<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T11:22:57.075030+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-227290</id>
    <title>EUVD-2026-227290</title>
    <updated>2026-10-08T11:22:57.077795+00:00</updated>
    <content>EUVD-2026-227290</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-227290"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32013</id>
    <title>fkie_cve-2025-32013</title>
    <updated>2026-10-08T11:22:57.077826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authentication handling functionality. When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn't properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-32013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qp8j-p87f-c8cc</id>
    <title>GHSA-qp8j-p87f-c8cc — LNbits Lightning Network Payment System Vulnerable to Server-Side Request Forgery via LNURL Authentication Callback</title>
    <updated>2026-10-08T11:22:57.077860+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lnbits</p>
<p># Server-Side Request Forgery via LNURL Authentication Callback in LNbits Lightning Network Payment System</p>
<p>## Disclaimer</p>
<p>This vulnerability was detected using **[XBOW](https://xbow.com/)**, a system that autonomously finds and exploits potential security vulnerabilities. The finding has been thoroughly reviewed and validated by a security researcher before submission. While XBOW is intended to work autonomously, during its development human experts ensure the accuracy and relevance of its reports.</p>
<p>## Description</p>
<p>A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authentication handling functionality. The vulnerability exists in the LNURL authentication callback process where the application makes HTTP requests to user-provided callback URLs and follows redirects without proper validation.</p>
<p>When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn't properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.</p>
<p>This vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal network locations, potentially exposing sensitive information or accessing internal services that should not be accessible from the internet.</p>
<p>## Steps to Reproduce</p>
<p>1. Create a new wallet account to get an admin k…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qp8j-p87f-c8cc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2025-16</id>
    <title>PYSEC-2025-16</title>
    <updated>2026-10-08T11:22:57.077910+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lnbits</p>
<p>LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authentication handling functionality. When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn't properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2025-16"/>
  </entry>
</feed>
