<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:10:08.931758+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-252142</id>
    <title>EUVD-2026-252142</title>
    <updated>2026-10-02T17:10:08.981913+00:00</updated>
    <content>EUVD-2026-252142</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-252142"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58445</id>
    <title>fkie_cve-2025-58445</title>
    <updated>2026-10-02T17:10:08.981948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with the specific versions, potentially compromising the service's security posture. This issue does not currently have a fix.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-58445"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xh7v-965r-23f7</id>
    <title>GHSA-xh7v-965r-23f7 — Atlantis Exposes Service Version Publicly on /status API Endpoint</title>
    <updated>2026-10-02T17:10:08.981982+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/runatlantis/atlantis</p>
<p>### Summary
Atlantis publicly exposes detailed version information on its `/status` endpoint. This information disclosure could allow attackers to identify and target known vulnerabilities associated with the specific versions, potentially compromising the service's security posture.</p>
<p>### Details
The `/status` endpoint in Atlantis returns not only a health check but also detailed version and build information. This disclosure violates the principle of minimizing exposed sensitive metadata and can be leveraged by adversaries to correlate the version information with public vulnerability databases, including CVE listings. Although Atlantis is a public repository maintained by an external team, reducing this exposure can lessen the overall risk of targeted attacks.</p>
<p>For example, the source code handling the `/status` endpoint exposes version details that allow one to infer software dependencies and system configurations. Best practices, including guidelines from the [OWASP Top 10](https://owasp.org/www-project-top-ten/) and recommendations discussed in NIST SP 800-53, advocate for restricting such potentially exploitable information.</p>
<p>### PoC
1. Issue a GET request to `http://&lt;atlantis-host&gt;/status` using a tool like `curl` or a web browser.
2. Note that the API response includes detailed version and build information.
3. Verify that no authentication is required to access the endpoint, leading to public exposure.
4. Cross-reference the disclosed version with public vulnerabili…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xh7v-965r-23f7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15564-1</id>
    <title>openSUSE-SU-2025:15564-1 — govulncheck-vulndb-0.0.20250917T170349-1.1 on GA media</title>
    <updated>2026-10-02T17:10:08.982026+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250917T170349-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15564-1"/>
  </entry>
</feed>
