<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:47:44 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1256 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</link>
      <description>certfr-2026-avi-1256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</guid>
    </item>
    <item>
      <title>EUVD-2026-355121</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355121</link>
      <description>EUVD-2026-355121</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355121</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63670</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63670</link>
      <description>&lt;p&gt;ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as text by htmlparser2 and the ontext handler emits that content without escaping, while a browser parses the following img onerror markup as active HTML. This issue is fixed in version 2.17.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as text by htmlparser2 and the ontext handler emits that content without escaping, while a browser parses the following img onerror markup as active HTML. This issue is fixed in version 2.17.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63670</guid>
    </item>
    <item>
      <title>GHSA-jxwj-j7wr-gfrw — ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `&lt;/textarea/&gt;` solidus close</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jxwj-j7wr-gfrw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sanitize-html&lt;/p&gt;
&lt;p&gt;### Summary
A mutation-XSS / allowedTags bypass: when `textarea` (or `xmp`) is included in `allowedTags`, an input containing a literal `&amp;lt;/textarea/&amp;gt;` (a solidus right after the RCDATA end-tag name) lets non-allowed markup such as `&amp;lt;img src=x onerror=…&amp;gt;` pass through `sanitizeHtml()` **live and unescaped**, even though `img`/`onerror` are not in the allowlist. A spec-compliant browser executes the surviving handler — XSS. This is a literal-solidus variant that bypasses the two most recent fixes in this code area (CVE-2026-40186, CVE-2026-44990), both already applied in 2.17.5. The default configuration is not affected.&lt;/p&gt;
&lt;p&gt;### Details
`sanitize-html` emits the text content of HTML raw-text elements (`textarea`, `xmp`) without escaping. Two things combine:
- **Parser differential:** on input, htmlparser2 does NOT recognize `&amp;lt;/textarea/&amp;gt;` (solidus after the RCDATA
  end-tag name) as a close tag; it emits `&amp;lt;/textarea/&amp;gt;&amp;lt;img …&amp;gt;` as a single raw-text node.
- **Unescaped passthrough:** the `ontext` handler (`index.js` ~575-583) appends `textarea`/`xmp` content with
`result += text` (no `escapeHtml`), assuming it is &amp;#34;already properly encoded&amp;#34; — true for entity-decoded
  content (what CVE-2026-40186 fixed) but false for this mis-tokenized literal close tag.
A spec browser treats `&amp;lt;/textarea/&amp;gt;` as a valid `textarea` close, so the following `&amp;lt;img onerror&amp;gt;` is parsed as a live element. The recent fixes addressed entity-encoding (CVE-2026-40186) and the `xmp` default (CVE-2026-44990); neith…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sanitize-html&lt;/p&gt;
&lt;p&gt;### Summary
A mutation-XSS / allowedTags bypass: when `textarea` (or `xmp`) is included in `allowedTags`, an input containing a literal `&amp;lt;/textarea/&amp;gt;` (a solidus right after the RCDATA end-tag name) lets non-allowed markup such as `&amp;lt;img src=x onerror=…&amp;gt;` pass through `sanitizeHtml()` **live and unescaped**, even though `img`/`onerror` are not in the allowlist. A spec-compliant browser executes the surviving handler — XSS. This is a literal-solidus variant that bypasses the two most recent fixes in this code area (CVE-2026-40186, CVE-2026-44990), both already applied in 2.17.5. The default configuration is not affected.&lt;/p&gt;
&lt;p&gt;### Details
`sanitize-html` emits the text content of HTML raw-text elements (`textarea`, `xmp`) without escaping. Two things combine:
- **Parser differential:** on input, htmlparser2 does NOT recognize `&amp;lt;/textarea/&amp;gt;` (solidus after the RCDATA
  end-tag name) as a close tag; it emits `&amp;lt;/textarea/&amp;gt;&amp;lt;img …&amp;gt;` as a single raw-text node.
- **Unescaped passthrough:** the `ontext` handler (`index.js` ~575-583) appends `textarea`/`xmp` content with
`result += text` (no `escapeHtml`), assuming it is &amp;#34;already properly encoded&amp;#34; — true for entity-decoded
  content (what CVE-2026-40186 fixed) but false for this mis-tokenized literal close tag.
A spec browser treats `&amp;lt;/textarea/&amp;gt;` as a valid `textarea` close, so the following `&amp;lt;img onerror&amp;gt;` is parsed as a live element. The recent fixes addressed entity-encoding (CVE-2026-40186) and the `xmp` default (CVE-2026-44990); neith…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jxwj-j7wr-gfrw</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
