<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:38:55 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1165 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</link>
      <description>certfr-2026-avi-1165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1165</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BG21634 — Security fixes in langfuse-worker 3.216.0-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bg21634</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 3.216.0-r1 fixes 29 vulnerabilities: ghsa-frvp-7c67-39w9, ghsa-p63j-vcc4-9vmv, ghsa-55q2-fjhq-7xh7, ghsa-c2j3-45gr-mqc4, CVE-2026-69192...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: langfuse-worker&lt;/p&gt;
&lt;p&gt;Package langfuse-worker version 3.216.0-r1 fixes 29 vulnerabilities: ghsa-frvp-7c67-39w9, ghsa-p63j-vcc4-9vmv, ghsa-55q2-fjhq-7xh7, ghsa-c2j3-45gr-mqc4, CVE-2026-69192...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bg21634</guid>
    </item>
    <item>
      <title>EUVD-2026-343847</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343847</link>
      <description>EUVD-2026-343847</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343847</guid>
    </item>
    <item>
      <title>fkie_cve-2026-69153</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69153</link>
      <description>&lt;p&gt;PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-69153</guid>
    </item>
    <item>
      <title>GHSA-fxqj-rqcc-2cmp — PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fxqj-rqcc-2cmp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: postcss&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The fix for GHSA-6g55-p6wh-862q added a guard in `lib/previous-map.js` `PreviousMap.loadFile()` that restricts an attacker-controlled `sourceMappingURL` (from a CSS comment) to a `.map` extension and, for untrusted maps, rejects `..` traversal and absolute paths. The traversal/absolute rejection is nested inside `if (cssFile) { ... }`. When PostCSS is invoked without the `from` option, `cssFile` is falsy and that branch is skipped, leaving only the `.map` extension check.&lt;/p&gt;
&lt;p&gt;`PreviousMap` is constructed by `lib/input.js` whenever `pathAvailable &amp;amp;&amp;amp; sourceMapAvailable` (under Node with source-map available), independent of `opts.from`/`opts.map` (the constructor returns early only for `opts.map === false`). So `postcss([]).process(css)` on attacker CSS reaches `loadFile` with `cssFile` undefined, and an attacker `/*# sourceMappingURL=/abs/path/x.map */` (or `../`-traversing path) is read via `readFileSync`. When the file is valid JSON, its `sources` (filesystem paths) and `sourcesContent` (source contents) are disclosed in the generated source map.&lt;/p&gt;
&lt;p&gt;## Affected code (v8.5.22 — the release carrying the GHSA-6g55 fix)&lt;/p&gt;
&lt;p&gt;```js
// lib/previous-map.js
loadFile(path, cssFile, trusted) {
  if (!trusted &amp;amp;&amp;amp; !this.unsafeMap) {
    if (!/\.map$/i.test(path)) {
      return undefined
    }
    if (cssFile) {                       // guard runs ONLY when `from` is set
      let relativePath = relative(dirname(cssFile), path)
      if (relativePath === &amp;#39;..&amp;#39; ||
          relativePat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: postcss&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The fix for GHSA-6g55-p6wh-862q added a guard in `lib/previous-map.js` `PreviousMap.loadFile()` that restricts an attacker-controlled `sourceMappingURL` (from a CSS comment) to a `.map` extension and, for untrusted maps, rejects `..` traversal and absolute paths. The traversal/absolute rejection is nested inside `if (cssFile) { ... }`. When PostCSS is invoked without the `from` option, `cssFile` is falsy and that branch is skipped, leaving only the `.map` extension check.&lt;/p&gt;
&lt;p&gt;`PreviousMap` is constructed by `lib/input.js` whenever `pathAvailable &amp;amp;&amp;amp; sourceMapAvailable` (under Node with source-map available), independent of `opts.from`/`opts.map` (the constructor returns early only for `opts.map === false`). So `postcss([]).process(css)` on attacker CSS reaches `loadFile` with `cssFile` undefined, and an attacker `/*# sourceMappingURL=/abs/path/x.map */` (or `../`-traversing path) is read via `readFileSync`. When the file is valid JSON, its `sources` (filesystem paths) and `sourcesContent` (source contents) are disclosed in the generated source map.&lt;/p&gt;
&lt;p&gt;## Affected code (v8.5.22 — the release carrying the GHSA-6g55 fix)&lt;/p&gt;
&lt;p&gt;```js
// lib/previous-map.js
loadFile(path, cssFile, trusted) {
  if (!trusted &amp;amp;&amp;amp; !this.unsafeMap) {
    if (!/\.map$/i.test(path)) {
      return undefined
    }
    if (cssFile) {                       // guard runs ONLY when `from` is set
      let relativePath = relative(dirname(cssFile), path)
      if (relativePath === &amp;#39;..&amp;#39; ||
          relativePat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fxqj-rqcc-2cmp</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-69153 — PostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads arbitrary .map files when `from`…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-69153</link>
      <description>msrc_CVE-2026-69153</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-69153</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11680-1 — agama-web-ui-24+0.a836cced5-52.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1</link>
      <description>&lt;p&gt;agama-web-ui-24+0.a836cced5-52.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;agama-web-ui-24+0.a836cced5-52.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11680-1</guid>
    </item>
    <item>
      <title>RHSA-2026:50070 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:50070</link>
      <description>&lt;p&gt;postcss: PostCSS: Information disclosure via crafted sourceMappingURL&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postcss: PostCSS: Information disclosure via crafted sourceMappingURL&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:50070</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-69153</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69153</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-postcss, Ubuntu:22.04:LTS: node-postcss, Ubuntu:24.04:LTS: node-postcss, Ubuntu:26.04:LTS: node-postcss&lt;/p&gt;
&lt;p&gt;PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-postcss, Ubuntu:22.04:LTS: node-postcss, Ubuntu:24.04:LTS: node-postcss, Ubuntu:26.04:LTS: node-postcss&lt;/p&gt;
&lt;p&gt;PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69153</guid>
    </item>
  </channel>
</rss>
