<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 11:30:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-309185</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-309185</link>
      <description>EUVD-2026-309185</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-309185</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41885</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41885</link>
      <description>&lt;p&gt;i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for Deno. Prior to version 9.0.2, i18next-locize-backend interpolates lng, ns, projectId, and version directly into the configured loadPath / privatePath / addPath / updatePath / getLanguagesPath URL templates with no path-component validation and no encoding. When an application exposes any of these values to user-controlled input (?lng= / ?ns= query parameters via i18next-browser-languagedetector, cookies, request headers, or a URL-derived projectId), a crafted value can change the structure of the outgoing request URL. Affected call sites in lib/index.js (pre-patch): the interpolate() helper is used at the five URL-build sites — _readAny/read (line 415 for private, 426 for public), getLanguages (lines 271 and 296), and writePage (lines 616 and 622) for the missing-key and update POST paths. The helper interpolate in lib/utils.js substitutes raw values with no encoding. This issue has been patched in version 9.0.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for Deno. Prior to version 9.0.2, i18next-locize-backend interpolates lng, ns, projectId, and version directly into the configured loadPath / privatePath / addPath / updatePath / getLanguagesPath URL templates with no path-component validation and no encoding. When an application exposes any of these values to user-controlled input (?lng= / ?ns= query parameters via i18next-browser-languagedetector, cookies, request headers, or a URL-derived projectId), a crafted value can change the structure of the outgoing request URL. Affected call sites in lib/index.js (pre-patch): the interpolate() helper is used at the five URL-build sites — _readAny/read (line 415 for private, 426 for public), getLanguages (lines 271 and 296), and writePage (lines 616 and 622) for the missing-key and update POST paths. The helper interpolate in lib/utils.js substitutes raw values with no encoding. This issue has been patched in version 9.0.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41885</guid>
    </item>
    <item>
      <title>GHSA-mgcp-mfp8-3q45 — i18next-locize-backend has URL Injection via Unsanitized Path Parameters</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mgcp-mfp8-3q45</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: i18next-locize-backend&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Versions of `i18next-locize-backend` prior to 9.0.2 interpolate `lng`, `ns`, `projectId`, and `version` directly into the configured `loadPath` / `privatePath` / `addPath` / `updatePath` / `getLanguagesPath` URL templates with no path-component validation and no encoding. When an application exposes any of these values to user-controlled input (`?lng=` / `?ns=` query parameters via `i18next-browser-languagedetector`, cookies, request headers, or a URL-derived `projectId`), a crafted value can change the structure of the outgoing request URL.&lt;/p&gt;
&lt;p&gt;Affected call sites in `lib/index.js` (pre-patch): the `interpolate()` helper is used at the five URL-build sites — `_readAny`/`read` (line 415 for private, 426 for public), `getLanguages` (lines 271 and 296), and `writePage` (lines 616 and 622) for the missing-key and update POST paths. The helper `interpolate` in `lib/utils.js` substitutes raw values with no encoding.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker who can influence `lng`, `ns`, `projectId`, or `version` can:&lt;/p&gt;
&lt;p&gt;- **Path traversal** — `lng = &amp;#39;../../admin&amp;#39;` against `https://api.locize.app/{{projectId}}/{{version}}/{{lng}}/{{ns}}` changes the request URL path segment that reaches the locize CDN / API.
- **Query-string injection** — `lng = &amp;#39;en?x=y&amp;#39;` appends an attacker-chosen query to the URL.
- **Fragment truncation** — `lng = &amp;#39;en#x&amp;#39;` silently truncates the path in browser fetches.
- **URL-encoded bypass** — `lng = &amp;#39;en%2F..&amp;#39;` leverages server-side decoding to reintroduce `/..`.&lt;/p&gt;
&lt;p&gt;Th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: i18next-locize-backend&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Versions of `i18next-locize-backend` prior to 9.0.2 interpolate `lng`, `ns`, `projectId`, and `version` directly into the configured `loadPath` / `privatePath` / `addPath` / `updatePath` / `getLanguagesPath` URL templates with no path-component validation and no encoding. When an application exposes any of these values to user-controlled input (`?lng=` / `?ns=` query parameters via `i18next-browser-languagedetector`, cookies, request headers, or a URL-derived `projectId`), a crafted value can change the structure of the outgoing request URL.&lt;/p&gt;
&lt;p&gt;Affected call sites in `lib/index.js` (pre-patch): the `interpolate()` helper is used at the five URL-build sites — `_readAny`/`read` (line 415 for private, 426 for public), `getLanguages` (lines 271 and 296), and `writePage` (lines 616 and 622) for the missing-key and update POST paths. The helper `interpolate` in `lib/utils.js` substitutes raw values with no encoding.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker who can influence `lng`, `ns`, `projectId`, or `version` can:&lt;/p&gt;
&lt;p&gt;- **Path traversal** — `lng = &amp;#39;../../admin&amp;#39;` against `https://api.locize.app/{{projectId}}/{{version}}/{{lng}}/{{ns}}` changes the request URL path segment that reaches the locize CDN / API.
- **Query-string injection** — `lng = &amp;#39;en?x=y&amp;#39;` appends an attacker-chosen query to the URL.
- **Fragment truncation** — `lng = &amp;#39;en#x&amp;#39;` silently truncates the path in browser fetches.
- **URL-encoded bypass** — `lng = &amp;#39;en%2F..&amp;#39;` leverages server-side decoding to reintroduce `/..`.&lt;/p&gt;
&lt;p&gt;Th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mgcp-mfp8-3q45</guid>
    </item>
  </channel>
</rss>
