<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:40:05.284251+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337428</id>
    <title>EUVD-2026-337428</title>
    <updated>2026-10-02T18:40:05.535797+00:00</updated>
    <content>EUVD-2026-337428</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27489</id>
    <title>fkie_cve-2026-27489</title>
    <updated>2026-10-02T18:40:05.535845+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27489"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3r9x-f23j-gc73</id>
    <title>GHSA-3r9x-f23j-gc73 — onnx Vulnerable to Path Traversal via Symlink</title>
    <updated>2026-10-02T18:40:05.535879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: onnx</p>
<p>### Summary
A path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory.</p>
<p>### Details
The following check for symlink is ineffective and it is possible to point a symlink to an arbitrary location on the file system:
https://github.com/onnx/onnx/blob/336652a4b2ab1e530ae02269efa7038082cef250/onnx/checker.cc#L1024-L1033</p>
<p>`std::filesystem::is_regular_file` performs a `status(p)` call on the provided path, which follows symbolic links to determine the file type, meaning it will return true if the target of a symlink is a regular file.</p>
<p>### PoC</p>
<p>```python
# Create a demo model with external data
import os
import numpy as np
import onnx
from onnx import helper, TensorProto, numpy_helper</p>
<p>def create_onnx_model(output_path="model.onnx"):
    weight_matrix = np.random.randn(1000, 1000).astype(np.float32)</p>
<p>X = helper.make_tensor_value_info("X", TensorProto.FLOAT, [1, 1000])
    Y = helper.make_tensor_value_info("Y", TensorProto.FLOAT, [1, 1000])
    W = numpy_helper.from_array(weight_matrix, name="W")</p>
<p>matmul_node = helper.make_node("MatMul", inputs=["X", "W"], outputs=["Y"], name="matmul")</p>
<p>graph = helper.make_graph(
        nodes=[matmul_node],
        name="SimpleModel",
        inputs=[X],
        outputs=[Y],
        initializer=[W]
    )</p>
<p>model = helper.make_model(graph, opset_imports=[helper.make_opsetid("", 11)])
    onnx.checker.check_model(model)</p>
<p>data_file = output_path.replace('.onnx', '.data')…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3r9x-f23j-gc73"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2239</id>
    <title>PYSEC-2026-2239</title>
    <updated>2026-10-02T18:40:05.535940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: onnx</p>
<p>Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2239"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:24977</id>
    <title>RHSA-2026:24977 — Red Hat Security Advisory: RHOAI 2.25.7 - Red Hat OpenShift AI</title>
    <updated>2026-10-02T18:40:05.535962+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests golang: net/url: Memory exhaustion in query parameter parsing in net/url axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization aiohttp: aiohttp: Denial of Service via specially crafted POST request aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe Mode lodash: lodash: Arbitrary code execution via untrusted input in template imports fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID pytorch: PyTorch: Arbitrary code execution via malicious checkpoint file loading xgrammar: xgrammar: Denial of Service via multi-level nested syntax vLLM: vLLM: Server-Side Request Forgery bypass via inconsistent URL parsing onnx: ONNX: Information Disclosure via Path Traversal Vulnerability vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting onnx: ONNX: Untrusted Model Repository Warnings Suppressed python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution svgo: SVGO: Denial of Service via XML entity expansion tornado-pyth…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:24977"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27489</id>
    <title>UBUNTU-CVE-2026-27489</title>
    <updated>2026-10-02T18:40:05.536041+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: onnx, Ubuntu:Pro:24.04:LTS: onnx, Ubuntu:25.10: onnx, Ubuntu:26.04:LTS: onnx</p>
<p>Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27489"/>
  </entry>
</feed>
