<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:44:04.024527+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-226975</id>
    <title>EUVD-2026-226975</title>
    <updated>2026-10-02T18:44:04.098442+00:00</updated>
    <content>EUVD-2026-226975</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-226975"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-31483</id>
    <title>fkie_cve-2025-31483</title>
    <updated>2026-10-02T18:44:04.098481+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Miniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP of the media proxy and execute cross-site scripting when opening external images in a new tab/window. To mitigate the vulnerability, the CSP for the media proxy has been changed from default-src 'self' to default-src 'none'; form-action 'none'; sandbox;. This vulnerability is fixed in 2.2.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-31483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cq88-842x-2jhp</id>
    <title>GHSA-cq88-842x-2jhp — Miniflux Media Proxy vulnerable to Stored Cross-site Scripting due to improper Content-Security-Policy configuration</title>
    <updated>2026-10-02T18:44:04.098517+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: miniflux.app/v2</p>
<p>## Summary</p>
<p>Due to a weak Content Security Policy on the `/proxy/*` route, an attacker can bypass the CSP of the media proxy and execute cross-site scripting when opening external images in a new tab/window.</p>
<p>## Impact</p>
<p>A malicious feed added to Miniflux can execute arbitrary JavaScript in the user's browser when opening external resources, such as proxified images, in a new tab or window.</p>
<p>## Mitigation</p>
<p>The CSP for the media proxy has been changed from `default-src 'self'` to `default-src 'none'; form-action 'none'; sandbox;`.</p>
<p>Upgrade to Miniflux &gt;= 2.2.7</p>
<p>## Credit
[RyotaK](https://ryotak.net) (GMO Flatt Security Inc.) with [takumi-san.ai](https://takumi-san.ai)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cq88-842x-2jhp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14982-1</id>
    <title>openSUSE-SU-2025:14982-1 — govulncheck-vulndb-0.0.20250409T170536-1.1 on GA media</title>
    <updated>2026-10-02T18:44:04.098551+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250409T170536-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14982-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-31483</id>
    <title>UBUNTU-CVE-2025-31483</title>
    <updated>2026-10-02T18:44:04.098571+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:24.04:LTS: miniflux, Ubuntu:25.10: miniflux, Ubuntu:Pro:26.04:LTS: miniflux</p>
<p>Miniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP of the media proxy and execute cross-site scripting when opening external images in a new tab/window. To mitigate the vulnerability, the CSP for the media proxy has been changed from default-src 'self' to default-src 'none'; form-action 'none'; sandbox;. This vulnerability is fixed in 2.2.7.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-31483"/>
  </entry>
</feed>
