<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:50:31 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-UL03599 — Caddy is an extensible server platform that uses TLS by default</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ul03599</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: caddy&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the caddy package. Caddy is an extensible server platform that uses TLS by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: caddy&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the caddy package. Caddy is an extensible server platform that uses TLS by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ul03599</guid>
    </item>
    <item>
      <title>EUVD-2026-330141</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330141</link>
      <description>EUVD-2026-330141</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330141</guid>
    </item>
    <item>
      <title>fkie_cve-2026-52846</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52846</link>
      <description>&lt;p&gt;Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as &amp;lt;&amp;lt;&amp;gt;img src=x onerror=alert()&amp;gt;, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely. This vulnerability is fixed in 2.11.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as &amp;lt;&amp;lt;&amp;gt;img src=x onerror=alert()&amp;gt;, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely. This vulnerability is fixed in 2.11.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-52846</guid>
    </item>
    <item>
      <title>GHSA-vcc4-2c75-vc9v — Caddy: stripHTML template function bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vcc4-2c75-vc9v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/caddyserver/caddy/v2, Go: github.com/caddyserver/caddy&lt;/p&gt;
&lt;p&gt;### Summary
Caddy’s `stripHTML` template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as `&amp;lt;&amp;lt;&amp;gt;img src=x onerror=alert()&amp;gt;`, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability originates from `funcStripHTML` in:&lt;/p&gt;
&lt;p&gt;[caddy/caddy/caddyhttp/templates/tplcontext.go](https://github.com/caddyserver/caddy/blob/77e9ce7404c4a76853e101a9f5687a929ee56654/modules/caddyhttp/templates/tplcontext.go)&lt;/p&gt;
&lt;p&gt;```go
func (TemplateContext) funcStripHTML(s string) string {
    var buf bytes.Buffer
    var inTag, inQuotes bool
    var tagStart int
    for i, ch := range s {
        if inTag {
            if ch == &amp;#39;&amp;gt;&amp;#39; &amp;amp;&amp;amp; !inQuotes {
                inTag = false
            } else if ch == &amp;#39;&amp;lt;&amp;#39; &amp;amp;&amp;amp; !inQuotes {
                // false start
                buf.WriteString(s[tagStart:i])
                tagStart = i
            } else if ch == &amp;#39;&amp;#34;&amp;#39; {
                inQuotes = !inQuotes
            }
            continue
        }
        if ch == &amp;#39;&amp;lt;&amp;#39; {
            inTag = true
            tagStart = i
            continue
        }
        buf.WriteRune(ch)
    }
    if inTag {
        // false start
        buf.WriteString(s[tagStart:])
    }
    return buf.String()
}
```&lt;/p&gt;
&lt;p&gt;### POC&lt;/p&gt;
&lt;p&gt;Caddyfile setup&lt;/p&gt;
&lt;p&gt;```
:8080 {
    root * ./site
    file_server
    templates
}
```&lt;/p&gt;
&lt;p&gt;Templa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/caddyserver/caddy/v2, Go: github.com/caddyserver/caddy&lt;/p&gt;
&lt;p&gt;### Summary
Caddy’s `stripHTML` template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as `&amp;lt;&amp;lt;&amp;gt;img src=x onerror=alert()&amp;gt;`, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability originates from `funcStripHTML` in:&lt;/p&gt;
&lt;p&gt;[caddy/caddy/caddyhttp/templates/tplcontext.go](https://github.com/caddyserver/caddy/blob/77e9ce7404c4a76853e101a9f5687a929ee56654/modules/caddyhttp/templates/tplcontext.go)&lt;/p&gt;
&lt;p&gt;```go
func (TemplateContext) funcStripHTML(s string) string {
    var buf bytes.Buffer
    var inTag, inQuotes bool
    var tagStart int
    for i, ch := range s {
        if inTag {
            if ch == &amp;#39;&amp;gt;&amp;#39; &amp;amp;&amp;amp; !inQuotes {
                inTag = false
            } else if ch == &amp;#39;&amp;lt;&amp;#39; &amp;amp;&amp;amp; !inQuotes {
                // false start
                buf.WriteString(s[tagStart:i])
                tagStart = i
            } else if ch == &amp;#39;&amp;#34;&amp;#39; {
                inQuotes = !inQuotes
            }
            continue
        }
        if ch == &amp;#39;&amp;lt;&amp;#39; {
            inTag = true
            tagStart = i
            continue
        }
        buf.WriteRune(ch)
    }
    if inTag {
        // false start
        buf.WriteString(s[tagStart:])
    }
    return buf.String()
}
```&lt;/p&gt;
&lt;p&gt;### POC&lt;/p&gt;
&lt;p&gt;Caddyfile setup&lt;/p&gt;
&lt;p&gt;```
:8080 {
    root * ./site
    file_server
    templates
}
```&lt;/p&gt;
&lt;p&gt;Templa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vcc4-2c75-vc9v</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-52846</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52846</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: caddy, Ubuntu:25.10: caddy, Ubuntu:Pro:26.04:LTS: caddy&lt;/p&gt;
&lt;p&gt;Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as &amp;lt;&amp;lt;&amp;gt;img src=x onerror=alert()&amp;gt;, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely. This vulnerability is fixed in 2.11.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: caddy, Ubuntu:25.10: caddy, Ubuntu:Pro:26.04:LTS: caddy&lt;/p&gt;
&lt;p&gt;Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as &amp;lt;&amp;lt;&amp;gt;img src=x onerror=alert()&amp;gt;, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side XSS in cases where untrusted strings are rendered unsafely. This vulnerability is fixed in 2.11.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-52846</guid>
    </item>
  </channel>
</rss>
