<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:55:07 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-13724</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-13724</link>
      <description>bdu:2026-13724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-13724</guid>
    </item>
    <item>
      <title>EUVD-2026-363536</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363536</link>
      <description>EUVD-2026-363536</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363536</guid>
    </item>
    <item>
      <title>fkie_cve-2026-83615</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83615</link>
      <description>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js uses _copy to clone the complete currentNSMap for each nested element that declares a new namespace prefix. Keeping every ancestor map live on the parse stack creates quadratic peak namespace-map storage, so a small highly compressible XML document can exhaust the process heap before application validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js uses _copy to clone the complete currentNSMap for each nested element that declares a new namespace prefix. Keeping every ancestor map live on the parse stack creates quadratic peak namespace-map storage, so a small highly compressible XML document can exhaust the process heap before application validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-83615</guid>
    </item>
    <item>
      <title>GHSA-965w-775f-mr7g — xmldom: Quadratic-memory consumption</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-965w-775f-mr7g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When an element declares a namespace prefix, xmldom copies the entire in-scope namespace map
into a fresh object and keeps that copy on the element while it is open on the parse stack. A
crafted document that nests N elements, each declaring one unique prefix, therefore drives the
parser to hold on the order of N(N+1)/2 = **O(N²) namespace-map entries at its peak**, so a small,
highly compressible input exhausts the heap. Parsing runs under default options on untrusted,
network-delivered XML, so a sub-megabyte payload can OOM-crash the process before any
application-level validation runs — an unauthenticated denial of service.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`appendElement` performs the copy: `_copy` clones the current namespace map into a fresh object for
each prefix-declaring element, and the copy is retained on that element&amp;#39;s parse-stack entry:&lt;/p&gt;
&lt;p&gt;```js
if (localNSMap == null) {
    localNSMap = Object.create(null);
    _copy(currentNSMap, (currentNSMap = Object.create(null)));   // full copy of all ancestor prefixes
}
currentNSMap[nsPrefix] = localNSMap[nsPrefix] = value;
...
el.currentNSMap = currentNSMap;   // retained while the element is open on the parse stack
```&lt;/p&gt;
&lt;p&gt;https://github.com/xmldom/xmldom/blob/08a22d78e4bc50f12ce9f5090b8d96ee6031ac7b/lib/sax.js#L467-L540&lt;/p&gt;
&lt;p&gt;The copies stack: the element at depth `i` copies a map of size ~`i`, and every ancestor stays live
on the parse stack until it closes, so at the deepest point Σ`i` namespace entries are held at once.
That peak is…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom, npm: xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When an element declares a namespace prefix, xmldom copies the entire in-scope namespace map
into a fresh object and keeps that copy on the element while it is open on the parse stack. A
crafted document that nests N elements, each declaring one unique prefix, therefore drives the
parser to hold on the order of N(N+1)/2 = **O(N²) namespace-map entries at its peak**, so a small,
highly compressible input exhausts the heap. Parsing runs under default options on untrusted,
network-delivered XML, so a sub-megabyte payload can OOM-crash the process before any
application-level validation runs — an unauthenticated denial of service.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`appendElement` performs the copy: `_copy` clones the current namespace map into a fresh object for
each prefix-declaring element, and the copy is retained on that element&amp;#39;s parse-stack entry:&lt;/p&gt;
&lt;p&gt;```js
if (localNSMap == null) {
    localNSMap = Object.create(null);
    _copy(currentNSMap, (currentNSMap = Object.create(null)));   // full copy of all ancestor prefixes
}
currentNSMap[nsPrefix] = localNSMap[nsPrefix] = value;
...
el.currentNSMap = currentNSMap;   // retained while the element is open on the parse stack
```&lt;/p&gt;
&lt;p&gt;https://github.com/xmldom/xmldom/blob/08a22d78e4bc50f12ce9f5090b8d96ee6031ac7b/lib/sax.js#L467-L540&lt;/p&gt;
&lt;p&gt;The copies stack: the element at depth `i` copies a map of size ~`i`, and every ancestor stays live
on the parse stack until it closes, so at the deepest point Σ`i` namespace entries are held at once.
That peak is…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-965w-775f-mr7g</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-83615 — xmldom: Quadratic-memory consumption</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-83615</link>
      <description>msrc_CVE-2026-83615</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-83615</guid>
    </item>
    <item>
      <title>RHSA-2026:69248 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.9 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:69248</link>
      <description>&lt;p&gt;undici: undici: Denial of Service via unrequested WebSocket subprotocol encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification urllib: urllib: Credential leakage via cross-origin redirects net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages nanoid: nanoid: Denial of Service via negative size input in non-secure module functions axios: axios: Denial of Service via uncontrolled recursion in form data processing pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass nanoid: nanoid: Predictable ID generation due to integer overflow fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: undici: Denial of Service via unrequested WebSocket subprotocol encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification urllib: urllib: Credential leakage via cross-origin redirects net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages nanoid: nanoid: Denial of Service via negative size input in non-secure module functions axios: axios: Denial of Service via uncontrolled recursion in form data processing pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass nanoid: nanoid: Predictable ID generation due to integer overflow fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:69248</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-83615</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83615</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js uses _copy to clone the complete currentNSMap for each nested element that declares a new namespace prefix. Keeping every ancestor map live on the parse stack creates quadratic peak namespace-map storage, so a small highly compressible XML document can exhaust the process heap before application validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js uses _copy to clone the complete currentNSMap for each nested element that declares a new namespace prefix. Keeping every ancestor map live on the parse stack creates quadratic peak namespace-map storage, so a small highly compressible XML document can exhaust the process heap before application validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83615</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
