<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 07:12:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275711</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275711</link>
      <description>EUVD-2026-275711</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275711</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30226</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30226</link>
      <description>&lt;p&gt;Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn&amp;#39;t sufficient for the job. In devalue v5.6.3 and earlier, devalue.parse and devalue.unflatten were susceptible to prototype pollution via maliciously crafted payloads. Successful exploitation could lead to Denial of Service (DoS) or type confusion. This vulnerability is fixed in 5.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn&amp;#39;t sufficient for the job. In devalue v5.6.3 and earlier, devalue.parse and devalue.unflatten were susceptible to prototype pollution via maliciously crafted payloads. Successful exploitation could lead to Denial of Service (DoS) or type confusion. This vulnerability is fixed in 5.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30226</guid>
    </item>
    <item>
      <title>GHSA-cfw5-2vxh-hr84 — devalue has prototype pollution in devalue.parse and devalue.unflatten</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cfw5-2vxh-hr84</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: devalue&lt;/p&gt;
&lt;p&gt;In devalue v5.6.3, `devalue.parse` and `devalue.unflatten` were susceptible to prototype pollution via maliciously crafted payloads. Successful exploitation could lead to Denial of Service (DoS) or type confusion.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: devalue&lt;/p&gt;
&lt;p&gt;In devalue v5.6.3, `devalue.parse` and `devalue.unflatten` were susceptible to prototype pollution via maliciously crafted payloads. Successful exploitation could lead to Denial of Service (DoS) or type confusion.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cfw5-2vxh-hr84</guid>
    </item>
  </channel>
</rss>
