<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:10:50 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-14134</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14134</link>
      <description>bdu:2026-14134</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14134</guid>
    </item>
    <item>
      <title>EUVD-2026-362690</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362690</link>
      <description>EUVD-2026-362690</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362690</guid>
    </item>
    <item>
      <title>fkie_cve-2026-83609</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-83609</link>
      <description>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchored QName_exact validator with the multiline flag, so ^ and $ validate only one line instead of the complete name. createElementNS, createAttributeNS, createDocumentType, and createAttribute consequently accept a malformed XML name whose first line is valid and whose later text injects markup when serialized through either the default path or requireWellFormed: true. The triggering ECMAScript line terminators are U+000A, U+000D, U+2028, and U+2029. This issue is fixed in @xmldom/xmldom version 0.9.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchored QName_exact validator with the multiline flag, so ^ and $ validate only one line instead of the complete name. createElementNS, createAttributeNS, createDocumentType, and createAttribute consequently accept a malformed XML name whose first line is valid and whose later text injects markup when serialized through either the default path or requireWellFormed: true. The triggering ECMAScript line terminators are U+000A, U+000D, U+2028, and U+2029. This issue is fixed in @xmldom/xmldom version 0.9.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-83609</guid>
    </item>
    <item>
      <title>GHSA-3px3-54cx-rmw9 — xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on th…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3px3-54cx-rmw9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An embedded line terminator bypasses xmldom&amp;#39;s always-on, WHATWG-mandated creation-time name
validation. `createElementNS`, `createAttributeNS`, `createDocumentType`, and `createAttribute` should
reject a malformed qualified name with `InvalidCharacterError`, but a name whose first line is
well-formed slips through and enters the DOM. On serialization it is emitted verbatim, so the
characters after the line terminator inject markup into the output. The injection reaches the default
serialization path, and enabling `requireWellFormed` does not prevent it.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`createElementNS`, `createAttributeNS`, and `createDocumentType` route through `validateQualifiedName`,
and `createAttribute` performs the analogous check; each validates the name with
`g.QName_exact.test(name)`. `QName_exact = reg(&amp;#39;^&amp;#39;, QName, &amp;#39;$&amp;#39;)` inherits the `m` flag from xmldom&amp;#39;s
shared regexp builder, so the matcher accepts any name whose first line is a valid `QName` and leaves
the remaining lines unconstrained (see Root Cause).&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;1. A shared regexp builder compiles anchored productions with the `m` flag.
2. `^…$` under `m` are line anchors, not string anchors.
3. `validateQualifiedName` / `createAttribute` validate with `.test()` against such a production, so a
   line terminator followed by breakout markup passes and the malformed name is stored.&lt;/p&gt;
&lt;p&gt;The triggering line terminators are the ECMAScript `LineTerminator` set: U+000A, U+000D, U+2028, U+2029.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```js…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @xmldom/xmldom&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;An embedded line terminator bypasses xmldom&amp;#39;s always-on, WHATWG-mandated creation-time name
validation. `createElementNS`, `createAttributeNS`, `createDocumentType`, and `createAttribute` should
reject a malformed qualified name with `InvalidCharacterError`, but a name whose first line is
well-formed slips through and enters the DOM. On serialization it is emitted verbatim, so the
characters after the line terminator inject markup into the output. The injection reaches the default
serialization path, and enabling `requireWellFormed` does not prevent it.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`createElementNS`, `createAttributeNS`, and `createDocumentType` route through `validateQualifiedName`,
and `createAttribute` performs the analogous check; each validates the name with
`g.QName_exact.test(name)`. `QName_exact = reg(&amp;#39;^&amp;#39;, QName, &amp;#39;$&amp;#39;)` inherits the `m` flag from xmldom&amp;#39;s
shared regexp builder, so the matcher accepts any name whose first line is a valid `QName` and leaves
the remaining lines unconstrained (see Root Cause).&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;1. A shared regexp builder compiles anchored productions with the `m` flag.
2. `^…$` under `m` are line anchors, not string anchors.
3. `validateQualifiedName` / `createAttribute` validate with `.test()` against such a production, so a
   line terminator followed by breakout markup passes and the malformed name is stored.&lt;/p&gt;
&lt;p&gt;The triggering line terminators are the ECMAScript `LineTerminator` set: U+000A, U+000D, U+2028, U+2029.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```js…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3px3-54cx-rmw9</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-83609</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83609</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchored QName_exact validator with the multiline flag, so ^ and $ validate only one line instead of the complete name. createElementNS, createAttributeNS, createDocumentType, and createAttribute consequently accept a malformed XML name whose first line is valid and whose later text injects markup when serialized through either the default path or requireWellFormed: true. The triggering ECMAScript line terminators are U+000A, U+000D, U+2028, and U+2029. This issue is fixed in @xmldom/xmldom version 0.9.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: node-xmldom, Ubuntu:22.04:LTS: node-xmldom, Ubuntu:24.04:LTS: node-xmldom, Ubuntu:26.04:LTS: node-xmldom&lt;/p&gt;
&lt;p&gt;xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchored QName_exact validator with the multiline flag, so ^ and $ validate only one line instead of the complete name. createElementNS, createAttributeNS, createDocumentType, and createAttribute consequently accept a malformed XML name whose first line is valid and whose later text injects markup when serialized through either the default path or requireWellFormed: true. The triggering ECMAScript line terminators are U+000A, U+000D, U+2028, and U+2029. This issue is fixed in @xmldom/xmldom version 0.9.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-83609</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3596 — IBM App Connect Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3596</guid>
    </item>
  </channel>
</rss>
