<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:51:49 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1049 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Certaines d'entre elles permettent à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049</link>
      <description>certfr-2026-avi-1049</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1049</guid>
    </item>
    <item>
      <title>EUVD-2026-339886</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339886</link>
      <description>EUVD-2026-339886</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339886</guid>
    </item>
    <item>
      <title>fkie_cve-2026-65914</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-65914</link>
      <description>&lt;p&gt;DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-65914</guid>
    </item>
    <item>
      <title>GHSA-h8r8-wccr-v5f2 — DOMPurify is vulnerable to mutation-XSS via Re-Contextualization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h8r8-wccr-v5f2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dompurify&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using `innerHTML` and special wrappers. The vulnerable wrappers confirmed in browser behavior are `script`, `xmp`, `iframe`, `noembed`, `noframes`, and `noscript`. The payload remains seemingly benign after `DOMPurify.sanitize()`, but mutates during the second parse into executable markup with an event handler, enabling JavaScript execution in the client (`alert(1)` in the PoC).&lt;/p&gt;
&lt;p&gt;## Vulnerability&lt;/p&gt;
&lt;p&gt;The root cause is context switching after sanitization: sanitized output is treated as trusted and concatenated into a wrapper string (for example, `&amp;lt;xmp&amp;gt; ... &amp;lt;/xmp&amp;gt;` or other special wrappers) before being reparsed by the browser. In this flow, attacker-controlled text inside an attribute (for example `&amp;lt;/xmp&amp;gt;` or equivalent closing sequences for each wrapper) closes the special parsing context early and reintroduces attacker markup (`&amp;lt;img ... onerror=...&amp;gt;`) outside the original attribute context. DOMPurify sanitizes the original parse tree, but the application performs a second parse in a different context, reactivating dangerous tokens (classic mXSS pattern).&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;1. Start the PoC app:
```bash
npm install
npm start
```&lt;/p&gt;
&lt;p&gt;2. Open `http://localhost:3001`.
3. Set `Wrapper en sink` to `xmp`.
4. Use payload:
```html
 &amp;lt;img src=x alt=&amp;#34;&amp;lt;/xmp&amp;gt;&amp;lt;img src=x onerror=alert(&amp;#39;expoc&amp;#39;)&amp;gt;&amp;#34;&amp;gt;
```&lt;/p&gt;
&lt;p&gt;5. Click `Sanitize + Render`.
6. Observe:
- `Sanitized response` still contains t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dompurify&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A mutation-XSS (mXSS) condition was confirmed when sanitized HTML is reinserted into a new parsing context using `innerHTML` and special wrappers. The vulnerable wrappers confirmed in browser behavior are `script`, `xmp`, `iframe`, `noembed`, `noframes`, and `noscript`. The payload remains seemingly benign after `DOMPurify.sanitize()`, but mutates during the second parse into executable markup with an event handler, enabling JavaScript execution in the client (`alert(1)` in the PoC).&lt;/p&gt;
&lt;p&gt;## Vulnerability&lt;/p&gt;
&lt;p&gt;The root cause is context switching after sanitization: sanitized output is treated as trusted and concatenated into a wrapper string (for example, `&amp;lt;xmp&amp;gt; ... &amp;lt;/xmp&amp;gt;` or other special wrappers) before being reparsed by the browser. In this flow, attacker-controlled text inside an attribute (for example `&amp;lt;/xmp&amp;gt;` or equivalent closing sequences for each wrapper) closes the special parsing context early and reintroduces attacker markup (`&amp;lt;img ... onerror=...&amp;gt;`) outside the original attribute context. DOMPurify sanitizes the original parse tree, but the application performs a second parse in a different context, reactivating dangerous tokens (classic mXSS pattern).&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;1. Start the PoC app:
```bash
npm install
npm start
```&lt;/p&gt;
&lt;p&gt;2. Open `http://localhost:3001`.
3. Set `Wrapper en sink` to `xmp`.
4. Use payload:
```html
 &amp;lt;img src=x alt=&amp;#34;&amp;lt;/xmp&amp;gt;&amp;lt;img src=x onerror=alert(&amp;#39;expoc&amp;#39;)&amp;gt;&amp;#34;&amp;gt;
```&lt;/p&gt;
&lt;p&gt;5. Click `Sanitize + Render`.
6. Observe:
- `Sanitized response` still contains t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h8r8-wccr-v5f2</guid>
    </item>
    <item>
      <title>NCSC-2026-0315 — Kwetsbaarheden verholpen in Oracle MySQL</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0315</link>
      <description>NCSC-2026-0315</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0315</guid>
    </item>
    <item>
      <title>RHSA-2026:54517 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:54517</link>
      <description>&lt;p&gt;fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling DOMPurify: DOMPurify: Cross-Site Scripting via unsanitized DOM elements from different realms DOMPurify: DOMPurify: Cross-site scripting due to state leakage in sanitization. dompurify: DOMPurify: URI validation bypass leads to cross-site scripting dompurify: DOMPurify: Cross-Site Scripting (XSS) via prototype pollution in USE_PROFILES mode dompurify: DOMPurify: Cross-Site Scripting vulnerability allows arbitrary code execution browserslist: Browserslist: Prototype pollution leading to denial of service browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling DOMPurify: DOMPurify: Cross-Site Scripting via unsanitized DOM elements from different realms DOMPurify: DOMPurify: Cross-site scripting due to state leakage in sanitization. dompurify: DOMPurify: URI validation bypass leads to cross-site scripting dompurify: DOMPurify: Cross-Site Scripting (XSS) via prototype pollution in USE_PROFILES mode dompurify: DOMPurify: Cross-Site Scripting vulnerability allows arbitrary code execution browserslist: Browserslist: Prototype pollution leading to denial of service browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:54517</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-65914</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-65914</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify&lt;/p&gt;
&lt;p&gt;DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-dompurify, Ubuntu:24.04:LTS: node-dompurify&lt;/p&gt;
&lt;p&gt;DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing contexts using innerHTML with wrappers like script, xmp, iframe, noembed, noframes, or noscript. Attackers can craft payloads with closing sequences that break out of the wrapper context during reparsing, reactivating dangerous markup with event handlers to execute JavaScript.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-65914</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2903 — Oracle MySQL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2903</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2903</guid>
    </item>
  </channel>
</rss>
