<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 11:41:00 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-34345 — @cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-34345</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; cyclonedx-javascript-library&lt;/p&gt;
&lt;p&gt;The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; cyclonedx-javascript-library&lt;/p&gt;
&lt;p&gt;The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-34345</guid>
    </item>
  </channel>
</rss>
