<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:43:24 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1049 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Certaines d'entre elles permettent à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049</link>
      <description>certfr-2026-avi-1049</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049</guid>
    </item>
    <item>
      <title>EUVD-2026-339195</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339195</link>
      <description>EUVD-2026-339195</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339195</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49978</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49978</link>
      <description>&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside &amp;lt;template&amp;gt;.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside &amp;lt;template&amp;gt;.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49978</guid>
    </item>
    <item>
      <title>GHSA-rp9w-3fw7-7cwq — DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside &lt;template&gt;.content</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rp9w-3fw7-7cwq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dompurify&lt;/p&gt;
&lt;p&gt;If the HTML you give it contains a &amp;lt;template&amp;gt; element, and inside that template there&amp;#39;s an element with a shadow DOM attached to it, DOMPurify quietly skips over the shadow contents. Whatever the attacker put in there - an image with an onerror handler, a link with a javascript: URL, even a full script - survives untouched. The moment the application uses that template the way templates are meant to be used (cloning it and inserting the result into the page), the malicious payload comes along and runs as if it had never been sanitized. From there an attacker gets everything XSS normally gets them: session cookies, stored tokens, the ability to act as the user, and the ability to leave persistent payloads behind for the next person who visits.&lt;/p&gt;
&lt;p&gt;[advisory.pdf](https://github.com/user-attachments/files/28275600/advisory.pdf)&lt;/p&gt;
&lt;p&gt;[poc.html](https://github.com/user-attachments/files/28275708/poc.html)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dompurify&lt;/p&gt;
&lt;p&gt;If the HTML you give it contains a &amp;lt;template&amp;gt; element, and inside that template there&amp;#39;s an element with a shadow DOM attached to it, DOMPurify quietly skips over the shadow contents. Whatever the attacker put in there - an image with an onerror handler, a link with a javascript: URL, even a full script - survives untouched. The moment the application uses that template the way templates are meant to be used (cloning it and inserting the result into the page), the malicious payload comes along and runs as if it had never been sanitized. From there an attacker gets everything XSS normally gets them: session cookies, stored tokens, the ability to act as the user, and the ability to leave persistent payloads behind for the next person who visits.&lt;/p&gt;
&lt;p&gt;[advisory.pdf](https://github.com/user-attachments/files/28275600/advisory.pdf)&lt;/p&gt;
&lt;p&gt;[poc.html](https://github.com/user-attachments/files/28275708/poc.html)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rp9w-3fw7-7cwq</guid>
    </item>
    <item>
      <title>RHSA-2026:42815 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:42815</link>
      <description>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decoding protobufjs: protobufjs: Denial of Service via crafted schema protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution protobufjs: protobufjs: Data integrity impact due to prototype pollution protobufjs: protobufjs: Denial of Service via crafted JSON descriptors linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution tar: node-tar: Denial of Service via crafted gzip bomb tar: Node-tar: Denial of Service via malformed tar archive header&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decoding protobufjs: protobufjs: Denial of Service via crafted schema protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution protobufjs: protobufjs: Data integrity impact due to prototype pollution protobufjs: protobufjs: Denial of Service via crafted JSON descriptors linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution tar: node-tar: Denial of Service via crafted gzip bomb tar: Node-tar: Denial of Service via malformed tar archive header&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:42815</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-49978</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49978</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: dompurify.js, Ubuntu:18.04:LTS: dompurify.js, Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify, Ubuntu:26.04:LTS: node-dompurify&lt;/p&gt;
&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside &amp;lt;template&amp;gt;.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: dompurify.js, Ubuntu:18.04:LTS: dompurify.js, Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify, Ubuntu:26.04:LTS: node-dompurify&lt;/p&gt;
&lt;p&gt;DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside &amp;lt;template&amp;gt;.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49978</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2452 — Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, DOMPurify): Mehrere S…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2452</guid>
    </item>
  </channel>
</rss>
