<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:05:50 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-195577</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-195577</link>
      <description>EUVD-2026-195577</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-195577</guid>
    </item>
    <item>
      <title>fkie_cve-2024-9506</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-9506</link>
      <description>&lt;p&gt;Improper regular expression in Vue&amp;#39;s parseHTML function leads to a potential regular expression denial of service vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper regular expression in Vue&amp;#39;s parseHTML function leads to a potential regular expression denial of service vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-9506</guid>
    </item>
    <item>
      <title>GHSA-5j4c-8p2g-v4jx — ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5j4c-8p2g-v4jx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vue&lt;/p&gt;
&lt;p&gt;The ReDoS can be exploited through the `parseHTML` function in the `html-parser.ts` file. This flaw allows attackers to slow down the application by providing specially crafted input that causes inefficient processing of regular expressions, leading to excessive resource consumption.&lt;/p&gt;
&lt;p&gt;To demonstrate this vulnerability, here&amp;#39;s an example. In a Vue client-side application, create a new Vue instance with a template string that includes a `&amp;lt;script&amp;gt;` tag but closes it incorrectly with something like `&amp;lt;/textarea&amp;gt;`.&lt;/p&gt;
&lt;p&gt;```javascript
new Vue({
  el: &amp;#39;#app&amp;#39;,
  template: &amp;#39;
    &amp;lt;div&amp;gt;
      Hello, world!
      &amp;lt;script&amp;gt;${&amp;#39;&amp;lt;&amp;#39;.repeat(1000000)}&amp;lt;/textarea&amp;gt;
    &amp;lt;/div&amp;gt;&amp;#39;
});
```
Next, set up a basic HTML page (e.g., index.html) to load this JavaScript and mount the Vue instance:&lt;/p&gt;
&lt;p&gt;```html
&amp;lt;!DOCTYPE html&amp;gt;
&amp;lt;html&amp;gt;
&amp;lt;head&amp;gt;
  &amp;lt;title&amp;gt;My first Vue app&amp;lt;/title&amp;gt;
&amp;lt;/head&amp;gt;
&amp;lt;body&amp;gt;
  &amp;lt;div id=\&amp;#34;app\&amp;#34;&amp;gt;Loading...&amp;lt;/div&amp;gt;
&amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;
```&lt;/p&gt;
&lt;p&gt;When you visit the app in your browser at http://localhost:3000, you&amp;#39;ll notice that the time taken to parse and mount the Vue application increases significantly due to the ReDoS vulnerability, demonstrating how the flaw can affect performance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vue&lt;/p&gt;
&lt;p&gt;The ReDoS can be exploited through the `parseHTML` function in the `html-parser.ts` file. This flaw allows attackers to slow down the application by providing specially crafted input that causes inefficient processing of regular expressions, leading to excessive resource consumption.&lt;/p&gt;
&lt;p&gt;To demonstrate this vulnerability, here&amp;#39;s an example. In a Vue client-side application, create a new Vue instance with a template string that includes a `&amp;lt;script&amp;gt;` tag but closes it incorrectly with something like `&amp;lt;/textarea&amp;gt;`.&lt;/p&gt;
&lt;p&gt;```javascript
new Vue({
  el: &amp;#39;#app&amp;#39;,
  template: &amp;#39;
    &amp;lt;div&amp;gt;
      Hello, world!
      &amp;lt;script&amp;gt;${&amp;#39;&amp;lt;&amp;#39;.repeat(1000000)}&amp;lt;/textarea&amp;gt;
    &amp;lt;/div&amp;gt;&amp;#39;
});
```
Next, set up a basic HTML page (e.g., index.html) to load this JavaScript and mount the Vue instance:&lt;/p&gt;
&lt;p&gt;```html
&amp;lt;!DOCTYPE html&amp;gt;
&amp;lt;html&amp;gt;
&amp;lt;head&amp;gt;
  &amp;lt;title&amp;gt;My first Vue app&amp;lt;/title&amp;gt;
&amp;lt;/head&amp;gt;
&amp;lt;body&amp;gt;
  &amp;lt;div id=\&amp;#34;app\&amp;#34;&amp;gt;Loading...&amp;lt;/div&amp;gt;
&amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;
```&lt;/p&gt;
&lt;p&gt;When you visit the app in your browser at http://localhost:3000, you&amp;#39;ll notice that the time taken to parse and mount the Vue application increases significantly due to the ReDoS vulnerability, demonstrating how the flaw can affect performance.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5j4c-8p2g-v4jx</guid>
    </item>
  </channel>
</rss>
