<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 05:58:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-276444</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276444</link>
      <description>EUVD-2026-276444</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276444</guid>
    </item>
    <item>
      <title>fkie_cve-2026-28499</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28499</link>
      <description>&lt;p&gt;LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn&amp;#39;t work correctly when a template prints a collection (Array / Dictionary) via `#(value)`. This can result in XSS, allowing potentially untrusted input to be rendered unescaped. Version 1.14.2 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn&amp;#39;t work correctly when a template prints a collection (Array / Dictionary) via `#(value)`. This can result in XSS, allowing potentially untrusted input to be rendered unescaped. Version 1.14.2 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-28499</guid>
    </item>
    <item>
      <title>GHSA-6jj5-j4j8-8473 — LeafKit's HTML escaping may be skipped for Collection values, enabling XSS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6jj5-j4j8-8473</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; SwiftURL: github.com/vapor/leaf-kit&lt;/p&gt;
&lt;p&gt;### Summary
LeafKit HTML-escaping is not working correctly when a template prints a collection (Array / Dictionary) via `#(value)`. This can result in XSS, allowing potentially untrusted input to be rendered unescaped.&lt;/p&gt;
&lt;p&gt;### Details
LeafKit attempts to escape expressions during serialization, but due to [`LeafData.htmlEscaped()`](https://github.com/vapor/leaf-kit/blob/8ff06839d8b3ddf74032d2ade01e3453eb556d30/Sources/LeafKit/LeafData/LeafData.swift#L322)&amp;#39;s implementation, when the escaped type&amp;#39;s conversion to `String` is marked as `.ambiguous` (as it is the case for Arrays and Dictionaries), an unescaped `self` is returned.&lt;/p&gt;
&lt;p&gt;&amp;gt; **Note: I recommend first looking at the POC, before taking a look at the details below, as it is simple.** In the detailed, verbose analysis below, I explored the functions involved in more detail, in hopes that it will help you understand and locate this issue.&lt;/p&gt;
&lt;p&gt;#### The issue&amp;#39;s detailed analysis:
1. Leaf expression serialization eventually reaches `LeafSerializer`&amp;#39;s `serialize` private function below.  This is where the `leafData` is `.htmlEscaped()`, and then serialized.&lt;/p&gt;
&lt;p&gt;https://github.com/vapor/leaf-kit/blob/8ff06839d8b3ddf74032d2ade01e3453eb556d30/Sources/LeafKit/LeafSerialize/LeafSerializer.swift#L60-L66&lt;/p&gt;
&lt;p&gt;2. The `LeafData.htmlEscaped()` method uses the `LeafData.string` computed property to convert itself to a string. Then, it calls the `htmlEscaped()` method on it. However, if the string conversion fails, notice that an unescaped, unsafe `self`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; SwiftURL: github.com/vapor/leaf-kit&lt;/p&gt;
&lt;p&gt;### Summary
LeafKit HTML-escaping is not working correctly when a template prints a collection (Array / Dictionary) via `#(value)`. This can result in XSS, allowing potentially untrusted input to be rendered unescaped.&lt;/p&gt;
&lt;p&gt;### Details
LeafKit attempts to escape expressions during serialization, but due to [`LeafData.htmlEscaped()`](https://github.com/vapor/leaf-kit/blob/8ff06839d8b3ddf74032d2ade01e3453eb556d30/Sources/LeafKit/LeafData/LeafData.swift#L322)&amp;#39;s implementation, when the escaped type&amp;#39;s conversion to `String` is marked as `.ambiguous` (as it is the case for Arrays and Dictionaries), an unescaped `self` is returned.&lt;/p&gt;
&lt;p&gt;&amp;gt; **Note: I recommend first looking at the POC, before taking a look at the details below, as it is simple.** In the detailed, verbose analysis below, I explored the functions involved in more detail, in hopes that it will help you understand and locate this issue.&lt;/p&gt;
&lt;p&gt;#### The issue&amp;#39;s detailed analysis:
1. Leaf expression serialization eventually reaches `LeafSerializer`&amp;#39;s `serialize` private function below.  This is where the `leafData` is `.htmlEscaped()`, and then serialized.&lt;/p&gt;
&lt;p&gt;https://github.com/vapor/leaf-kit/blob/8ff06839d8b3ddf74032d2ade01e3453eb556d30/Sources/LeafKit/LeafSerialize/LeafSerializer.swift#L60-L66&lt;/p&gt;
&lt;p&gt;2. The `LeafData.htmlEscaped()` method uses the `LeafData.string` computed property to convert itself to a string. Then, it calls the `htmlEscaped()` method on it. However, if the string conversion fails, notice that an unescaped, unsafe `self`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6jj5-j4j8-8473</guid>
    </item>
  </channel>
</rss>
