;/p&gt;
&lt;p&gt;The image-builder-frontend generates custom images suitable for deploying systems or uploading to the cloud. It integrates into Cockpit as a frontend for osbuild.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)&lt;/p&gt;
&lt;p&gt;* lodash: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: cockpit-image-builder&lt;/p&gt;
&lt;p&gt;The image-builder-frontend generates custom images suitable for deploying systems or uploading to the cloud. It integrates into Cockpit as a frontend for osbuild.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lodash: prototype pollution in _.unset and _.omit functions (CVE-2025-13465)&lt;/p&gt;
&lt;p&gt;* lodash: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:24331</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-4800</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4800</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: node-lodash, Ubuntu:Pro:18.04:LTS: node-lodash, Ubuntu:Pro:20.04:LTS: node-lodash, Ubuntu:Pro:22.04:LTS: node-lodash, Ubuntu:Pro:24.04:LTS: node-lodash, Ubuntu:25.10: node-lodash, Ubuntu:Pro:26.04:LTS: node-lodash&lt;/p&gt;
&lt;p&gt;Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: node-lodash, Ubuntu:Pro:18.04:LTS: node-lodash, Ubuntu:Pro:20.04:LTS: node-lodash, Ubuntu:Pro:22.04:LTS: node-lodash, Ubuntu:Pro:24.04:LTS: node-lodash, Ubuntu:25.10: node-lodash, Ubuntu:Pro:26.04:LTS: node-lodash&lt;/p&gt;
&lt;p&gt;Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time. Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function(). Patches: Users should upgrade to version 4.18.0. Workarounds: Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4800</guid>
    </item>
    <item>
      <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-088</link>
      <description>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-088</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1160 — Red Hat Enterprise Linux und Satellite (satellite/iop-remediations-rhel9 container image): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1160</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Red Hat Satellite ausnutzen, um Informationen offenzulegen oder beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Red Hat Satellite ausnutzen, um Informationen offenzulegen oder beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1160</guid>
    </item>
  </channel>
</rss>
