<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:32:55.606361+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-4680</id>
    <title>EUVD-2026-4680</title>
    <updated>2026-10-02T14:32:55.660346+00:00</updated>
    <content>EUVD-2026-4680</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-4680"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-29886</id>
    <title>fkie_cve-2024-29886</title>
    <updated>2026-10-02T14:32:55.660393+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Serverpod is an app and web server, built for the Flutter and Dart ecosystem. An issue was identified with the old password hash algorithm that made it susceptible to rainbow attacks if the database was compromised. This vulnerability is fixed by 1.2.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-29886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r75m-26cq-mjxc</id>
    <title>GHSA-r75m-26cq-mjxc — Serverpod improved security for stored password hashes</title>
    <updated>2026-10-02T14:32:55.660425+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Pub: serverpod_auth_server</p>
<p>## Description</p>
<p>### Improved security for stored password hashes
Serverpod now uses the OWASP, [source](https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#introduction), recommended Argon2Id password hash algorithm to store password hashes for the email authentication module.</p>
<p>Starting from Serverpod `1.2.6` all users that either creates an account or authenticates with the server will have their password stored using the safer algorithm. No changes are required from the developer to start storing passwords using the safer algorithm.</p>
<p>### Why did we change how passwords are stored?
An issue was identified with the old password hash algorithm that made it susceptible to rainbow attacks if the database was compromised.</p>
<p>It is strongly recommended to migrate your existing password hashes.</p>
<p>### Migrate existing password hashes
The email authentication module provides a helper method to migrate all the existing legacy password hashes in the database. Simply call  `Emails.migrateLegacyPasswordHashes(...)` with a session instance as an argument to migrate the password hashes.</p>
<p>The method is implemented as an idempotent operation and will yield the same result regardless of how many times it is called.</p>
<p>We recommend either implementing a web server route that can be called remotely or by calling the method as part of starting the server.</p>
<p>Following is example code for implementing a web server route.</p>
<p>&lt;details&gt;&lt;summary&gt;&lt;h4&gt;Web server route code&lt;/h4&gt;&lt;/su…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r75m-26cq-mjxc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-29886</id>
    <title>gsd-2024-29886</title>
    <updated>2026-10-02T14:32:55.660483+00:00</updated>
    <content>gsd-2024-29886</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-29886"/>
  </entry>
</feed>
