<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:39:19.765246+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-257151</id>
    <title>EUVD-2026-257151</title>
    <updated>2026-10-02T18:39:19.816964+00:00</updated>
    <content>EUVD-2026-257151</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-257151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27093</id>
    <title>fkie_cve-2025-27093</title>
    <updated>2026-10-02T18:39:19.817009+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to communicate with each other unrestrictedly, potentially enabling leaked or recovered keypairs to be used to attack operators or allowing port forwardings to be accessible from other implants.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-27093"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q8j9-34qf-7vq7</id>
    <title>GHSA-q8j9-34qf-7vq7 — Silver has unrestricted traffic between Wireguard clients</title>
    <updated>2026-10-02T18:39:19.817053+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/BishopFox/sliver</p>
<p>### Summary
Sliver's custom Wireguard netstack doesn't limit traffic between Wireguard clients, this could lead to:
1. Leaked/recovered keypair (from a beacon) being used to attack operators.
2. Port forwardings usable from other implants.</p>
<p>### Details
1. Sliver treat operators' Wireguard config and beacon/session's Wireguard config equally, they both connect to the wireguard listener created from the CLI.</p>
<p>2. The current netstack implementation does not filter traffic between clients. 
I think this piece of code handle traffic between clients, from experimental results clients can ping and connect to each other freely, and I didn't see any filtering here either:
```
File: server\c2\wireguard.go
246: func socketWGWriteEnvelope(connection net.Conn, envelope *sliverpb.Envelope) error {
247: 	data, err := proto.Marshal(envelope)
248: 	if err != nil {
249: 		wgLog.Errorf("Envelope marshaling error: %v", err)
250: 		return err
251: 	}
252: 	dataLengthBuf := new(bytes.Buffer)
253: 	binary.Write(dataLengthBuf, binary.LittleEndian, uint32(len(data)))
254: 	connection.Write(dataLengthBuf.Bytes())
255: 	connection.Write(data)
256: 	return nil
257: }
258:</p>
<p>```
3. The docs says to use a Wireguard clients and operator wg-config to connect to the same WG listener as beacons:
https://sliver.sh/docs?name=Port%20Forwarding</p>
<p>4. If the operator uses official wireguard clients that integrates with the OS's netstack (I'm using the [Windows client](https://www.wireguard.com/install/)) then thei…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q8j9-34qf-7vq7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1</id>
    <title>openSUSE-SU-2025:15710-1 — govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media</title>
    <updated>2026-10-02T18:39:19.817131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1"/>
  </entry>
</feed>
