<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:52:57.803122+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07268</id>
    <title>bdu:2023-07268</title>
    <updated>2026-10-03T21:52:57.806680+00:00</updated>
    <content>bdu:2023-07268</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-wiremock-2023-41327</id>
    <title>BIT-wiremock-2023-41327 — Controlled SSRF through URL in the WireMock</title>
    <updated>2026-10-03T21:52:57.806711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: wiremock</p>
<p>WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first.</p>
<p>Until WireMock Webhooks Extension 3.0.0, the filtering of target addresses from the proxy mode DID NOT work for Webhooks, so the users were potentially vulnerable regardless of the `limitProxyTargets` settings. Via the WireMock webhooks configuration, POST requests from a webhook might be forwarded to an arbitrary service reachable from WireMock’s instance. For example, If someone is running the WireMock docker Container inside a private cluster, they can trigger internal POST requests against unsecured APIs or even against secure ones by passing a token, discovered using another exploit, via authentication headers. This issue has been addressed in versions 2.35.1 and 3.0.3 of wiremock. Wiremock studio has been discontinued and will not see a fix. Users unable to upgrade should use external firewall rules to define the list of permitted destinations.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-wiremock-2023-41327"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-188900</id>
    <title>EUVD-2026-188900</title>
    <updated>2026-10-03T21:52:57.806754+00:00</updated>
    <content>EUVD-2026-188900</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-188900"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-41327</id>
    <title>fkie_cve-2023-41327</title>
    <updated>2026-10-03T21:52:57.806768+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first.</p>
<p>Until WireMock Webhooks Extension 3.0.0-beta-15, the filtering of target addresses from the proxy mode DID NOT work for Webhooks, so the users were potentially vulnerable regardless of the `limitProxyTargets` settings. Via the WireMock webhooks configuration, POST requests from a webhook might be forwarded to an arbitrary service reachable from WireMock’s instance. For example, If someone is running the WireMock docker Container inside a private cluster, they can trigger internal POST requests against unsecured APIs or even against secure ones by passing a token, discovered using another exploit, via authentication headers. This issue has been addressed in versions 2.35.1 and 3.0.3 of wiremock. Wiremock studio has been discontinued and will not see a fix. Users unable to upgrade should use external firewall rules to define the list of permitted destinations.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-41327"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hq8w-9w8w-pmx7</id>
    <title>GHSA-hq8w-9w8w-pmx7 — WireMock Controlled Server Side Request Forgery vulnerability through URL</title>
    <updated>2026-10-03T21:52:57.806798+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.wiremock:wiremock-webhooks-extension</p>
<p>### Impact</p>
<p>WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first. [Documentation](https://wiremock.org/docs/configuration/#preventing-proxying-to-and-recording-from-specific-target-addresses).</p>
<p>Until WireMock Webhooks Extension [3.0.0-beta-15](https://github.com/wiremock/wiremock/releases/tag/3.0.0-beta-15), the filtering of target addresses from the proxy mode DID NOT work for Webhooks, so the users were potentially vulnerable regardless of the `limitProxyTargets` settings.</p>
<p>Via the WireMock webhooks configuration, POST requests from a webhook might be forwarded to an arbitrary service reachable from WireMock’s instance. For example, If someone is running the WireMock docker Container inside a private cluster, they can trigger internal POST requests against unsecured APIs or even against secure ones by passing a token, discovered using another exploit, via authentication headers.</p>
<p>### Affected  components</p>
<p>- WireMock Webhooks Extension 2.x versions until 2.35.1 (security patch)
- WireMock 3.x version until 3.0.3 (security patch)
- All versions of WireMock Studio (discontinued). This distribution bundles the WireMock Webhooks Extension and activates it by default</p>
<p>### Patches and Mitigation</p>
<p>- For WireMock 2.x and 3.x - upgrade to the versions with the security patches
- Setup network restrictions s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hq8w-9w8w-pmx7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-41327</id>
    <title>gsd-2023-41327</title>
    <updated>2026-10-03T21:52:57.806844+00:00</updated>
    <content>gsd-2023-41327</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-41327"/>
  </entry>
</feed>
