<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 16:07:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-5997</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-5997</link>
      <description>EUVD-2026-5997</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-5997</guid>
    </item>
    <item>
      <title>fkie_cve-2024-38364</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-38364</link>
      <description>&lt;p&gt;DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institutions worldwide to provide durable access to digital resources. In DSpace 7.0 through 7.6.1, when an HTML, XML or JavaScript Bitstream is downloaded, the user&amp;#39;s browser may execute any embedded JavaScript. If that embedded JavaScript is malicious, there is a risk of an XSS attack. This vulnerability has been patched in version 7.6.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institutions worldwide to provide durable access to digital resources. In DSpace 7.0 through 7.6.1, when an HTML, XML or JavaScript Bitstream is downloaded, the user&amp;#39;s browser may execute any embedded JavaScript. If that embedded JavaScript is malicious, there is a risk of an XSS attack. This vulnerability has been patched in version 7.6.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-38364</guid>
    </item>
    <item>
      <title>GHSA-94cc-xjxr-pwvf — DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-94cc-xjxr-pwvf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.dspace:dspace-server-webapp&lt;/p&gt;
&lt;p&gt;### Impact
In DSpace 7.0 through 7.6.1, when an HTML, XML or JavaScript Bitstream is downloaded, the user&amp;#39;s browser _may_ execute any embedded JavaScript.  If that embedded JavaScript is malicious, there is a risk of an XSS attack.&lt;/p&gt;
&lt;p&gt;This attack may only be initialized by a user who already has Submitter privileges in the repository. The submitter must upload the malicious HTML/XML/JavaScript file themselves. The attack itself would not occur until a visitor or logged-in user downloads the file or clicks on a download link shared by the attacker.&lt;/p&gt;
&lt;p&gt;If your site is running the frontend and backend from separate domains, CORS and CSRF protection built into DSpace help to limit the impact of the attack.&lt;/p&gt;
&lt;p&gt;If the repository is configured to only download HTML / XML / JavaScript Bitstreams using the [`Content-Disposition: attachment`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Disposition) header, then the attack is no longer possible.  See &amp;#34;Workarounds&amp;#34; below.&lt;/p&gt;
&lt;p&gt;### Patches
The fix is included in both 8.0 and 7.6.2.  Please upgrade to one of these versions, or manually apply one of the &amp;#34;Workarounds&amp;#34; below.&lt;/p&gt;
&lt;p&gt;If you are already running 7.6 or 7.6.1, then this vulnerability can be fixed via a configuration update in your `dspace.cfg` configuration file.  See details in below.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;**DSpace sites running 7.6 or 7.6.1** can fix this issue by adding the following `webui.content_disposition_format` settings to their `dspace.cfg` (or `local.cfg`).  Thes…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.dspace:dspace-server-webapp&lt;/p&gt;
&lt;p&gt;### Impact
In DSpace 7.0 through 7.6.1, when an HTML, XML or JavaScript Bitstream is downloaded, the user&amp;#39;s browser _may_ execute any embedded JavaScript.  If that embedded JavaScript is malicious, there is a risk of an XSS attack.&lt;/p&gt;
&lt;p&gt;This attack may only be initialized by a user who already has Submitter privileges in the repository. The submitter must upload the malicious HTML/XML/JavaScript file themselves. The attack itself would not occur until a visitor or logged-in user downloads the file or clicks on a download link shared by the attacker.&lt;/p&gt;
&lt;p&gt;If your site is running the frontend and backend from separate domains, CORS and CSRF protection built into DSpace help to limit the impact of the attack.&lt;/p&gt;
&lt;p&gt;If the repository is configured to only download HTML / XML / JavaScript Bitstreams using the [`Content-Disposition: attachment`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Disposition) header, then the attack is no longer possible.  See &amp;#34;Workarounds&amp;#34; below.&lt;/p&gt;
&lt;p&gt;### Patches
The fix is included in both 8.0 and 7.6.2.  Please upgrade to one of these versions, or manually apply one of the &amp;#34;Workarounds&amp;#34; below.&lt;/p&gt;
&lt;p&gt;If you are already running 7.6 or 7.6.1, then this vulnerability can be fixed via a configuration update in your `dspace.cfg` configuration file.  See details in below.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;**DSpace sites running 7.6 or 7.6.1** can fix this issue by adding the following `webui.content_disposition_format` settings to their `dspace.cfg` (or `local.cfg`).  Thes…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-94cc-xjxr-pwvf</guid>
    </item>
  </channel>
</rss>
