<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T12:53:20.635520+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-30466</id>
    <title>EUVD-2026-30466</title>
    <updated>2026-10-08T12:53:20.724818+00:00</updated>
    <content>EUVD-2026-30466</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-30466"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-39229</id>
    <title>fkie_cve-2021-39229</title>
    <updated>2026-10-08T12:53:20.724863+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. In affected versions users who use Apprise granting them access to the IFTTT plugin (which just comes out of the box) are subject to a denial of service attack on an inefficient regular expression. The vulnerable regular expression is [here](https://github.com/caronc/apprise/blob/0007eade20934ddef0aba38b8f1aad980cfff253/apprise/plugins/NotifyIFTTT.py#L356-L359). The problem has been patched in release version 0.9.5.1. Users who are unable to upgrade are advised to remove `apprise/plugins/NotifyIFTTT.py` to eliminate the service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-39229"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qhmp-h54x-38qr</id>
    <title>GHSA-qhmp-h54x-38qr — Apprise vulnerable to regex injection with IFTTT Plugin</title>
    <updated>2026-10-08T12:53:20.724902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: apprise</p>
<p>### Impact
Anyone _publicly_ hosting the Apprise library and granting them access to the IFTTT notification service.</p>
<p>### Patches
Update to Apprise v0.9.5.1
   ```bash
   # Install Apprise v0.9.5.1 from PyPI
   pip install apprise==0.9.5.1
   ```</p>
<p>The patch to the problem was performed [here](https://github.com/caronc/apprise/pull/436/files).</p>
<p>### Workarounds
Alternatively, if upgrading is not an option, you can safely remove the following file:
- `apprise/plugins/NotifyIFTTT.py`</p>
<p>The above will eliminate the ability to use IFTTT, but everything else will work smoothly.</p>
<p>### For more information
If you have any questions or comments about this advisory:
* Open an issue in [Apprise](https://github.com/caronc/apprise/issues)
* Email me at [lead2gold@gmail.com](mailto:lead2gold@gmail.com)</p>
<p>### Additional Credit
Github would not allow me to additionally credit **Rasmus Petersen**, but I would like to put that here at the very least - thank you for finding and reporting this issue along with those already credited</p>
<p>## Additional Notes:
- Github would not allow me to add/tag the 2 CWE's this issue is applicable to (only CWE-400).  The other is: CWE-730 (placed in the title)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qhmp-h54x-38qr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-39229</id>
    <title>gsd-2021-39229</title>
    <updated>2026-10-08T12:53:20.724942+00:00</updated>
    <content>gsd-2021-39229</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-39229"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2021-327</id>
    <title>PYSEC-2021-327</title>
    <updated>2026-10-08T12:53:20.724955+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: apprise</p>
<p>Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. In affected versions users who use Apprise granting them access to the IFTTT plugin (which just comes out of the box) are subject to a denial of service attack on an inefficient regular expression. The vulnerable regular expression is [here](https://github.com/caronc/apprise/blob/0007eade20934ddef0aba38b8f1aad980cfff253/apprise/plugins/NotifyIFTTT.py#L356-L359). The problem has been patched in release version 0.9.5.1. Users who are unable to upgrade are advised to remove `apprise/plugins/NotifyIFTTT.py` to eliminate the service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2021-327"/>
  </entry>
</feed>
