<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:41:50.725563+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-5242</id>
    <title>EUVD-2026-5242</title>
    <updated>2026-10-03T23:41:50.806518+00:00</updated>
    <content>EUVD-2026-5242</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-5242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-32977</id>
    <title>fkie_cve-2024-32977</title>
    <updated>2026-10-03T23:41:50.806565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within `config.yaml`, even if they come from networks that are not configured as `localNetworks`, spoofing their IP via the `X-Forwarded-For` header. If autologin is not enabled, this vulnerability does not have any impact. The vulnerability has been patched in version 1.10.1. Until the patch has been applied, OctoPrint administrators who have autologin enabled on their instances should disable it and/or to make the instance inaccessible from potentially hostile networks like the internet.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-32977"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2vjq-hg5w-5gm7</id>
    <title>GHSA-2vjq-hg5w-5gm7 — OctoPrint has an Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabled</title>
    <updated>2026-10-03T23:41:50.806612+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: OctoPrint</p>
<p>### Impact</p>
<p>OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication **if the `autologinLocal` option is enabled** within `config.yaml`, even if they come from networks that are not configured as `localNetworks`, by spoofing their IP via the `X-Forwarded-For` header.</p>
<p>If autologin is not enabled, this vulnerability does not have any impact.</p>
<p>### Patches</p>
<p>The vulnerability has been patched in version 1.10.1.</p>
<p>### Workaround</p>
<p>Until the patch has been applied, OctoPrint administrators who have autologin enabled on their instances should disable it and/or to make the instance inaccessible from potentially hostile networks like the internet.</p>
<p>### PoC</p>
<p>1. Enable the `autologinAs` configuration within the `accessControl` section in the [OctoPrint yaml configuration file](https://docs.octoprint.org/en/master/configuration/config_yaml.html#access-control)
2. Set your browser to add the `X-Forwarded-For: 127.0.0.1` header to HTTP requests. For example, this can be done using proxy software like Burp Suite. Alternatively, there are browser extensions such as https://github.com/MisterPhilip/x-forwarded-for, but I haven't tried them.
3. Navigate to OctoPrint and note that it logs you in automatically.</p>
<p>### Credits</p>
<p>This vulnerability was discovered and responsibly disclosed to OctoPrint by Jacopo Tediosi.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2vjq-hg5w-5gm7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-32977</id>
    <title>gsd-2024-32977</title>
    <updated>2026-10-03T23:41:50.806655+00:00</updated>
    <content>gsd-2024-32977</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-32977"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2024-237</id>
    <title>PYSEC-2024-237</title>
    <updated>2026-10-03T23:41:50.806669+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: octoprint</p>
<p>OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within `config.yaml`, even if they come from networks that are not configured as `localNetworks`, spoofing their IP via the `X-Forwarded-For` header. If autologin is not enabled, this vulnerability does not have any impact. The vulnerability has been patched in version 1.10.1. Until the patch has been applied, OctoPrint administrators who have autologin enabled on their instances should disable it and/or to make the instance inaccessible from potentially hostile networks like the internet.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2024-237"/>
  </entry>
</feed>
