<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:50:15.524947+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-11514</id>
    <title>bdu:2024-11514</title>
    <updated>2026-10-03T12:50:15.594796+00:00</updated>
    <content>bdu:2024-11514</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-11514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-186175</id>
    <title>EUVD-2026-186175</title>
    <updated>2026-10-03T12:50:15.594834+00:00</updated>
    <content>EUVD-2026-186175</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-186175"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45816</id>
    <title>fkie_cve-2024-45816</title>
    <updated>2026-10-03T12:50:15.594849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage. This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package. All users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-45816"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-39v3-f278-vj3g</id>
    <title>GHSA-39v3-f278-vj3g — @backstage/plugin-techdocs-backend storage bucket Directory Traversal vulnerability</title>
    <updated>2026-10-03T12:50:15.594882+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @backstage/plugin-techdocs-backend</p>
<p>### Impact</p>
<p>When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage.</p>
<p>### Patches</p>
<p>This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package.</p>
<p>### References</p>
<p>If you have any questions or comments about this advisory:</p>
<p>Open an issue in the [Backstage repository](https://github.com/backstage/backstage)
Visit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-39v3-f278-vj3g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2024:11265</id>
    <title>RHBA-2024:11265 — Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.4.0 release.</title>
    <updated>2026-10-03T12:50:15.594913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>http-proxy-middleware: http-proxy-middleware: Denial of Service via unhandled error during path matching cross-spawn: regular expression denial of service path-to-regexp: Backtracking regular expressions cause ReDoS body-parser: Denial of Service Vulnerability in body-parser plugin-catalog-backend: prototype pollution vulnerability plugin-techdocs-backend: storage bucket directory traversal in TechDocs plugin-techdocs-backend: circumvention of XSS protection in TechDocs backstage/plugin-app-backend: Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2024:11265"/>
  </entry>
</feed>
