<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:44:15.228271+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232628</id>
    <title>EUVD-2026-232628</title>
    <updated>2026-10-06T16:44:15.231411+00:00</updated>
    <content>EUVD-2026-232628</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232628"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36085</id>
    <title>fkie_cve-2022-36085</title>
    <updated>2026-10-06T16:44:15.231482+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `WithUnsafeBuiltins` function, which allows users to provide a set of built-in functions that should be deemed unsafe — and as such rejected — by the compiler if encountered in the policy compilation stage. A bypass of this protection has been found, where the use of the `with` keyword to mock such a built-in function (a feature introduced in OPA v0.40.0), isn’t taken into account by `WithUnsafeBuiltins`. Multiple conditions need to be met in order to create an adverse effect. Version 0.43.1 contains a patch for this issue. As a workaround, avoid using the `WithUnsafeBuiltins` function and use the `capabilities` feature instead.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-36085"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f524-rf33-2jjr</id>
    <title>GHSA-f524-rf33-2jjr — OPA Compiler: Bypass of WithUnsafeBuiltins using "with" keyword to mock functions</title>
    <updated>2026-10-06T16:44:15.231542+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/open-policy-agent/opa</p>
<p>### Impact</p>
<p>The Rego compiler provides a (deprecated) `WithUnsafeBuiltins` function, which allows users to provide a set of built-in functions that should be deemed unsafe — and as such rejected — by the compiler if encountered in the policy compilation stage. A bypass of this protection has been found, where the use of the `with` keyword to mock such a built-in function (a feature introduced in OPA v0.40.0), isn’t taken into account by `WithUnsafeBuiltins`.</p>
<p>The same method is exposed via `rego.UnsafeBuiltins` in the `github.com/open-policy-agent/opa/rego` package.</p>
<p>When provided e.g. the `http.send` built-in function to `WithUnsafeBuiltins`, the following policy would still compile, and call the `http.send` function with the arguments provided to the `is_object` function when evaluated:</p>
<p>```rego
package policy</p>
<p>foo := is_object({
    "method": "get", 
    "url": "https://www.openpolicyagent.org"
})</p>
<p>allow := r {
    r := foo with is_object as http.send
}
```</p>
<p>Both built-in functions and user provided (i.e. custom) functions are mockable using this construct.</p>
<p>In addition to `http.send`, the `opa.runtime` built-in function is commonly considered unsafe in integrations where policy provided by untrusted parties is evaluated, as it risks exposing configuration, or environment variables, potentially carrying sensitive information.</p>
<p>#### Affected Users</p>
<p>**All of these conditions have to be met** to create an adverse effect:</p>
<p>* Use the Go API for policy evaluation (not the OPA s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f524-rf33-2jjr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-36085</id>
    <title>gsd-2022-36085</title>
    <updated>2026-10-06T16:44:15.231657+00:00</updated>
    <content>gsd-2022-36085</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-36085"/>
  </entry>
</feed>
