<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:31:28 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-14132</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14132</link>
      <description>bdu:2026-14132</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14132</guid>
    </item>
    <item>
      <title>EUVD-2026-362483</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362483</link>
      <description>EUVD-2026-362483</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362483</guid>
    </item>
    <item>
      <title>fkie_cve-2026-83606</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83606</link>
      <description>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction production in lib/grammar.js lets the greedy S+ separator and lazy Char*? data group repeatedly repartition a long whitespace tail when the required closing ?&amp;gt; is absent. Both parsePI and parseProcessingInstruction apply the expression to the entire remaining source, causing quadratic backtracking during DOMParser.parseFromString() under default options and allowing a small unauthenticated XML input to stall the Node.js event loop. This issue is fixed in @xmldom/xmldom version 0.9.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction production in lib/grammar.js lets the greedy S+ separator and lazy Char*? data group repeatedly repartition a long whitespace tail when the required closing ?&amp;gt; is absent. Both parsePI and parseProcessingInstruction apply the expression to the entire remaining source, causing quadratic backtracking during DOMParser.parseFromString() under default options and allowing a small unauthenticated XML input to stall the Node.js event loop. This issue is fixed in @xmldom/xmldom version 0.9.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-83606</guid>
    </item>
    <item>
      <title>GHSA-g53g-w8rj-fmg7 — xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g53g-w8rj-fmg7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`@xmldom/xmldom`&amp;#39;s processing-instruction (PI) grammar regex exhibits quadratic-time backtracking
(ReDoS) when parsing an **unterminated** processing instruction. A single small XML document
containing `&amp;lt;?` + a target + a long run of whitespace and no closing `?&amp;gt;` forces the regular
expression engine into O(n²) work, stalling the Node.js event loop. The input is parsed with
`DOMParser.parseFromString` under **default options**, so it is reachable from unauthenticated,
network-delivered XML (SOAP/SAML, webhooks, uploads, XML APIs).&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The PI production in `lib/grammar.js` compiles (flags `mu`) to:&lt;/p&gt;
&lt;p&gt;```
^&amp;lt;\?(NameChars)(?:[\x20\x09\x0D\x0A]+([Char]*?))?\?&amp;gt;
                     ^^^ S+ greedy       ^^^ Char*? lazy
```&lt;/p&gt;
&lt;p&gt;- `lib/grammar.js` line 261: https://github.com/xmldom/xmldom/blob/bb7a085dc5ba1eea3212388509b97bb4b4af32b9/lib/grammar.js#L261&lt;/p&gt;
&lt;p&gt;In the optional tail `(?:S+(Char*?))?`, both the greedy separator `S+` and the lazy data `Char*?`
match XML whitespace. When the required trailing `?&amp;gt;` is absent, the engine must ultimately fail —
but first it tries every partition of the whitespace run between `S+` and `Char*?`, which is O(n²)
in the length of the trailing whitespace.&lt;/p&gt;
&lt;p&gt;The regex is executed against the **entire remaining source string** in two places in `lib/sax.js`,
so the whole whitespace tail is scanned:&lt;/p&gt;
&lt;p&gt;- `parsePI` — https://github.com/xmldom/xmldom/blob/bb7a085dc5ba1eea3212388509b97bb4b4af32b9/lib/sax.js#L680-L691
- `parseProcessingInstruction…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`@xmldom/xmldom`&amp;#39;s processing-instruction (PI) grammar regex exhibits quadratic-time backtracking
(ReDoS) when parsing an **unterminated** processing instruction. A single small XML document
containing `&amp;lt;?` + a target + a long run of whitespace and no closing `?&amp;gt;` forces the regular
expression engine into O(n²) work, stalling the Node.js event loop. The input is parsed with
`DOMParser.parseFromString` under **default options**, so it is reachable from unauthenticated,
network-delivered XML (SOAP/SAML, webhooks, uploads, XML APIs).&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The PI production in `lib/grammar.js` compiles (flags `mu`) to:&lt;/p&gt;
&lt;p&gt;```
^&amp;lt;\?(NameChars)(?:[\x20\x09\x0D\x0A]+([Char]*?))?\?&amp;gt;
                     ^^^ S+ greedy       ^^^ Char*? lazy
```&lt;/p&gt;
&lt;p&gt;- `lib/grammar.js` line 261: https://github.com/xmldom/xmldom/blob/bb7a085dc5ba1eea3212388509b97bb4b4af32b9/lib/grammar.js#L261&lt;/p&gt;
&lt;p&gt;In the optional tail `(?:S+(Char*?))?`, both the greedy separator `S+` and the lazy data `Char*?`
match XML whitespace. When the required trailing `?&amp;gt;` is absent, the engine must ultimately fail —
but first it tries every partition of the whitespace run between `S+` and `Char*?`, which is O(n²)
in the length of the trailing whitespace.&lt;/p&gt;
&lt;p&gt;The regex is executed against the **entire remaining source string** in two places in `lib/sax.js`,
so the whole whitespace tail is scanned:&lt;/p&gt;
&lt;p&gt;- `parsePI` — https://github.com/xmldom/xmldom/blob/bb7a085dc5ba1eea3212388509b97bb4b4af32b9/lib/sax.js#L680-L691
- `parseProcessingInstruction…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g53g-w8rj-fmg7</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-83606</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83606</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction production in lib/grammar.js lets the greedy S+ separator and lazy Char*? data group repeatedly repartition a long whitespace tail when the required closing ?&amp;gt; is absent. Both parsePI and parseProcessingInstruction apply the expression to the entire remaining source, causing quadratic backtracking during DOMParser.parseFromString() under default options and allowing a small unauthenticated XML input to stall the Node.js event loop. This issue is fixed in @xmldom/xmldom version 0.9.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction production in lib/grammar.js lets the greedy S+ separator and lazy Char*? data group repeatedly repartition a long whitespace tail when the required closing ?&amp;gt; is absent. Both parsePI and parseProcessingInstruction apply the expression to the entire remaining source, causing quadratic backtracking during DOMParser.parseFromString() under default options and allowing a small unauthenticated XML input to stall the Node.js event loop. This issue is fixed in @xmldom/xmldom version 0.9.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83606</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
