<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:47:31 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275297</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275297</link>
      <description>EUVD-2026-275297</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275297</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68467</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68467</link>
      <description>&lt;p&gt;Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the extension works by analyzing the colors of web pages found in CSS style sheet files. In order to analyze cross-origin style sheets (stored on websites different from the original web page), Dark Reader requests such files via a background worker, ensuring the request is performed with no credentials and that the content type of the response is a CSS file. Prior to Dark Reader 4.9.117, this style content was assigned to an HTML Style Element in order to parse and loop through style declarations, and also stored in page&amp;#39;s Session Storage for performance gains. This could allow a website author to request a style sheet from a locally running web server, for example by having a link pointing to `http[:]//localhost[:]8080/style[.]css`. The brute force of the host name, port and file name would be unlikely due to performance impact, that would cause the browser tab to hang shortly, but it could be possible to request a style sheet if the full URL was known in advance. As per December 18, 2025 there is no known exploit of the issue. The problem has been fixed in version 4.9.117 on December 3, 2025. The style sheets are now parsed using modern Constructed Style Sheets API and the contents of cross-origin style sheets is no longer stored in page&amp;#39;s Session Storage. Version 4.9.118 (December 8, 2025) restricts cross-origin requests to localhost aliases, IP addresses,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the extension works by analyzing the colors of web pages found in CSS style sheet files. In order to analyze cross-origin style sheets (stored on websites different from the original web page), Dark Reader requests such files via a background worker, ensuring the request is performed with no credentials and that the content type of the response is a CSS file. Prior to Dark Reader 4.9.117, this style content was assigned to an HTML Style Element in order to parse and loop through style declarations, and also stored in page&amp;#39;s Session Storage for performance gains. This could allow a website author to request a style sheet from a locally running web server, for example by having a link pointing to `http[:]//localhost[:]8080/style[.]css`. The brute force of the host name, port and file name would be unlikely due to performance impact, that would cause the browser tab to hang shortly, but it could be possible to request a style sheet if the full URL was known in advance. As per December 18, 2025 there is no known exploit of the issue. The problem has been fixed in version 4.9.117 on December 3, 2025. The style sheets are now parsed using modern Constructed Style Sheets API and the contents of cross-origin style sheets is no longer stored in page&amp;#39;s Session Storage. Version 4.9.118 (December 8, 2025) restricts cross-origin requests to localhost aliases, IP addresses,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68467</guid>
    </item>
    <item>
      <title>GHSA-x369-mcw8-8rvj — Dark Reader gives users the ability to request style sheets from local web servers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x369-mcw8-8rvj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: darkreader&lt;/p&gt;
&lt;p&gt;### Description
Dark Reader versions prior to 4.9.117 included a behavior where a website could request a style sheet from a locally running web server, for example `http://localhost:8080/style.css`, If an address was available and returned a `text/css` content type.&lt;/p&gt;
&lt;p&gt;### Patches
The problem was fixed in version 4.9.117, released on December 3, 2025. Most users received the update automatically. Users running manual builds must upgrade to version 4.9.117 or later.&lt;/p&gt;
&lt;p&gt;The installed extension version number can be verified in Dark Reader&amp;#39;s menu (More &amp;gt; All settings &amp;gt; About), browser settings, `chrome://extensions` or `about:addons` pages.&lt;/p&gt;
&lt;p&gt;Users are encouraged not to disable automatic extension updates and use the latest browser version, as browser releases typically include multiple security fixes of varying severity.&lt;/p&gt;
&lt;p&gt;### NPM package&lt;/p&gt;
&lt;p&gt;The issue does not affect developers using the `darkreader` NPM package for website integration. Developers using the `setFetchMethod()` API must ensure the cross-origin requests are restricted to the intended scope.&lt;/p&gt;
&lt;p&gt;### Custom forks&lt;/p&gt;
&lt;p&gt;Developers using custom forks of earlier versions of Dark Reader to build other extensions, or integrating it into their apps or browsers, should review their implementation to ensure cross-origin requests are handled securely.&lt;/p&gt;
&lt;p&gt;### Acknowledgements
Security research performed by [Brian Carpenter](https://x.com/geeknik) - [Deep Fork Cyber](https://deepforkcyber.com/).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: darkreader&lt;/p&gt;
&lt;p&gt;### Description
Dark Reader versions prior to 4.9.117 included a behavior where a website could request a style sheet from a locally running web server, for example `http://localhost:8080/style.css`, If an address was available and returned a `text/css` content type.&lt;/p&gt;
&lt;p&gt;### Patches
The problem was fixed in version 4.9.117, released on December 3, 2025. Most users received the update automatically. Users running manual builds must upgrade to version 4.9.117 or later.&lt;/p&gt;
&lt;p&gt;The installed extension version number can be verified in Dark Reader&amp;#39;s menu (More &amp;gt; All settings &amp;gt; About), browser settings, `chrome://extensions` or `about:addons` pages.&lt;/p&gt;
&lt;p&gt;Users are encouraged not to disable automatic extension updates and use the latest browser version, as browser releases typically include multiple security fixes of varying severity.&lt;/p&gt;
&lt;p&gt;### NPM package&lt;/p&gt;
&lt;p&gt;The issue does not affect developers using the `darkreader` NPM package for website integration. Developers using the `setFetchMethod()` API must ensure the cross-origin requests are restricted to the intended scope.&lt;/p&gt;
&lt;p&gt;### Custom forks&lt;/p&gt;
&lt;p&gt;Developers using custom forks of earlier versions of Dark Reader to build other extensions, or integrating it into their apps or browsers, should review their implementation to ensure cross-origin requests are handled securely.&lt;/p&gt;
&lt;p&gt;### Acknowledgements
Security research performed by [Brian Carpenter](https://x.com/geeknik) - [Deep Fork Cyber](https://deepforkcyber.com/).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x369-mcw8-8rvj</guid>
    </item>
  </channel>
</rss>
