<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:30:56.289149+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00103</id>
    <title>bdu:2026-00103</title>
    <updated>2026-10-03T17:30:56.295841+00:00</updated>
    <content>bdu:2026-00103</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-22703</id>
    <title>cnvd-2025-22703</title>
    <updated>2026-10-03T17:30:56.295890+00:00</updated>
    <content>cnvd-2025-22703</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-22703"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248971</id>
    <title>EUVD-2026-248971</title>
    <updated>2026-10-03T17:30:56.295907+00:00</updated>
    <content>EUVD-2026-248971</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248971"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52996</id>
    <title>fkie_cve-2025-52996</title>
    <updated>2026-10-03T17:30:56.295919+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions 2.32.0 and prior, the implementation of password protected links is error-prone, resulting in potential unprotected sharing of a file through a direct download link. This link can either be shared unknowingly by a user or discovered from various locations such as the browser history or the log of a proxy server used. At time of publication, no known patched versions are available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-52996"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3v48-283x-f2w4</id>
    <title>GHSA-3v48-283x-f2w4 — File Browser's password protection of links is bypassable</title>
    <updated>2026-10-03T17:30:56.295952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser</p>
<p>## Summary ##</p>
<p>Files managed by the *File Browser* can be shared with a link to external persons. While the application allows protecting those links with a password, the implementation is error-prone, making an incidental unprotected sharing of a file possible.</p>
<p>## Impact ##</p>
<p>File owners might rest in the assumption that their shared files are only accessible to persons knowing the defined password, giving them a false sense of security. Meanwhile, attackers gaining access to the unprotected link can use this information alone to download the possibly sensitive file.</p>
<p>## Vulnerability Description ##</p>
<p>When sharing a file, the user is presented with a dialog asking for an optional password to protect the file share. The assumption of the user at this point would be, that the shared file won't be accessible without knowledge of the password. After clicking on `SHARE` the following dialog opens allowing the file's owner to copy the share-link:</p>
<p>![image](https://github.com/user-attachments/assets/f3add074-40ac-4367-a538-ede5bb526916)</p>
<p>In fact, there is not one, but two links offered: A `Download Link` and an unnamed second one. They have the following format:</p>
<p>* http://filebrowser.local:8080/share/6Gtw0xAw
* http://filebrowser.local:8080/api/public/dl/6Gtw0xAw/dummy1.pdf?token=voDK6j[...]</p>
<p>Apparently, the first of the two share links is that one that users are supposed to actually share, while the second one is a direct download link not protected by the password. This behavior…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3v48-283x-f2w4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</id>
    <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
    <updated>2026-10-03T17:30:56.296017+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1"/>
  </entry>
</feed>
