<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:27:03 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-13729</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-13729</link>
      <description>bdu:2026-13729</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-13729</guid>
    </item>
    <item>
      <title>EUVD-2026-363633</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363633</link>
      <description>EUVD-2026-363633</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363633</guid>
    </item>
    <item>
      <title>fkie_cve-2026-83618</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83618</link>
      <description>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requireWellFormed: true serializer validates DocumentType.publicId and DocumentType.systemId with PubidLiteral_match and SystemLiteral_match expressions produced by reg() in lib/grammar.js, which inherit the multiline flag. A complete valid literal on the first line can therefore satisfy the matcher while U+000A, U+000D, U+2028, or U+2029 and breakout markup remain in the emitted &amp;lt;!DOCTYPE ...&amp;gt; declaration. This bypasses the strict-serialization mitigation for the earlier DocumentType injection advisory; creation and direct property assignment remain unvalidated by design. This issue is fixed in @xmldom/xmldom version 0.9.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requireWellFormed: true serializer validates DocumentType.publicId and DocumentType.systemId with PubidLiteral_match and SystemLiteral_match expressions produced by reg() in lib/grammar.js, which inherit the multiline flag. A complete valid literal on the first line can therefore satisfy the matcher while U+000A, U+000D, U+2028, or U+2029 and breakout markup remain in the emitted &amp;lt;!DOCTYPE ...&amp;gt; declaration. This bypasses the strict-serialization mitigation for the earlier DocumentType injection advisory; creation and direct property assignment remain unvalidated by design. This issue is fixed in @xmldom/xmldom version 0.9.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-83618</guid>
    </item>
    <item>
      <title>GHSA-vr34-hp96-76pp — xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vr34-hp96-76pp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An embedded line terminator bypasses the `requireWellFormed` serializer check for a `DocumentType`&amp;#39;s
publicId and systemId. The check was added to fix GHSA-f6ww-3ggp-fr8h; an id whose first line is a
valid literal slips past it and is emitted verbatim into the `&amp;lt;!DOCTYPE …&amp;gt;` declaration, so the markup
after the line terminator breaks out into the surrounding document. Callers who enabled
`requireWellFormed` to neutralize DocumentType injection remain exposed.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`publicId` and `systemId` are stored as raw values **including their surrounding quotes**, and the
`PubidLiteral`/`SystemLiteral` productions include those quotes. The serializer validates them with
`g.PubidLiteral_match.test(publicId)` and `g.SystemLiteral_match.test(systemId)`, where both matchers
are `reg(&amp;#39;^&amp;#39;, …, &amp;#39;$&amp;#39;)` and inherit the `m` flag from xmldom&amp;#39;s shared regexp builder. Under `m`, `$`
matches at an interior line terminator, so a value such as `&amp;#34;valid pubid&amp;#34;\n&amp;#34;&amp;gt;&amp;lt;!ENTITY …&amp;gt;` satisfies
the matcher on its first line (`&amp;#34;valid pubid&amp;#34;` is a complete `PubidLiteral`) and the whole value —
including the post-newline breakout — is emitted after `PUBLIC`/`SYSTEM`.&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;1. A shared regexp builder compiles anchored productions with the `m` flag.
2. `^…$` under `m` are line anchors, not string anchors.
3. A full-string validator built on such a production (`.test()`) accepts any string with one
   conforming line, so a complete, valid literal on the first line passes even though a line…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An embedded line terminator bypasses the `requireWellFormed` serializer check for a `DocumentType`&amp;#39;s
publicId and systemId. The check was added to fix GHSA-f6ww-3ggp-fr8h; an id whose first line is a
valid literal slips past it and is emitted verbatim into the `&amp;lt;!DOCTYPE …&amp;gt;` declaration, so the markup
after the line terminator breaks out into the surrounding document. Callers who enabled
`requireWellFormed` to neutralize DocumentType injection remain exposed.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`publicId` and `systemId` are stored as raw values **including their surrounding quotes**, and the
`PubidLiteral`/`SystemLiteral` productions include those quotes. The serializer validates them with
`g.PubidLiteral_match.test(publicId)` and `g.SystemLiteral_match.test(systemId)`, where both matchers
are `reg(&amp;#39;^&amp;#39;, …, &amp;#39;$&amp;#39;)` and inherit the `m` flag from xmldom&amp;#39;s shared regexp builder. Under `m`, `$`
matches at an interior line terminator, so a value such as `&amp;#34;valid pubid&amp;#34;\n&amp;#34;&amp;gt;&amp;lt;!ENTITY …&amp;gt;` satisfies
the matcher on its first line (`&amp;#34;valid pubid&amp;#34;` is a complete `PubidLiteral`) and the whole value —
including the post-newline breakout — is emitted after `PUBLIC`/`SYSTEM`.&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;1. A shared regexp builder compiles anchored productions with the `m` flag.
2. `^…$` under `m` are line anchors, not string anchors.
3. A full-string validator built on such a production (`.test()`) accepts any string with one
   conforming line, so a complete, valid literal on the first line passes even though a line…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vr34-hp96-76pp</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-83618</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83618</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requireWellFormed: true serializer validates DocumentType.publicId and DocumentType.systemId with PubidLiteral_match and SystemLiteral_match expressions produced by reg() in lib/grammar.js, which inherit the multiline flag. A complete valid literal on the first line can therefore satisfy the matcher while U+000A, U+000D, U+2028, or U+2029 and breakout markup remain in the emitted &amp;lt;!DOCTYPE ...&amp;gt; declaration. This bypasses the strict-serialization mitigation for the earlier DocumentType injection advisory; creation and direct property assignment remain unvalidated by design. This issue is fixed in @xmldom/xmldom version 0.9.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requireWellFormed: true serializer validates DocumentType.publicId and DocumentType.systemId with PubidLiteral_match and SystemLiteral_match expressions produced by reg() in lib/grammar.js, which inherit the multiline flag. A complete valid literal on the first line can therefore satisfy the matcher while U+000A, U+000D, U+2028, or U+2029 and breakout markup remain in the emitted &amp;lt;!DOCTYPE ...&amp;gt; declaration. This bypasses the strict-serialization mitigation for the earlier DocumentType injection advisory; creation and direct property assignment remain unvalidated by design. This issue is fixed in @xmldom/xmldom version 0.9.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83618</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
