<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 13:10:59 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-57259 — Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-57259</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Foxit Software Inc. Foxit PDF Editor, Foxit Software Inc. Foxit PDF Reader&lt;/p&gt;
&lt;p&gt;The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user&amp;#39;s permission range.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Foxit Software Inc. Foxit PDF Editor, Foxit Software Inc. Foxit PDF Reader&lt;/p&gt;
&lt;p&gt;The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user&amp;#39;s permission range.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-57259</guid>
    </item>
  </channel>
</rss>
