<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:12:59.347001+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-246993</id>
    <title>EUVD-2026-246993</title>
    <updated>2026-10-03T14:12:59.415864+00:00</updated>
    <content>EUVD-2026-246993</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-246993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-0928</id>
    <title>fkie_cve-2025-0928</title>
    <updated>2026-10-03T14:12:59.415898+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model membership or requiring explicit permissions. This enabled the distribution of poisoned binaries to new or upgraded machines, potentially resulting in remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-0928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4vc8-wvhw-m5gv</id>
    <title>GHSA-4vc8-wvhw-m5gv — Juju allows arbitrary executable uploads via authenticated endpoint without authorization</title>
    <updated>2026-10-03T14:12:59.415930+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/juju/juju</p>
<p>### Summary
You can affect the agent binaries used in a Juju controller and the code that is run in the binaries by simply having a user account on a controller. You aren't required to have a model or any permissions. This just requires a user account in the controller database.</p>
<p>### Details
Because of the way Juju upload tools code works in the controller it only checks that the user uploading agent binaries is authenticated and is a user tag. No more checks are performed and it allows that user to upload binaries to any model they like (as long as they know the model uuid) or upload binaries to the controller (attacker doesn't need to know any uuid's for controller or controller model).</p>
<p>Once the poison binaries have been uploaded any new machine that is started in the affected model or controller will get started with the poison binaries. Alternatively administrator's of the controller running either `juju upgrade-controller` or `juju upgrade-model` will force distribution of the poisoned binaries to all machines in either the model or poison the controllers themselves.</p>
<p>On top of this the exploit can be done with the Juju client tooling itself and no real knowledge on constructing raw API requests is required.</p>
<p>The tools handler is the main piece of code that is used in the APIServer for handling upload requests and persisting the data uploaded: The following code references is how Juju uses and defines this:
- The tools upload handler is defined here (https://github.com…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4vc8-wvhw-m5gv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</id>
    <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
    <updated>2026-10-03T14:12:59.415996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1"/>
  </entry>
</feed>
