<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 09:19:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-254082</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-254082</link>
      <description>EUVD-2026-254082</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-254082</guid>
    </item>
    <item>
      <title>fkie_cve-2025-61668</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-61668</link>
      <description>&lt;p&gt;Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. This issue is fixed in versions 16.34.1, 17.22.2, 18.27.2 and 19.0.0-alpha.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. This issue is fixed in versions 16.34.1, 17.22.2, 18.27.2 and 19.0.0-alpha.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-61668</guid>
    </item>
    <item>
      <title>GHSA-m8rj-ppph-mj33 — @plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m8rj-ppph-mj33</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @plone/volto&lt;/p&gt;
&lt;p&gt;### Impact
When visiting a specific URL, an anonymous user could cause the NodeJS server part of Volto to quit with an error.&lt;/p&gt;
&lt;p&gt;### Patches
The problem has been patched and the patch has been backported to Volto major versions down until 16. It is advised to upgrade to the latest patch release of your respective current major version:&lt;/p&gt;
&lt;p&gt;- Volto 16: [16.34.1](https://github.com/plone/volto/releases/tag/16.34.1)
- Volto 17: [17.22.2](https://github.com/plone/volto/releases/tag/17.22.2)
- Volto 18: [18.27.2](https://github.com/plone/volto/releases/tag/18.27.2)
- Volto 19: [19.0.0-alpha6](https://github.com/plone/volto/releases/tag/19.0.0-alpha.6)&lt;/p&gt;
&lt;p&gt;### Workarounds
Make sure your setup automatically restarts processes that quit with an error. This won&amp;#39;t prevent a crash, but it minimises downtime.&lt;/p&gt;
&lt;p&gt;### Report
The problem was discovered by FHNW, a client of Plone provider kitconcept, who shared it with the Plone Zope Security Team (security@plone.org).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @plone/volto&lt;/p&gt;
&lt;p&gt;### Impact
When visiting a specific URL, an anonymous user could cause the NodeJS server part of Volto to quit with an error.&lt;/p&gt;
&lt;p&gt;### Patches
The problem has been patched and the patch has been backported to Volto major versions down until 16. It is advised to upgrade to the latest patch release of your respective current major version:&lt;/p&gt;
&lt;p&gt;- Volto 16: [16.34.1](https://github.com/plone/volto/releases/tag/16.34.1)
- Volto 17: [17.22.2](https://github.com/plone/volto/releases/tag/17.22.2)
- Volto 18: [18.27.2](https://github.com/plone/volto/releases/tag/18.27.2)
- Volto 19: [19.0.0-alpha6](https://github.com/plone/volto/releases/tag/19.0.0-alpha.6)&lt;/p&gt;
&lt;p&gt;### Workarounds
Make sure your setup automatically restarts processes that quit with an error. This won&amp;#39;t prevent a crash, but it minimises downtime.&lt;/p&gt;
&lt;p&gt;### Report
The problem was discovered by FHNW, a client of Plone provider kitconcept, who shared it with the Plone Zope Security Team (security@plone.org).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m8rj-ppph-mj33</guid>
    </item>
  </channel>
</rss>
