<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:09:57 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0500 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Elles permettent à un attaquant de provoquer un prob…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</link>
      <description>certfr-2026-avi-0500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0500</guid>
    </item>
    <item>
      <title>EUVD-2026-366099</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366099</link>
      <description>EUVD-2026-366099</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366099</guid>
    </item>
    <item>
      <title>fkie_cve-2026-29074</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29074</link>
      <description>&lt;p&gt;SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-29074</guid>
    </item>
    <item>
      <title>GHSA-xpqw-6gx7-v673 — SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xpqw-6gx7-v673</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: svgo&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with `JavaScript heap out of memory`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The upstream XML parser ([sax](https://www.npmjs.com/package/sax)) doesn&amp;#39;t interpret custom XML entities by default. We pattern matched custom XML entities from the `DOCTYPE`, inserting them into `parser.ENTITIES`, and enabled `unparsedEntities`. This gives us the desired behavior of supporting SVGs with entities declared in the `DOCTYPE`.&lt;/p&gt;
&lt;p&gt;However, entities can reference other entities, which can enable small SVGs to explode exponentially when we try to parse them.&lt;/p&gt;
&lt;p&gt;#### Proof of Concept&lt;/p&gt;
&lt;p&gt;```js
import { optimize } from &amp;#39;svgo&amp;#39;;&lt;/p&gt;
&lt;p&gt;/** Presume that this string was obtained in some other way, such as network. */
const original = `
  &amp;lt;?xml version=&amp;#34;1.0&amp;#34;?&amp;gt;
  &amp;lt;!DOCTYPE lolz [
  &amp;lt;!ENTITY lol &amp;#34;lol&amp;#34;&amp;gt;
  &amp;lt;!ELEMENT lolz (#PCDATA)&amp;gt;
  &amp;lt;!ENTITY lol1 &amp;#34;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol2 &amp;#34;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol3 &amp;#34;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol4 &amp;#34;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol5 &amp;#34;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol6 &amp;#34;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol7 &amp;#34;&amp;amp;lol6;&amp;amp;lol6;&amp;amp;lo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: svgo&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with `JavaScript heap out of memory`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The upstream XML parser ([sax](https://www.npmjs.com/package/sax)) doesn&amp;#39;t interpret custom XML entities by default. We pattern matched custom XML entities from the `DOCTYPE`, inserting them into `parser.ENTITIES`, and enabled `unparsedEntities`. This gives us the desired behavior of supporting SVGs with entities declared in the `DOCTYPE`.&lt;/p&gt;
&lt;p&gt;However, entities can reference other entities, which can enable small SVGs to explode exponentially when we try to parse them.&lt;/p&gt;
&lt;p&gt;#### Proof of Concept&lt;/p&gt;
&lt;p&gt;```js
import { optimize } from &amp;#39;svgo&amp;#39;;&lt;/p&gt;
&lt;p&gt;/** Presume that this string was obtained in some other way, such as network. */
const original = `
  &amp;lt;?xml version=&amp;#34;1.0&amp;#34;?&amp;gt;
  &amp;lt;!DOCTYPE lolz [
  &amp;lt;!ENTITY lol &amp;#34;lol&amp;#34;&amp;gt;
  &amp;lt;!ELEMENT lolz (#PCDATA)&amp;gt;
  &amp;lt;!ENTITY lol1 &amp;#34;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;amp;lol;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol2 &amp;#34;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;amp;lol1;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol3 &amp;#34;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;amp;lol2;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol4 &amp;#34;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;amp;lol3;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol5 &amp;#34;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;amp;lol4;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol6 &amp;#34;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;amp;lol5;&amp;#34;&amp;gt;
  &amp;lt;!ENTITY lol7 &amp;#34;&amp;amp;lol6;&amp;amp;lol6;&amp;amp;lo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xpqw-6gx7-v673</guid>
    </item>
    <item>
      <title>RHSA-2026:11856 — Red Hat Security Advisory: Red Hat Quay 3.12.17</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:11856</link>
      <description>&lt;p&gt;net/url: Incorrect parsing of IPv6 host literals in net/url pyOpenSSL: DTLS cookie callback buffer overflow svgo: SVGO: Denial of Service via XML entity expansion github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;net/url: Incorrect parsing of IPv6 host literals in net/url pyOpenSSL: DTLS cookie callback buffer overflow svgo: SVGO: Denial of Service via XML entity expansion github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:11856</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:2005-1 — Security update for cockpit</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:2005-1</link>
      <description>&lt;p&gt;Security update for cockpit&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for cockpit&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:2005-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0935 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0935</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0935</guid>
    </item>
  </channel>
</rss>
