<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 08:10:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-382444</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-382444</link>
      <description>EUVD-2026-382444</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-382444</guid>
    </item>
    <item>
      <title>fkie_cve-2026-104871</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-104871</link>
      <description>&lt;p&gt;The Angular SSR is a server-rise rendering tool for Angular applications. Prior to versions 20.3.36, 21.2.23, and 22.1.7, the CommonEngine retrieveSSGPage prerendered-page retrieval logic in @angular/ssr/node, and in @angular/ssr for versions 17 through 18, accepts a relative request URL containing a backslash parent-traversal segment on Windows. The non-special resolve:// URL base preserves the backslash, path.join interprets it as a Windows separator, and the pagePath.startsWith(normalize(publicPath)) check incorrectly accepts a sibling output directory whose name shares the configured public-directory prefix. An unauthenticated requester can therefore retrieve a sibling prerendered HTML page when that page contains the Angular SSG marker. The issue is limited to Windows deployments that pass relative request URLs to CommonEngine.render, have a prefix-sharing sibling output directory, and contain qualifying prerendered Angular HTML; it does not provide arbitrary file read. This issue is fixed in versions 20.3.36, 21.2.23, and 22.1.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Angular SSR is a server-rise rendering tool for Angular applications. Prior to versions 20.3.36, 21.2.23, and 22.1.7, the CommonEngine retrieveSSGPage prerendered-page retrieval logic in @angular/ssr/node, and in @angular/ssr for versions 17 through 18, accepts a relative request URL containing a backslash parent-traversal segment on Windows. The non-special resolve:// URL base preserves the backslash, path.join interprets it as a Windows separator, and the pagePath.startsWith(normalize(publicPath)) check incorrectly accepts a sibling output directory whose name shares the configured public-directory prefix. An unauthenticated requester can therefore retrieve a sibling prerendered HTML page when that page contains the Angular SSG marker. The issue is limited to Windows deployments that pass relative request URLs to CommonEngine.render, have a prefix-sharing sibling output directory, and contain qualifying prerendered Angular HTML; it does not provide arbitrary file read. This issue is fixed in versions 20.3.36, 21.2.23, and 22.1.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-104871</guid>
    </item>
    <item>
      <title>GHSA-7g7c-h8rr-7p6q — Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7g7c-h8rr-7p6q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @angular/ssr&lt;/p&gt;
&lt;p&gt;A Path Traversal vulnerability exists in the prerendered (SSG) page retrieval logic of `CommonEngine` in `@angular/ssr/node` (and `@angular/ssr` in earlier versions). When deployed on Windows, an attacker can craft a request path with backslash directory traversal sequences that causes `CommonEngine` to serve prerendered pages from sibling output directories.&lt;/p&gt;
&lt;p&gt;The vulnerability occurs due to how relative URLs and Windows file paths are resolved and validated:&lt;/p&gt;
&lt;p&gt;1. A request URL containing a backslash parent traversal segment (e.g., `/..\app-admin`) is passed to `CommonEngine.render({ url })`.
2. The engine parses the URL using `new URL(url, &amp;#39;resolve://&amp;#39;)`. Because `resolve://` is a non-special scheme under the WHATWG URL standard, backslashes are not normalized to forward slashes, leaving the `pathname` unnormalized as `/..\app-admin`.
3. The engine constructs the candidate file path using `join(publicPath, pathname, &amp;#39;index.html&amp;#39;)`. On Windows, `path.join` treats `\` as a path delimiter, resolving the parent segment (`..\`) out of `publicPath` (e.g., `dist\app`) into a sibling directory (e.g., `dist\app-admin\index.html`).
4. The containment check (`pagePath.startsWith(normalize(publicPath))`) performs a prefix match without a trailing path delimiter. Because the sibling folder name starts with the configured public folder name (e.g., `dist\app-admin` starts with `dist\app`), the check erroneously succeeds.
5. If the target file exists and contains the Angular SSG marker (`ng…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @angular/ssr&lt;/p&gt;
&lt;p&gt;A Path Traversal vulnerability exists in the prerendered (SSG) page retrieval logic of `CommonEngine` in `@angular/ssr/node` (and `@angular/ssr` in earlier versions). When deployed on Windows, an attacker can craft a request path with backslash directory traversal sequences that causes `CommonEngine` to serve prerendered pages from sibling output directories.&lt;/p&gt;
&lt;p&gt;The vulnerability occurs due to how relative URLs and Windows file paths are resolved and validated:&lt;/p&gt;
&lt;p&gt;1. A request URL containing a backslash parent traversal segment (e.g., `/..\app-admin`) is passed to `CommonEngine.render({ url })`.
2. The engine parses the URL using `new URL(url, &amp;#39;resolve://&amp;#39;)`. Because `resolve://` is a non-special scheme under the WHATWG URL standard, backslashes are not normalized to forward slashes, leaving the `pathname` unnormalized as `/..\app-admin`.
3. The engine constructs the candidate file path using `join(publicPath, pathname, &amp;#39;index.html&amp;#39;)`. On Windows, `path.join` treats `\` as a path delimiter, resolving the parent segment (`..\`) out of `publicPath` (e.g., `dist\app`) into a sibling directory (e.g., `dist\app-admin\index.html`).
4. The containment check (`pagePath.startsWith(normalize(publicPath))`) performs a prefix match without a trailing path delimiter. Because the sibling folder name starts with the configured public folder name (e.g., `dist\app-admin` starts with `dist\app`), the check erroneously succeeds.
5. If the target file exists and contains the Angular SSG marker (`ng…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7g7c-h8rr-7p6q</guid>
    </item>
  </channel>
</rss>
