<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T06:29:13.649125+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-268864</id>
    <title>EUVD-2026-268864</title>
    <updated>2026-10-09T06:29:13.652731+00:00</updated>
    <content>EUVD-2026-268864</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-268864"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24126</id>
    <title>fkie_cve-2026-24126</title>
    <updated>2026-10-09T06:29:13.652774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-24126"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-33fm-6gp7-4p47</id>
    <title>GHSA-33fm-6gp7-4p47 — Weblate has an argument injection in management console</title>
    <updated>2026-10-09T06:29:13.652820+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Weblate</p>
<p>### Impact
The SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`.</p>
<p>### Patches
* https://github.com/WeblateOrg/weblate/pull/17722</p>
<p>### Workarounds
Properly limit access to the management console.</p>
<p>### References
This issue was reported to us by [alexb_616](https://hackerone.com/alexb_616) via HackerOne.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-33fm-6gp7-4p47"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2309</id>
    <title>PYSEC-2026-2309</title>
    <updated>2026-10-09T06:29:13.652862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: weblate</p>
<p>Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2309"/>
  </entry>
</feed>
