<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:26:47 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-363539</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363539</link>
      <description>EUVD-2026-363539</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363539</guid>
    </item>
    <item>
      <title>fkie_cve-2026-83610</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83610</link>
      <description>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &amp;amp;name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &amp;amp;name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-83610</guid>
    </item>
    <item>
      <title>GHSA-6gmq-8vp8-gcm6 — xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6gmq-8vp8-gcm6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An `EntityReference` node can be created with an invalid, attacker-controlled name through `Document.createEntityReference(name)`. When this node is serialized directly with:&lt;/p&gt;
&lt;p&gt;```js
serializer.serializeToString(ref, { requireWellFormed: true })
```&lt;/p&gt;
&lt;p&gt;the invalid `nodeName` is emitted into the serialized XML fragment without validation or escaping.&lt;/p&gt;
&lt;p&gt;This can produce real XML markup in the serialized output. In the proof of concept below, the serialized fragment contains `&amp;lt;injected/&amp;gt;`, and reparsing the fragment creates a real `injected` element.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The issue appears to be in the serialization path for `ENTITY_REFERENCE_NODE`.&lt;/p&gt;
&lt;p&gt;For several other node types, `requireWellFormed: true` performs specific validation checks before serialization. For example, comments, processing instructions, document types, and some character data cases are checked before being emitted.&lt;/p&gt;
&lt;p&gt;However, for `ENTITY_REFERENCE_NODE`, the serializer appears to emit the node name directly in entity reference form:&lt;/p&gt;
&lt;p&gt;```js
case ENTITY_REFERENCE_NODE:
  buf.push(&amp;#39;&amp;amp;&amp;#39;, n.nodeName, &amp;#39;;&amp;#39;);
  return null;
```&lt;/p&gt;
&lt;p&gt;As a result, if `nodeName` contains characters that break out of the intended `&amp;amp;name;` structure, the serializer can emit additional XML markup.&lt;/p&gt;
&lt;p&gt;For example, an entity reference created with the name:&lt;/p&gt;
&lt;p&gt;```text
safe; &amp;lt;injected/&amp;gt; &amp;amp;x
```&lt;/p&gt;
&lt;p&gt;is serialized as:&lt;/p&gt;
&lt;p&gt;```xml
&amp;amp;safe; &amp;lt;injected/&amp;gt; &amp;amp;x;
```&lt;/p&gt;
&lt;p&gt;When this fragment is later parsed in an XML context, `&amp;lt;injected/&amp;gt;` becomes a real element.&lt;/p&gt;
&lt;p&gt;This…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An `EntityReference` node can be created with an invalid, attacker-controlled name through `Document.createEntityReference(name)`. When this node is serialized directly with:&lt;/p&gt;
&lt;p&gt;```js
serializer.serializeToString(ref, { requireWellFormed: true })
```&lt;/p&gt;
&lt;p&gt;the invalid `nodeName` is emitted into the serialized XML fragment without validation or escaping.&lt;/p&gt;
&lt;p&gt;This can produce real XML markup in the serialized output. In the proof of concept below, the serialized fragment contains `&amp;lt;injected/&amp;gt;`, and reparsing the fragment creates a real `injected` element.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The issue appears to be in the serialization path for `ENTITY_REFERENCE_NODE`.&lt;/p&gt;
&lt;p&gt;For several other node types, `requireWellFormed: true` performs specific validation checks before serialization. For example, comments, processing instructions, document types, and some character data cases are checked before being emitted.&lt;/p&gt;
&lt;p&gt;However, for `ENTITY_REFERENCE_NODE`, the serializer appears to emit the node name directly in entity reference form:&lt;/p&gt;
&lt;p&gt;```js
case ENTITY_REFERENCE_NODE:
  buf.push(&amp;#39;&amp;amp;&amp;#39;, n.nodeName, &amp;#39;;&amp;#39;);
  return null;
```&lt;/p&gt;
&lt;p&gt;As a result, if `nodeName` contains characters that break out of the intended `&amp;amp;name;` structure, the serializer can emit additional XML markup.&lt;/p&gt;
&lt;p&gt;For example, an entity reference created with the name:&lt;/p&gt;
&lt;p&gt;```text
safe; &amp;lt;injected/&amp;gt; &amp;amp;x
```&lt;/p&gt;
&lt;p&gt;is serialized as:&lt;/p&gt;
&lt;p&gt;```xml
&amp;amp;safe; &amp;lt;injected/&amp;gt; &amp;amp;x;
```&lt;/p&gt;
&lt;p&gt;When this fragment is later parsed in an XML context, `&amp;lt;injected/&amp;gt;` becomes a real element.&lt;/p&gt;
&lt;p&gt;This…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6gmq-8vp8-gcm6</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-83610 — xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-83610</link>
      <description>msrc_CVE-2026-83610</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-83610</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-83610</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83610</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &amp;amp;name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &amp;amp;name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83610</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
