<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:33:14.662443+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-28147</id>
    <title>EUVD-2026-28147</title>
    <updated>2026-10-03T21:33:14.668028+00:00</updated>
    <content>EUVD-2026-28147</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-28147"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-32769</id>
    <title>fkie_cve-2021-32769</title>
    <updated>2026-10-03T21:33:14.668071+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs because Micronaut does not restrict file access to configured paths. The vulnerability is patched in version 2.5.9. As a workaround, do not use `**` in mapping, use only `*`, which exposes only flat structure of a directory not allowing traversal. If using Linux, another workaround is to run micronaut in chroot.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-32769"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cjx7-399x-p2rj</id>
    <title>GHSA-cjx7-399x-p2rj — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in micronaut-core</title>
    <updated>2026-10-03T21:33:14.668135+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.micronaut:micronaut-http-server-netty</p>
<p>With a basic configuration like</p>
<p>```yaml
router:
  static-resources:
    assets:
      enabled: true
      mapping: /.assets/public/**
      paths: file:/home/lstrmiska/test/
```</p>
<p>it is possible to access any file from a filesystem, using "/../../" in URL, as Micronaut does not restrict file access to configured paths.</p>
<p>**Repro Steps**
- create a file test.txt in /home/lstrmiska
- start micronaut
- execute command
`curl -v --path-as-is "http://localhost:8080/.assets/public/../test.txt"`</p>
<p>### Impact</p>
<p>Micronaut can potentially leak sensitive information.</p>
<p>See https://cwe.mitre.org/data/definitions/22.html</p>
<p>### Patches</p>
<p>```
diff --git a/core/src/main/java/io/micronaut/core/io/file/DefaultFileSystemResourceLoader.java b/core/src/main/java/io/micronaut/core/io/file/DefaultFileSystemResourceLoader.java
index 2f5a91403..19d3b7f05 100644
--- a/core/src/main/java/io/micronaut/core/io/file/DefaultFileSystemResourceLoader.java
+++ b/core/src/main/java/io/micronaut/core/io/file/DefaultFileSystemResourceLoader.java
@@ -69,6 +69,9 @@ public class DefaultFileSystemResourceLoader implements FileSystemResourceLoader
     @Override
     public Optional&lt;InputStream&gt; getResourceAsStream(String path) {
         Path filePath = getFilePath(normalize(path));
+        if (pathOutsideBase(filePath)) {
+            return Optional.empty();
+        }
         try {
             return Optional.of(Files.newInputStream(filePath));
         } catch (IOException e) {
@@ -79,7 +82,7 @@ public class Defa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cjx7-399x-p2rj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-32769</id>
    <title>gsd-2021-32769</title>
    <updated>2026-10-03T21:33:14.668216+00:00</updated>
    <content>gsd-2021-32769</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-32769"/>
  </entry>
</feed>
