<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:44:44.418187+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-64943</id>
    <title>cnvd-2020-64943</title>
    <updated>2026-10-03T02:44:44.483682+00:00</updated>
    <content>cnvd-2020-64943</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-64943"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42742</id>
    <title>EUVD-2026-42742</title>
    <updated>2026-10-03T02:44:44.483748+00:00</updated>
    <content>EUVD-2026-42742</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42742"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15230</id>
    <title>fkie_cve-2020-15230</title>
    <updated>2026-10-03T02:44:44.483763+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem paths on the same host as an application. Only applications using FileMiddleware are affected. This is fixed in version 4.29.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-15230"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vcvg-xgr8-p5gq</id>
    <title>GHSA-vcvg-xgr8-p5gq — Arbitrary file read using percent-encoded relative paths in FileMiddleware</title>
    <updated>2026-10-03T02:44:44.483796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> SwiftURL: github.com/vapor/vapor</p>
<p>### Impact</p>
<p>Attackers can access data at arbitrary filesystem paths on the same host as an application using `FileMiddleware`.</p>
<p>### Patches</p>
<p>Version [4.29.4](https://github.com/vapor/vapor/releases/tag/4.29.4)</p>
<p>### Workarounds</p>
<p>Upgrade to 4.24.4 or later, or disable `FileMiddleware`.</p>
<p>### References</p>
<p>* Introduced in https://github.com/vapor/vapor/pull/2223
* Fixed by https://github.com/vapor/vapor/pull/2500</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory:
* Open [an issue](https://github.com/vapor/vapor/issues)
* Email us at [security@vapor.codes](mailto:security@vapor.codes)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vcvg-xgr8-p5gq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-15230</id>
    <title>gsd-2020-15230</title>
    <updated>2026-10-03T02:44:44.483889+00:00</updated>
    <content>gsd-2020-15230</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-15230"/>
  </entry>
</feed>
