<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 04:17:16 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:69098 — Important: webkit2gtk3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:69098</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: webkit2gtk3, AlmaLinux:9: webkit2gtk3-devel, AlmaLinux:9: webkit2gtk3-jsc, AlmaLinux:9: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)
  * chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)
  * chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)
  * chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)
  * chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)
  * webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)
  * webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)
  * webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)
  * webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)
  * webkitgtk: use-after-free of JSCValue f…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: webkit2gtk3, AlmaLinux:9: webkit2gtk3-devel, AlmaLinux:9: webkit2gtk3-jsc, AlmaLinux:9: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)
  * chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)
  * chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)
  * chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)
  * chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)
  * webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)
  * webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)
  * webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)
  * webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)
  * webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)
  * webkitgtk: use-after-free of JSCValue f…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:69098</guid>
    </item>
    <item>
      <title>EUVD-2026-379848</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-379848</link>
      <description>EUVD-2026-379848</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-379848</guid>
    </item>
    <item>
      <title>fkie_cve-2026-83596</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83596</link>
      <description>&lt;p&gt;A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-83596</guid>
    </item>
    <item>
      <title>GHSA-xxgm-wv7m-9vch</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xxgm-wv7m-9vch</link>
      <description>&lt;p&gt;A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xxgm-wv7m-9vch</guid>
    </item>
    <item>
      <title>OESA-2026-3770 — webkitgtk security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3770</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: webkitgtk&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. This package contains WebKitGTK for GTK 3 and libsoup 3.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.(CVE-2026-78376)&lt;/p&gt;
&lt;p&gt;A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. The vulnerability exists in the findFeature function of OpenTypeVerticalData, which fails to properly validate the full featurelist array.(CVE-2026-83596)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: webkitgtk&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. This package contains WebKitGTK for GTK 3 and libsoup 3.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.(CVE-2026-78376)&lt;/p&gt;
&lt;p&gt;A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. The vulnerability exists in the findFeature function of OpenTypeVerticalData, which fails to properly validate the full featurelist array.(CVE-2026-83596)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3770</guid>
    </item>
    <item>
      <title>RHSA-2026:69098 — Red Hat Security Advisory: webkit2gtk3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:69098</link>
      <description>&lt;p&gt;chromium-browser: angle: Out of bounds memory access in ANGLE chromium-browser: angle: ANGLE Out-of-Bounds Write Vulnerability chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Inappropriate implementation in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Insufficient validation of untrusted input in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Out of bounds read and write in Angle chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Insufficient validation of untrusted input in ANGLE chromium-browser: angle: chromium-browser: Integer overflow in ANGLE chromium-browser: angle: chromium-browser: Heap buffer overflow in ANGLE chromium-browser: angle: chromium-browser: Type Confusion in ANGLE…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;chromium-browser: angle: Out of bounds memory access in ANGLE chromium-browser: angle: ANGLE Out-of-Bounds Write Vulnerability chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Inappropriate implementation in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Insufficient validation of untrusted input in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Out of bounds read and write in Angle chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Heap buffer overflow in ANGLE chromium-browser: angle: Use after free in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Integer overflow in ANGLE chromium-browser: angle: Insufficient validation of untrusted input in ANGLE chromium-browser: angle: chromium-browser: Integer overflow in ANGLE chromium-browser: angle: chromium-browser: Heap buffer overflow in ANGLE chromium-browser: angle: chromium-browser: Type Confusion in ANGLE…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:69098</guid>
    </item>
    <item>
      <title>RLSA-2026:69098 — Important: webkit2gtk3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:69098</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: webkit2gtk3&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)&lt;/p&gt;
&lt;p&gt;* chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)&lt;/p&gt;
&lt;p&gt;* webkitgtk: use-after-free of JSCValue function parameters…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: webkit2gtk3&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Sandbox escape via crafted HTML page (CVE-2026-19154)&lt;/p&gt;
&lt;p&gt;* chromium-browser: skia: Skia: Sandbox escape via out-of-bounds write in Chromium (CVE-2026-19173)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia in Google Chrome: Cross-origin data leakage via uninitialized use (CVE-2026-19161)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Skia: Arbitrary code execution via crafted HTML page (CVE-2026-19176)&lt;/p&gt;
&lt;p&gt;* chromium-browser: Chromium: Information leak allows web origin policy bypass (CVE-2026-76041)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-28984)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website may lead to an app denial-of-service (CVE-2026-43804)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Websites may know if the user has visited a given link (CVE-2026-64713)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy (CVE-2026-64728)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination (CVE-2026-64787)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing (CVE-2026-64730)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64757)&lt;/p&gt;
&lt;p&gt;* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2026-64783)&lt;/p&gt;
&lt;p&gt;* webkitgtk: use-after-free of JSCValue function parameters…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:69098</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-83596</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83596</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: webkitgtk, Ubuntu:18.04:LTS: webkitgtk&lt;/p&gt;
&lt;p&gt;A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: webkitgtk, Ubuntu:18.04:LTS: webkitgtk&lt;/p&gt;
&lt;p&gt;A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83596</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3107 — WebKitGTK: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3107</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in WebKitGTK ausnutzen, um eine Speicherbeschädigung zu verursachen und möglicherweise beliebigen Code auszuführen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in WebKitGTK ausnutzen, um eine Speicherbeschädigung zu verursachen und möglicherweise beliebigen Code auszuführen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3107</guid>
    </item>
  </channel>
</rss>
