<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:26:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-363631</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363631</link>
      <description>EUVD-2026-363631</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363631</guid>
    </item>
    <item>
      <title>fkie_cve-2026-83608</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83608</link>
      <description>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE branch in lib/dom.js validates publicId, systemId, and internalSubset under requireWellFormed: true but emits DocumentType.name verbatim. A name containing &amp;gt; or whitespace can terminate the &amp;lt;!DOCTYPE ...&amp;gt; declaration and inject sibling markup; the value can be supplied through createDocumentType() on the 0.8.x and unscoped lines or through a direct DocumentType.name property write on every affected line. The default path and legacy creation-time behavior remain permissive, while the vulnerable strict path fails to enforce an XML Name. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE branch in lib/dom.js validates publicId, systemId, and internalSubset under requireWellFormed: true but emits DocumentType.name verbatim. A name containing &amp;gt; or whitespace can terminate the &amp;lt;!DOCTYPE ...&amp;gt; declaration and inject sibling markup; the value can be supplied through createDocumentType() on the 0.8.x and unscoped lines or through a direct DocumentType.name property write on every affected line. The default path and legacy creation-time behavior remain permissive, while the vulnerable strict path fails to enforce an XML Name. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-83608</guid>
    </item>
    <item>
      <title>GHSA-27p8-2357-5qqv — xmldom: DocType `name` Injection Bypasses requireWellFormed</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-27p8-2357-5qqv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `@xmldom/xmldom` serializer emits `DocumentType.name` verbatim into the
`&amp;lt;!DOCTYPE …&amp;gt;` declaration with no well-formedness guard. GHSA-f6ww-3ggp-fr8h
(CVE-2026-41674) hardened the serializer&amp;#39;s `requireWellFormed` path for a
DocumentType&amp;#39;s sibling fields — `publicId`, `systemId`, and `internalSubset` —
but it did **not** add any check for `name`. A `&amp;gt;` (or whitespace) in the name
terminates the doctype declaration early, letting the remaining characters
become sibling markup in the serialized output.&lt;/p&gt;
&lt;p&gt;Because `requireWellFormed: true` — the recommended mitigation for the prior
xmldom injection CVEs — performs no validation on the DocType `name`, this is a
bypass of that control, in the same family as the open element-name
(GHSA-w2rr-34g9-rvrj) and attribute-name (GHSA-4w3w-2rp5-g8jm) name-injection advisories.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The serializer&amp;#39;s `DOCUMENT_TYPE_NODE` case runs the `requireWellFormed` block
only against `publicId`, `systemId`, and `internalSubset`, then pushes
`n.name` directly into the buffer between the `&amp;lt;!DOCTYPE ` prefix and the
closing `&amp;gt;`:&lt;/p&gt;
&lt;p&gt;- 0.9.x (v0.9.10, `bb7a085`):
  [serializer DocType case, `lib/dom.js#L3256-L3283`](https://github.com/xmldom/xmldom/blob/bb7a085dc5ba1eea3212388509b97bb4b4af32b9/lib/dom.js#L3256-L3283)
  — the `requireWellFormed` block ([#L3259-L3269](https://github.com/xmldom/xmldom/blob/bb7a085dc5ba1eea3212388509b97bb4b4af32b9/lib/dom.js#L3259-L3269))
  validates `publicId`/`systemId`/`internalSubset` but not `name`, whic…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `@xmldom/xmldom` serializer emits `DocumentType.name` verbatim into the
`&amp;lt;!DOCTYPE …&amp;gt;` declaration with no well-formedness guard. GHSA-f6ww-3ggp-fr8h
(CVE-2026-41674) hardened the serializer&amp;#39;s `requireWellFormed` path for a
DocumentType&amp;#39;s sibling fields — `publicId`, `systemId`, and `internalSubset` —
but it did **not** add any check for `name`. A `&amp;gt;` (or whitespace) in the name
terminates the doctype declaration early, letting the remaining characters
become sibling markup in the serialized output.&lt;/p&gt;
&lt;p&gt;Because `requireWellFormed: true` — the recommended mitigation for the prior
xmldom injection CVEs — performs no validation on the DocType `name`, this is a
bypass of that control, in the same family as the open element-name
(GHSA-w2rr-34g9-rvrj) and attribute-name (GHSA-4w3w-2rp5-g8jm) name-injection advisories.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The serializer&amp;#39;s `DOCUMENT_TYPE_NODE` case runs the `requireWellFormed` block
only against `publicId`, `systemId`, and `internalSubset`, then pushes
`n.name` directly into the buffer between the `&amp;lt;!DOCTYPE ` prefix and the
closing `&amp;gt;`:&lt;/p&gt;
&lt;p&gt;- 0.9.x (v0.9.10, `bb7a085`):
  [serializer DocType case, `lib/dom.js#L3256-L3283`](https://github.com/xmldom/xmldom/blob/bb7a085dc5ba1eea3212388509b97bb4b4af32b9/lib/dom.js#L3256-L3283)
  — the `requireWellFormed` block ([#L3259-L3269](https://github.com/xmldom/xmldom/blob/bb7a085dc5ba1eea3212388509b97bb4b4af32b9/lib/dom.js#L3259-L3269))
  validates `publicId`/`systemId`/`internalSubset` but not `name`, whic…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-27p8-2357-5qqv</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-83608 — xmldom: DocType `name` Injection Bypasses requireWellFormed</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-83608</link>
      <description>msrc_CVE-2026-83608</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-83608</guid>
    </item>
    <item>
      <title>RHSA-2026:69248 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.9 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:69248</link>
      <description>&lt;p&gt;undici: undici: Denial of Service via unrequested WebSocket subprotocol encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification urllib: urllib: Credential leakage via cross-origin redirects net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages nanoid: nanoid: Denial of Service via negative size input in non-secure module functions axios: axios: Denial of Service via uncontrolled recursion in form data processing pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass nanoid: nanoid: Predictable ID generation due to integer overflow fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: undici: Denial of Service via unrequested WebSocket subprotocol encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification urllib: urllib: Credential leakage via cross-origin redirects net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages nanoid: nanoid: Denial of Service via negative size input in non-secure module functions axios: axios: Denial of Service via uncontrolled recursion in form data processing pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass nanoid: nanoid: Predictable ID generation due to integer overflow fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:69248</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-83608</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83608</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE branch in lib/dom.js validates publicId, systemId, and internalSubset under requireWellFormed: true but emits DocumentType.name verbatim. A name containing &amp;gt; or whitespace can terminate the &amp;lt;!DOCTYPE ...&amp;gt; declaration and inject sibling markup; the value can be supplied through createDocumentType() on the 0.8.x and unscoped lines or through a direct DocumentType.name property write on every affected line. The default path and legacy creation-time behavior remain permissive, while the vulnerable strict path fails to enforce an XML Name. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE branch in lib/dom.js validates publicId, systemId, and internalSubset under requireWellFormed: true but emits DocumentType.name verbatim. A name containing &amp;gt; or whitespace can terminate the &amp;lt;!DOCTYPE ...&amp;gt; declaration and inject sibling markup; the value can be supplied through createDocumentType() on the 0.8.x and unscoped lines or through a direct DocumentType.name property write on every affected line. The default path and legacy creation-time behavior remain permissive, while the vulnerable strict path fails to enforce an XML Name. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83608</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
