<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:43:31 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-8829</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-8829</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl-html-parser, Alpaquita:25: perl-html-parser, Alpaquita:stream: perl-html-parser&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl-html-parser, Alpaquita:25: perl-html-parser, Alpaquita:stream: perl-html-parser&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-8829</guid>
    </item>
    <item>
      <title>BREW-extract_url-CVE-2026-8829 — HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities</title>
      <link>https://cve.radiocsirt.org/vuln/brew-extract_url-cve-2026-8829</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: extract_url&lt;/p&gt;
&lt;p&gt;HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.&lt;/p&gt;
&lt;p&gt;The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV&amp;#39;s PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.&lt;/p&gt;
&lt;p&gt;The read may disclose adjacent heap contents into the destination SV.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: extract_url&lt;/p&gt;
&lt;p&gt;HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.&lt;/p&gt;
&lt;p&gt;The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV&amp;#39;s PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.&lt;/p&gt;
&lt;p&gt;The read may disclose adjacent heap contents into the destination SV.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-extract_url-cve-2026-8829</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0737 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0737</link>
      <description>certfr-2026-avi-0737</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0737</guid>
    </item>
    <item>
      <title>EUVD-2026-330909</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330909</link>
      <description>EUVD-2026-330909</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330909</guid>
    </item>
    <item>
      <title>fkie_cve-2026-8829</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8829</link>
      <description>&lt;p&gt;HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.&lt;/p&gt;
&lt;p&gt;The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV&amp;#39;s PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.&lt;/p&gt;
&lt;p&gt;The read may disclose adjacent heap contents into the destination SV.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.&lt;/p&gt;
&lt;p&gt;The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV&amp;#39;s PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.&lt;/p&gt;
&lt;p&gt;The read may disclose adjacent heap contents into the destination SV.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-8829</guid>
    </item>
    <item>
      <title>GHSA-9p7j-9995-m88w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9p7j-9995-m88w</link>
      <description>&lt;p&gt;HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.&lt;/p&gt;
&lt;p&gt;The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV&amp;#39;s PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.&lt;/p&gt;
&lt;p&gt;The read may disclose adjacent heap contents into the destination SV.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.&lt;/p&gt;
&lt;p&gt;The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV&amp;#39;s PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.&lt;/p&gt;
&lt;p&gt;The read may disclose adjacent heap contents into the destination SV.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9p7j-9995-m88w</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-8829 — HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-8829</link>
      <description>msrc_CVE-2026-8829</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-8829</guid>
    </item>
    <item>
      <title>NCSC-2026-0321 — Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0321</link>
      <description>NCSC-2026-0321</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0321</guid>
    </item>
    <item>
      <title>OESA-2026-2672 — perl-HTML-Parser security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2672</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: perl-HTML-Parser, openEuler:24.03-LTS-SP3: perl-HTML-Parser, openEuler:20.03-LTS-SP4: perl-HTML-Parser, openEuler:22.03-LTS-SP4: perl-HTML-Parser&lt;/p&gt;
&lt;p&gt;Objects of the HTML::Parser class will recognize markup and separate it from plain text (alias data content) in HTML documents. As different kinds of markup and text are recognized, the corresponding event handlers are invoked.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.&lt;/p&gt;
&lt;p&gt;The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV&amp;amp;apos;s PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.&lt;/p&gt;
&lt;p&gt;The read may disclose adjacent heap contents into the destination SV.(CVE-2026-8829)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: perl-HTML-Parser, openEuler:24.03-LTS-SP3: perl-HTML-Parser, openEuler:20.03-LTS-SP4: perl-HTML-Parser, openEuler:22.03-LTS-SP4: perl-HTML-Parser&lt;/p&gt;
&lt;p&gt;Objects of the HTML::Parser class will recognize markup and separate it from plain text (alias data content) in HTML documents. As different kinds of markup and text are recognized, the corresponding event handlers are invoked.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities.&lt;/p&gt;
&lt;p&gt;The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV&amp;amp;apos;s PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation.&lt;/p&gt;
&lt;p&gt;The read may disclose adjacent heap contents into the destination SV.(CVE-2026-8829)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2672</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10957-1 — perl-HTML-Parser-3.850.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10957-1</link>
      <description>&lt;p&gt;perl-HTML-Parser-3.850.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;perl-HTML-Parser-3.850.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10957-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22189-1 — Security update for perl-HTML-Parser</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22189-1</link>
      <description>&lt;p&gt;Security update for perl-HTML-Parser&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for perl-HTML-Parser&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22189-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-8829</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8829</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libhtml-parser-perl, Ubuntu:16.04:LTS: libhtml-parser-perl, Ubuntu:18.04:LTS: libhtml-parser-perl, Ubuntu:20.04:LTS: libhtml-parser-perl, Ubuntu:22.04:LTS: libhtml-parser-perl, Ubuntu:24.04:LTS: libhtml-parser-perl, Ubuntu:25.10: libhtml-parser-perl, Ubuntu:26.04:LTS: libhtml-parser-perl&lt;/p&gt;
&lt;p&gt;HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV&amp;#39;s PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation. The read may disclose adjacent heap contents into the destination SV.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libhtml-parser-perl, Ubuntu:16.04:LTS: libhtml-parser-perl, Ubuntu:18.04:LTS: libhtml-parser-perl, Ubuntu:20.04:LTS: libhtml-parser-perl, Ubuntu:22.04:LTS: libhtml-parser-perl, Ubuntu:24.04:LTS: libhtml-parser-perl, Ubuntu:25.10: libhtml-parser-perl, Ubuntu:26.04:LTS: libhtml-parser-perl&lt;/p&gt;
&lt;p&gt;HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated the SV&amp;#39;s PV buffer and freed the backing allocation that repl still pointed into. The subsequent copy loop read repl_len bytes from the freed allocation. The read may disclose adjacent heap contents into the destination SV.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-8829</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2858 — IBM AIX und VIOS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2858</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM AIX und IBM VIOS ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM AIX und IBM VIOS ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2858</guid>
    </item>
  </channel>
</rss>
