<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:56:22.152495+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-31633</id>
    <title>EUVD-2026-31633</title>
    <updated>2026-10-03T21:56:22.155381+00:00</updated>
    <content>EUVD-2026-31633</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-31633"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41275</id>
    <title>fkie_cve-2021-41275</title>
    <updated>2026-10-03T21:56:22.155421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by using an underlying Devise authentication framework. In affected versions spree_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of spree_auth_devise are affected if protect_from_forgery method is both: Executed whether as: A before_action callback (the default). A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find). Configured to use :null_session or :reset_session strategies (:null_session is the default in case the no strategy is given, but rails --new generated skeleton use :exception). Users are advised to update their spree_auth_devise gem. For users unable to update it may be possible to change your strategy to :exception. Please see the linked GHSA for more workaround details. ### Impact CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of `spree_auth_devise` are affected if `protect_from_forgery` method is both: * Executed whether as: * A before_action callback (the default) * A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find). * Configured to use :null_session or :reset_session strategies (:null_sessio…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-41275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-26xx-m4q2-xhq8</id>
    <title>GHSA-26xx-m4q2-xhq8 — Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness</title>
    <updated>2026-10-03T21:56:22.155471+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: spree_auth_devise</p>
<p>### Impact</p>
<p>CSRF vulnerability that allows user account takeover.</p>
<p>All applications using any version of the frontend component of `spree_auth_devise` are affected if `protect_from_forgery` method is both:</p>
<p>* Executed whether as:
  * A before_action callback (the default)
  * A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find).
* Configured to use :null_session or :reset_session strategies (:null_session is the default in case the no strategy is given, but rails --new generated skeleton use :exception).</p>
<p>That means that applications that haven't been configured differently from what it's generated with Rails aren't affected.</p>
<p>Thanks @waiting-for-dev for reporting and providing a patch 👏</p>
<p>### Patches</p>
<p>Spree 4.3 users should update to spree_auth_devise 4.4.1
Spree 4.2 users should update to spree_auth_devise 4.2.1
Spree 4.1 users should update to spree_auth_devise 4.1.1
Older Spree version users should update to spree_auth_devise 4.0.1
 
### Workarounds</p>
<p>If possible, change your strategy to :exception:</p>
<p>```ruby
class ApplicationController &lt; ActionController::Base
  protect_from_forgery with: :exception
end
```</p>
<p>Add the following to`config/application.rb `to at least run the `:exception` strategy on the affected controller:</p>
<p>```ruby
config.after_initialize do
  Spree::UsersController.protect_from_forgery with: :exception
end
```</p>
<p>### References
https://github.com/solidusio/solidus_auth_devise/se…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-26xx-m4q2-xhq8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-41275</id>
    <title>gsd-2021-41275</title>
    <updated>2026-10-03T21:56:22.155525+00:00</updated>
    <content>gsd-2021-41275</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-41275"/>
  </entry>
</feed>
