<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:41:56.324437+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10549</id>
    <title>bdu:2026-10549</title>
    <updated>2026-10-03T14:41:56.335444+00:00</updated>
    <content>bdu:2026-10549</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10549"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2026-10601</id>
    <title>BIT-grafana-2026-10601 — Path traversal in the Tempo and Loki data source plugins</title>
    <updated>2026-10-03T14:41:56.335484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2026-10601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-360220</id>
    <title>EUVD-2026-360220</title>
    <updated>2026-10-03T14:41:56.335516+00:00</updated>
    <content>EUVD-2026-360220</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-360220"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-10601</id>
    <title>fkie_cve-2026-10601</title>
    <updated>2026-10-03T14:41:56.335529+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-10601"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9493-h4f5-633x</id>
    <title>GHSA-9493-h4f5-633x — Grafana: Path traversal in the Tempo and Loki data source plugins</title>
    <updated>2026-10-03T14:41:56.335550+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling path traversal. A Viewer-role user can: (1) capture admin-configured datasource credentials (secureJsonData custom headers) by traversing to an attacker-controlled endpoint, (2) invoke state-changing admin endpoints on Tempo (e.g. /flush, /shutdown), and (3) exfiltrate internal service data via Loki's CallResource which returns full HTTP response bodies.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9493-h4f5-633x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:62527</id>
    <title>RHSA-2026:62527 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T14:41:56.335575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana: tempo: loki: Tempo and Loki Datasource Plugins: Information disclosure and unauthorized actions via path traversal github.com/mark3labs/mcp-go: mcp-go: DNS Rebinding vulnerability due to missing Host header validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:62527"/>
  </entry>
</feed>
