<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:29:03 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-13730</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-13730</link>
      <description>bdu:2026-13730</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-13730</guid>
    </item>
    <item>
      <title>EUVD-2026-362685</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362685</link>
      <description>EUVD-2026-362685</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362685</guid>
    </item>
    <item>
      <title>fkie_cve-2026-83619</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83619</link>
      <description>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release-0.8.x parser in lib/sax.js trims captured end-tag names with the unanchored global expression /[ \t\n\r]+$/g. For an end tag containing a long whitespace run followed by a non-whitespace character, the expression retries from each possible starting position and backtracks quadratically before failing its end anchor. DOMParser.parseFromString() reaches the path under default options, allowing a small unauthenticated XML input to stall the Node.js event loop; the 0.9.x and unscoped npm lines do not contain this expression. This issue is fixed in @xmldom/xmldom version 0.8.15.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release-0.8.x parser in lib/sax.js trims captured end-tag names with the unanchored global expression /[ \t\n\r]+$/g. For an end tag containing a long whitespace run followed by a non-whitespace character, the expression retries from each possible starting position and backtracks quadratically before failing its end anchor. DOMParser.parseFromString() reaches the path under default options, allowing a small unauthenticated XML input to stall the Node.js event loop; the 0.9.x and unscoped npm lines do not contain this expression. This issue is fixed in @xmldom/xmldom version 0.8.15.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-83619</guid>
    </item>
    <item>
      <title>GHSA-x4fp-j954-r2f4 — xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x4fp-j954-r2f4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On the `@xmldom/xmldom` **`0.8.x`** line, parsing an XML end tag whose name is followed by a long run
of whitespace and then a non-whitespace character triggers quadratic-time regular-expression
backtracking (ReDoS), so a single small crafted end tag stalls the Node.js event loop. It is reachable
from `DOMParser.parseFromString` under **default options**, unauthenticated, before any validity
check — an availability-only denial of service. The `0.9.x` line is **not** affected.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`lib/sax.js` (release-0.8.x, commit `e5c1480`) trims trailing whitespace from a captured end-tag name
with an unanchored global regex:&lt;/p&gt;
&lt;p&gt;- `lib/sax.js` line 120: https://github.com/xmldom/xmldom/blob/e5c14802592685bb872c042c54c3f73758875c85/lib/sax.js#L120&lt;/p&gt;
&lt;p&gt;```js
/[ \t\n\r]+$/g
```&lt;/p&gt;
&lt;p&gt;Applied to a string shaped `whitespace-run + one non-whitespace char` (e.g. the content of an end tag
`&amp;lt;/   …   x&amp;gt;`), the engine must, for every starting position, extend `[ws]+` to the end and then fail
the `$` anchor when the trailing non-whitespace char is present — classic O(n²) backtracking in the
length of the whitespace run. The trimmed substring is delimited only by `indexOf(&amp;#39;&amp;gt;&amp;#39;)`, so the
attacker controls its length directly.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```js
const { DOMParser } = require(&amp;#39;@xmldom/xmldom&amp;#39;); // 0.8.x
const n = 64 * 1024;
const payload = &amp;#39;&amp;lt;r&amp;gt;&amp;lt;/&amp;#39; + &amp;#39; &amp;#39;.repeat(n) + &amp;#39;x&amp;gt;&amp;#39;;
console.time(&amp;#39;parse&amp;#39;);
new DOMParser().parseFromString(payload, &amp;#39;text/xml&amp;#39;);
console.timeEnd(&amp;#39;parse&amp;#39;);
```&lt;/p&gt;
&lt;p&gt;Measured…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On the `@xmldom/xmldom` **`0.8.x`** line, parsing an XML end tag whose name is followed by a long run
of whitespace and then a non-whitespace character triggers quadratic-time regular-expression
backtracking (ReDoS), so a single small crafted end tag stalls the Node.js event loop. It is reachable
from `DOMParser.parseFromString` under **default options**, unauthenticated, before any validity
check — an availability-only denial of service. The `0.9.x` line is **not** affected.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`lib/sax.js` (release-0.8.x, commit `e5c1480`) trims trailing whitespace from a captured end-tag name
with an unanchored global regex:&lt;/p&gt;
&lt;p&gt;- `lib/sax.js` line 120: https://github.com/xmldom/xmldom/blob/e5c14802592685bb872c042c54c3f73758875c85/lib/sax.js#L120&lt;/p&gt;
&lt;p&gt;```js
/[ \t\n\r]+$/g
```&lt;/p&gt;
&lt;p&gt;Applied to a string shaped `whitespace-run + one non-whitespace char` (e.g. the content of an end tag
`&amp;lt;/   …   x&amp;gt;`), the engine must, for every starting position, extend `[ws]+` to the end and then fail
the `$` anchor when the trailing non-whitespace char is present — classic O(n²) backtracking in the
length of the whitespace run. The trimmed substring is delimited only by `indexOf(&amp;#39;&amp;gt;&amp;#39;)`, so the
attacker controls its length directly.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```js
const { DOMParser } = require(&amp;#39;@xmldom/xmldom&amp;#39;); // 0.8.x
const n = 64 * 1024;
const payload = &amp;#39;&amp;lt;r&amp;gt;&amp;lt;/&amp;#39; + &amp;#39; &amp;#39;.repeat(n) + &amp;#39;x&amp;gt;&amp;#39;;
console.time(&amp;#39;parse&amp;#39;);
new DOMParser().parseFromString(payload, &amp;#39;text/xml&amp;#39;);
console.timeEnd(&amp;#39;parse&amp;#39;);
```&lt;/p&gt;
&lt;p&gt;Measured…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x4fp-j954-r2f4</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-83619 — xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-83619</link>
      <description>msrc_CVE-2026-83619</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-83619</guid>
    </item>
    <item>
      <title>RHSA-2026:69248 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.9 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:69248</link>
      <description>&lt;p&gt;undici: undici: Denial of Service via unrequested WebSocket subprotocol encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification urllib: urllib: Credential leakage via cross-origin redirects net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages nanoid: nanoid: Denial of Service via negative size input in non-secure module functions axios: axios: Denial of Service via uncontrolled recursion in form data processing pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass nanoid: nanoid: Predictable ID generation due to integer overflow fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: undici: Denial of Service via unrequested WebSocket subprotocol encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification urllib: urllib: Credential leakage via cross-origin redirects net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages nanoid: nanoid: Denial of Service via negative size input in non-secure module functions axios: axios: Denial of Service via uncontrolled recursion in form data processing pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass nanoid: nanoid: Predictable ID generation due to integer overflow fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:69248</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-83619</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83619</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release-0.8.x parser in lib/sax.js trims captured end-tag names with the unanchored global expression /[ \t\n\r]+$/g. For an end tag containing a long whitespace run followed by a non-whitespace character, the expression retries from each possible starting position and backtracks quadratically before failing its end anchor. DOMParser.parseFromString() reaches the path under default options, allowing a small unauthenticated XML input to stall the Node.js event loop; the 0.9.x and unscoped npm lines do not contain this expression. This issue is fixed in @xmldom/xmldom version 0.8.15.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release-0.8.x parser in lib/sax.js trims captured end-tag names with the unanchored global expression /[ \t\n\r]+$/g. For an end tag containing a long whitespace run followed by a non-whitespace character, the expression retries from each possible starting position and backtracks quadratically before failing its end anchor. DOMParser.parseFromString() reaches the path under default options, allowing a small unauthenticated XML input to stall the Node.js event loop; the 0.9.x and unscoped npm lines do not contain this expression. This issue is fixed in @xmldom/xmldom version 0.8.15.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83619</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
