<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:07:59 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1049 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Certaines d'entre elles permettent à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049</link>
      <description>certfr-2026-avi-1049</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049</guid>
    </item>
    <item>
      <title>EUVD-2026-340294</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-340294</link>
      <description>EUVD-2026-340294</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-340294</guid>
    </item>
    <item>
      <title>fkie_cve-2026-65900</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-65900</link>
      <description>&lt;p&gt;DOMPurify versions &amp;gt;=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, &amp;lt;%evil%&amp;gt;) inside &amp;lt;template&amp;gt; element content. The final normalization/scrub pass (_scrubTemplateExpressions) uses a NodeIterator and node.normalize() that do not descend into template.content, so expressions that only form after adjacent text nodes merge survive sanitization. This bypasses SAFE_FOR_TEMPLATES and can allow a downstream template engine to evaluate attacker-supplied expressions. The string output path is not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DOMPurify versions &amp;gt;=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, &amp;lt;%evil%&amp;gt;) inside &amp;lt;template&amp;gt; element content. The final normalization/scrub pass (_scrubTemplateExpressions) uses a NodeIterator and node.normalize() that do not descend into template.content, so expressions that only form after adjacent text nodes merge survive sanitization. This bypasses SAFE_FOR_TEMPLATES and can allow a downstream template engine to evaluate attacker-supplied expressions. The string output path is not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-65900</guid>
    </item>
    <item>
      <title>GHSA-gvmj-g25r-r7wr — DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside &lt;template&gt; content when using D…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gvmj-g25r-r7wr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dompurify&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `&amp;lt;%evil%&amp;gt;`, that survive the sanitization pass inside `&amp;lt;template&amp;gt;` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.&lt;/p&gt;
&lt;p&gt;&amp;gt; **Note:** The string output path is **not** affected. Only the DOM return paths (`RETURN_DOM: true`, `RETURN_DOM_FRAGMENT: true`, `IN_PLACE: true`) are vulnerable.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;### Background&lt;/p&gt;
&lt;p&gt;`SAFE_FOR_TEMPLATES` is designed to strip `{{ }}`, `${ }`, and `&amp;lt;% %&amp;gt;` expressions from sanitized output so that downstream template engines do not evaluate user-controlled content. The feature operates through two mechanisms:&lt;/p&gt;
&lt;p&gt;1. **Per-node scrubbing** (`_sanitizeElements`, `src/purify.ts:1403`), scrubs individual text nodes during the main sanitization walk.
2. **Final normalization pass** (`_scrubTemplateExpressions`, `src/purify.ts:1115`), calls `node.normalize()` to merge adjacent text nodes, then walks the merged nodes and strips any expressions that only appeared after merging.&lt;/p&gt;
&lt;p&gt;### The Gap&lt;/p&gt;
&lt;p&gt;`_scrubTemplateExpressions` uses a standard `NodeIterator` rooted at the output body:&lt;/p&gt;
&lt;p&gt;```ts
// src/purify.ts:1117
const walker = createNodeIterator.call(
  node.ownerDocument || node,
  node,
  NodeFilter.SHOW_TEXT | NodeFilter.SHOW_COMMENT | ...,
  null
);
```&lt;/p&gt;
&lt;p&gt;Per…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dompurify&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `&amp;lt;%evil%&amp;gt;`, that survive the sanitization pass inside `&amp;lt;template&amp;gt;` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.&lt;/p&gt;
&lt;p&gt;&amp;gt; **Note:** The string output path is **not** affected. Only the DOM return paths (`RETURN_DOM: true`, `RETURN_DOM_FRAGMENT: true`, `IN_PLACE: true`) are vulnerable.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;### Background&lt;/p&gt;
&lt;p&gt;`SAFE_FOR_TEMPLATES` is designed to strip `{{ }}`, `${ }`, and `&amp;lt;% %&amp;gt;` expressions from sanitized output so that downstream template engines do not evaluate user-controlled content. The feature operates through two mechanisms:&lt;/p&gt;
&lt;p&gt;1. **Per-node scrubbing** (`_sanitizeElements`, `src/purify.ts:1403`), scrubs individual text nodes during the main sanitization walk.
2. **Final normalization pass** (`_scrubTemplateExpressions`, `src/purify.ts:1115`), calls `node.normalize()` to merge adjacent text nodes, then walks the merged nodes and strips any expressions that only appeared after merging.&lt;/p&gt;
&lt;p&gt;### The Gap&lt;/p&gt;
&lt;p&gt;`_scrubTemplateExpressions` uses a standard `NodeIterator` rooted at the output body:&lt;/p&gt;
&lt;p&gt;```ts
// src/purify.ts:1117
const walker = createNodeIterator.call(
  node.ownerDocument || node,
  node,
  NodeFilter.SHOW_TEXT | NodeFilter.SHOW_COMMENT | ...,
  null
);
```&lt;/p&gt;
&lt;p&gt;Per…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gvmj-g25r-r7wr</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11723-1 — python313-comfyui-frontend-package-1.52.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11723-1</link>
      <description>&lt;p&gt;python313-comfyui-frontend-package-1.52.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-comfyui-frontend-package-1.52.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11723-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-65900</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-65900</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify, Ubuntu:26.04:LTS: node-dompurify&lt;/p&gt;
&lt;p&gt;DOMPurify versions &amp;gt;=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, &amp;lt;%evil%&amp;gt;) inside &amp;lt;template&amp;gt; element content. The final normalization/scrub pass (_scrubTemplateExpressions) uses a NodeIterator and node.normalize() that do not descend into template.content, so expressions that only form after adjacent text nodes merge survive sanitization. This bypasses SAFE_FOR_TEMPLATES and can allow a downstream template engine to evaluate attacker-supplied expressions. The string output path is not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify, Ubuntu:26.04:LTS: node-dompurify&lt;/p&gt;
&lt;p&gt;DOMPurify versions &amp;gt;=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, &amp;lt;%evil%&amp;gt;) inside &amp;lt;template&amp;gt; element content. The final normalization/scrub pass (_scrubTemplateExpressions) uses a NodeIterator and node.normalize() that do not descend into template.content, so expressions that only form after adjacent text nodes merge survive sanitization. This bypasses SAFE_FOR_TEMPLATES and can allow a downstream template engine to evaluate attacker-supplied expressions. The string output path is not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-65900</guid>
    </item>
  </channel>
</rss>
