<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:32:19 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</link>
      <description>certfr-2026-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-GJ99967 — Security fixes in npm 11.14.0-r3</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-gj99967</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: npm&lt;/p&gt;
&lt;p&gt;Package npm version 11.14.0-r3 fixes 2 vulnerabilities: CVE-2026-53655, CVE-2026-9358&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: npm&lt;/p&gt;
&lt;p&gt;Package npm version 11.14.0-r3 fixes 2 vulnerabilities: CVE-2026-53655, CVE-2026-9358&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-gj99967</guid>
    </item>
    <item>
      <title>EUVD-2026-327219</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-327219</link>
      <description>EUVD-2026-327219</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-327219</guid>
    </item>
    <item>
      <title>fkie_cve-2026-9358</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9358</link>
      <description>&lt;p&gt;A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 6.1.3 and 7.1.3 is able to address this issue. This patch is called 5bc698cef66f8abd12610dc623e5d67cbc0f869d. It is suggested to upgrade the affected component. The vendor explains, that according to his definition &amp;#34;DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS).&amp;#34; The commits were backported to 6.x branch, which was the most downloaded version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 6.1.3 and 7.1.3 is able to address this issue. This patch is called 5bc698cef66f8abd12610dc623e5d67cbc0f869d. It is suggested to upgrade the affected component. The vendor explains, that according to his definition &amp;#34;DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS).&amp;#34; The commits were backported to 6.x branch, which was the most downloaded version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-9358</guid>
    </item>
    <item>
      <title>GHSA-w9m9-85wc-3x92 — postcss-selector-parser allows denial of service through uncontrolled AST recursion</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w9m9-85wc-3x92</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: postcss-selector-parser&lt;/p&gt;
&lt;p&gt;A vulnerability was determined in postcss-selector-parser before 6.1.3 and 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains, that according to his definition &amp;#34;DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS).&amp;#34;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: postcss-selector-parser&lt;/p&gt;
&lt;p&gt;A vulnerability was determined in postcss-selector-parser before 6.1.3 and 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains, that according to his definition &amp;#34;DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS).&amp;#34;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w9m9-85wc-3x92</guid>
    </item>
    <item>
      <title>RHSA-2026:22934 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:22934</link>
      <description>&lt;p&gt;undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing postcss-selector-parser: Postcss: Denial of Service via uncontrolled recursion in AST Serialization undici: undici WebSocket client vulnerable to denial of service via cumulative fragment bypass undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy urllib3: urllib3: Denial of Service due to excessive HTTP response decompression brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing postcss-selector-parser: Postcss: Denial of Service via uncontrolled recursion in AST Serialization undici: undici WebSocket client vulnerable to denial of service via cumulative fragment bypass undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy urllib3: urllib3: Denial of Service due to excessive HTTP response decompression brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:22934</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-9358</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9358</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-css-loader, Ubuntu:22.04:LTS: node-css-loader, Ubuntu:24.04:LTS: node-css-loader, Ubuntu:25.10: node-css-loader, Ubuntu:26.04:LTS: node-css-loader&lt;/p&gt;
&lt;p&gt;A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 6.1.3 and 7.1.3 is able to address this issue. This patch is called 5bc698cef66f8abd12610dc623e5d67cbc0f869d. It is suggested to upgrade the affected component. The vendor explains, that according to his definition &amp;#34;DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS).&amp;#34; The commits were backported to 6.x branch, which was the most downloaded version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-css-loader, Ubuntu:22.04:LTS: node-css-loader, Ubuntu:24.04:LTS: node-css-loader, Ubuntu:25.10: node-css-loader, Ubuntu:26.04:LTS: node-css-loader&lt;/p&gt;
&lt;p&gt;A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 6.1.3 and 7.1.3 is able to address this issue. This patch is called 5bc698cef66f8abd12610dc623e5d67cbc0f869d. It is suggested to upgrade the affected component. The vendor explains, that according to his definition &amp;#34;DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS).&amp;#34; The commits were backported to 6.x branch, which was the most downloaded version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9358</guid>
    </item>
  </channel>
</rss>
