<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:03:41 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292775</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292775</link>
      <description>EUVD-2026-292775</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292775</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40472</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40472</link>
      <description>&lt;p&gt;In hackage-server, user-controlled metadata from .cabal files are rendered into HTML
href attributes without proper sanitization, enabling stored
Cross-Site Scripting (XSS) attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In hackage-server, user-controlled metadata from .cabal files are rendered into HTML
href attributes without proper sanitization, enabling stored
Cross-Site Scripting (XSS) attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40472</guid>
    </item>
    <item>
      <title>GHSA-8fw8-47cx-j4q4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8fw8-47cx-j4q4</link>
      <description>&lt;p&gt;In hackage-server, user-controlled metadata from .cabal files are rendered into HTML
href attributes without proper sanitization, enabling stored
Cross-Site Scripting (XSS) attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In hackage-server, user-controlled metadata from .cabal files are rendered into HTML
href attributes without proper sanitization, enabling stored
Cross-Site Scripting (XSS) attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8fw8-47cx-j4q4</guid>
    </item>
    <item>
      <title>HSEC-2026-0004 — Hackage package metadata stored XSS vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2026-0004</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: hackage-server&lt;/p&gt;
&lt;p&gt;# Hackage package metadata stored XSS vulnerability&lt;/p&gt;
&lt;p&gt;User-controlled metadata from `.cabal` files are rendered into HTML
`href` attributes without proper sanitization, enabling stored
Cross-Site Scripting (XSS) attacks.  The specific fields affected
are:&lt;/p&gt;
&lt;p&gt;- `homepage`
- `bug-reports`
- `source-repository.location`
- `description` (Haddock hyperlinks)&lt;/p&gt;
&lt;p&gt;The Haskell Security Response Team audited the entire corpus of
**published** packages on `hackage.haskell.org`—all published
package versions but *not* candidates.  No exploitation attempts
were detected.&lt;/p&gt;
&lt;p&gt;To fix the issue, *hackage-server* now inspects target URIs and only
produces a hyperlink when the URI has an approved scheme: `http`,
`https`, and (only for some fields) `mailto`.&lt;/p&gt;
&lt;p&gt;The fix has been [committed][commit] and deployed on
`hackage.haskell.org`.  Other operations of *hackage-server*
instances should update as soon as possible to commit
`2de3ae45082f8f3f29a41f6aff620d09d0e74058` or later.&lt;/p&gt;
&lt;p&gt;## Acknowledgements&lt;/p&gt;
&lt;p&gt;- **Joshua Rogers** (https://joshua.hu/) of AISLE
  (https://aisle.com/) reported the issue to the Haskell Security
  Response Team.
- **Fraser Tweedale** implemented the fix.
- **Gershom Bazerman** merged the fix and deployed it to
  `hackage.haskell.org`.&lt;/p&gt;
&lt;p&gt;[commit]: https://github.com/haskell/hackage-server/commit/2de3ae45082f8f3f29a41f6aff620d09d0e74058&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: hackage-server&lt;/p&gt;
&lt;p&gt;# Hackage package metadata stored XSS vulnerability&lt;/p&gt;
&lt;p&gt;User-controlled metadata from `.cabal` files are rendered into HTML
`href` attributes without proper sanitization, enabling stored
Cross-Site Scripting (XSS) attacks.  The specific fields affected
are:&lt;/p&gt;
&lt;p&gt;- `homepage`
- `bug-reports`
- `source-repository.location`
- `description` (Haddock hyperlinks)&lt;/p&gt;
&lt;p&gt;The Haskell Security Response Team audited the entire corpus of
**published** packages on `hackage.haskell.org`—all published
package versions but *not* candidates.  No exploitation attempts
were detected.&lt;/p&gt;
&lt;p&gt;To fix the issue, *hackage-server* now inspects target URIs and only
produces a hyperlink when the URI has an approved scheme: `http`,
`https`, and (only for some fields) `mailto`.&lt;/p&gt;
&lt;p&gt;The fix has been [committed][commit] and deployed on
`hackage.haskell.org`.  Other operations of *hackage-server*
instances should update as soon as possible to commit
`2de3ae45082f8f3f29a41f6aff620d09d0e74058` or later.&lt;/p&gt;
&lt;p&gt;## Acknowledgements&lt;/p&gt;
&lt;p&gt;- **Joshua Rogers** (https://joshua.hu/) of AISLE
  (https://aisle.com/) reported the issue to the Haskell Security
  Response Team.
- **Fraser Tweedale** implemented the fix.
- **Gershom Bazerman** merged the fix and deployed it to
  `hackage.haskell.org`.&lt;/p&gt;
&lt;p&gt;[commit]: https://github.com/haskell/hackage-server/commit/2de3ae45082f8f3f29a41f6aff620d09d0e74058&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2026-0004</guid>
    </item>
  </channel>
</rss>
