<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:00:29 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-377129</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-377129</link>
      <description>EUVD-2026-377129</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-377129</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56735</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56735</link>
      <description>&lt;p&gt;Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad&amp;#39;s HTML sanitizer (HtmlSanitizer::Strict) blocks external URLs in  to prevent remote content loading, but the srcset attribute, also allowlisted for , is not subject to the same check. This oversight allows an attacker to embed arbitrary external URLs in the srcset attribute just by sending an e-mail, effectively bypassing the external content protection. When an agent views the ticket containing the malicious srcset, the browser will silently load the attacker-controlled URL, resulting in the leakage of the agent&amp;#39;s IP address, User-Agent, Referer, and the exact time the ticket was viewed. HtmlSanitizer::Strict got extended to block external URLs in the srcset attribute of  tags. This was done to prevent tracking pixels and external content loading, which could compromise user privacy. This issue is fixed in versions 7.0.2 and 7.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad&amp;#39;s HTML sanitizer (HtmlSanitizer::Strict) blocks external URLs in  to prevent remote content loading, but the srcset attribute, also allowlisted for , is not subject to the same check. This oversight allows an attacker to embed arbitrary external URLs in the srcset attribute just by sending an e-mail, effectively bypassing the external content protection. When an agent views the ticket containing the malicious srcset, the browser will silently load the attacker-controlled URL, resulting in the leakage of the agent&amp;#39;s IP address, User-Agent, Referer, and the exact time the ticket was viewed. HtmlSanitizer::Strict got extended to block external URLs in the srcset attribute of  tags. This was done to prevent tracking pixels and external content loading, which could compromise user privacy. This issue is fixed in versions 7.0.2 and 7.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56735</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1981 — Zammad: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1981</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Zammad ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Zammad ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1981</guid>
    </item>
  </channel>
</rss>
