<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T19:23:45.434425+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253034</id>
    <title>EUVD-2026-253034</title>
    <updated>2026-10-04T19:23:45.437245+00:00</updated>
    <content>EUVD-2026-253034</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59410</id>
    <title>fkie_cve-2025-59410</title>
    <updated>2026-10-04T19:23:45.437276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use the HTTP protocol, rather than HTTPS. This means that an attacker could perform a Man-in-the-Middle attack, changing the network request so that a different piece of data gets downloaded. This vulnerability is fixed in 2.1.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-59410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mcvp-rpgg-9273</id>
    <title>GHSA-mcvp-rpgg-9273 — DragonFly's tiny file download uses hard coded HTTP protocol</title>
    <updated>2026-10-04T19:23:45.437308+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/dragonflyoss/dragonfly, Go: d7y.io/dragonfly/v2</p>
<p>### Impact
The code in the scheduler for downloading a tiny file is hard coded to use the HTTP protocol, rather than HTTPS. This means that an attacker could perform a Man-in-the-Middle attack, changing the network request so that a different piece of data gets downloaded. Due to the use of weak integrity checks (TOB-DF2-15), this modification of the data may go unnoticed.</p>
<p>```golang
// DownloadTinyFile downloads tiny file from peer without range.
func (p *Peer) DownloadTinyFile() ([]byte, error) {
       ctx, cancel := context.WithTimeout(context.Background(),
downloadTinyFileContextTimeout)
       defer cancel()
       // Download url:
http://${host}:${port}/download/${taskIndex}/${taskID}?peerId=${peerID}
       targetURL := url.URL{
Scheme:
}
"http",
fmt.Sprintf("%s:%d", p.Host.IP, p.Host.DownloadPort),
fmt.Sprintf("download/%s/%s", p.Task.ID[:3], p.Task.ID),
Host:
Path:
RawQuery: fmt.Sprintf("peerId=%s", p.ID),
```</p>
<p>A network-level attacker who cannot join a peer-to-peer network performs a Man-in-the-Middle attack on peers. The adversary can do this because peers (partially) communicate over plaintext HTTP protocol. The attack chains this vulnerability with the one described in TOB-DF2-15 to replace correct files with malicious ones. Unconscious peers use the malicious files.</p>
<p>### Patches</p>
<p>- Dragonfy v2.1.0 and above.</p>
<p>### Workarounds</p>
<p>There are no effective workarounds, beyond upgrading.</p>
<p>### References</p>
<p>A third party security audit was performed by Trail of Bits, you…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mcvp-rpgg-9273"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15576-1</id>
    <title>openSUSE-SU-2025:15576-1 — govulncheck-vulndb-0.0.20250924T192141-1.1 on GA media</title>
    <updated>2026-10-04T19:23:45.437404+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250924T192141-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15576-1"/>
  </entry>
</feed>
