<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:49:57.475206+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-25848</id>
    <title>EUVD-2026-25848</title>
    <updated>2026-10-02T19:49:57.540314+00:00</updated>
    <content>EUVD-2026-25848</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-25848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-28099</id>
    <title>fkie_cve-2021-28099</title>
    <updated>2026-10-02T19:49:57.540358+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-28099"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9295-mhf3-v33m</id>
    <title>GHSA-9295-mhf3-v33m — Insecure temporary file in Netflix OSS Hollow</title>
    <updated>2026-10-02T19:49:57.540403+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.netflix.hollow:hollow</p>
<p>&gt; ID: NFLX-2021-001
&gt; Title: Local information disclosure in Hollow
&gt; Release Date: 2021-03-23
&gt; Credit: Security Researcher @JLLeitschuh</p>
<p># Overview</p>
<p>Security researcher @JLLeitschuh reported that Netflix Hollow (a Netflix OSS project available here: https://github.com/Netflix/hollow) writes to a local temporary directory before validating the permissions on it.</p>
<p># Impact</p>
<p>An attacker with the ability to create directories and set permissions on the local filesystem could pre-create this directory and read or modify anything written there by the Hollow process.</p>
<p># Description</p>
<p>Since the `Files.exists(parent)` is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.</p>
<p># Workarounds and Fixes</p>
<p>Avoid running Hollow in configurations that share a filesystem with less-trusted processes. May be fixed in a future release.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9295-mhf3-v33m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-28099</id>
    <title>gsd-2021-28099</title>
    <updated>2026-10-02T19:49:57.540476+00:00</updated>
    <content>gsd-2021-28099</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-28099"/>
  </entry>
</feed>
