<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T10:27:58.141821+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-220259</id>
    <title>EUVD-2026-220259</title>
    <updated>2026-10-08T10:27:58.144409+00:00</updated>
    <content>EUVD-2026-220259</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-220259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-25301</id>
    <title>fkie_cve-2025-25301</title>
    <updated>2026-10-08T10:27:58.144441+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker may be able to query this endpoint to view pictures hosted on the internal network of the rembg server. This issue may lead to Information Disclosure.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-25301"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r5gx-c49x-h878</id>
    <title>GHSA-r5gx-c49x-h878 — Rembg allows SSRF via /api/remove</title>
    <updated>2026-10-08T10:27:58.144471+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: rembg</p>
<p>Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker may be able to query this endpoint to view pictures hosted on the internal network of the rembg server. This issue may lead to Information Disclosure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r5gx-c49x-h878"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2025-24</id>
    <title>PYSEC-2025-24</title>
    <updated>2026-10-08T10:27:58.144495+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: rembg</p>
<p>Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query parameter that allows an image to be fetched, processed and returned. An attacker may be able to query this endpoint to view pictures hosted on the internal network of the rembg server. This issue may lead to Information Disclosure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2025-24"/>
  </entry>
</feed>
