<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:13:06 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-17543 — SQL injection in ext-pgsql via E'...' backslash breakout</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-17543</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PHP Group PHP&lt;/p&gt;
&lt;p&gt;Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PHP Group PHP&lt;/p&gt;
&lt;p&gt;Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-17543</guid>
    </item>
    <item>
      <title>USN-8734-1 — php7.0 vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8734-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: php7.0&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled Apache map decoding in SOAP
servers with a typemap configured. A remote attacker could use this issue
to cause a NULL pointer dereference, resulting in a denial of service.
(CVE-2026-7262)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled signed integer overflow in
the metaphone() function. An attacker could use this issue to cause an
out-of-bounds read, resulting in a denial of service. (CVE-2026-7568)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled circular symbolic links in
phar archives. An attacker could use this issue to cause unbounded
recursion, resulting in a denial of service. (CVE-2026-7260)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly escaped backslashes in the pgsql
extension when standard_conforming_strings is enabled. An attacker could
use this issue to perform SQL injection via a backslash breakout.
(CVE-2026-17543)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: php7.0&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled Apache map decoding in SOAP
servers with a typemap configured. A remote attacker could use this issue
to cause a NULL pointer dereference, resulting in a denial of service.
(CVE-2026-7262)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled signed integer overflow in
the metaphone() function. An attacker could use this issue to cause an
out-of-bounds read, resulting in a denial of service. (CVE-2026-7568)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly handled circular symbolic links in
phar archives. An attacker could use this issue to cause unbounded
recursion, resulting in a denial of service. (CVE-2026-7260)&lt;/p&gt;
&lt;p&gt;It was discovered that PHP incorrectly escaped backslashes in the pgsql
extension when standard_conforming_strings is enabled. An attacker could
use this issue to perform SQL injection via a backslash breakout.
(CVE-2026-17543)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8734-1</guid>
    </item>
  </channel>
</rss>
