<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:37:47.170527+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05283</id>
    <title>bdu:2026-05283</title>
    <updated>2026-10-03T14:37:47.244265+00:00</updated>
    <content>bdu:2026-05283</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05283"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0682</id>
    <title>certfr-2026-avi-0682 — Une vulnérabilité a été découverte dans les produits Laravel. Elle permet à un attaquant de provoquer un contournement…</title>
    <updated>2026-10-03T14:37:47.244309+00:00</updated>
    <content>certfr-2026-avi-0682</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0682"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290302</id>
    <title>EUVD-2026-290302</title>
    <updated>2026-10-03T14:37:47.244329+00:00</updated>
    <content>EUVD-2026-290302</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290302"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39976</id>
    <title>fkie_cve-2026-39976</title>
    <updated>2026-10-03T14:37:47.244341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials tokens. the league/oauth2-server library sets the JWT sub claim to the client identifier (since there's no user). The token guard then passes this value to retrieveById() without validating it's actually a user identifier, potentially resolving an unrelated real user. Any machine-to-machine token can inadvertently authenticate as an actual user. This vulnerability is fixed in 13.7.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39976"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-349c-2h2f-mxf6</id>
    <title>GHSA-349c-2h2f-mxf6 — Laravel Passport: TokenGuard Authenticates Unrelated User for Client Credentials Tokens</title>
    <updated>2026-10-03T14:37:47.244376+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: laravel/passport</p>
<p>### Impact
Authentication Bypass for `client_credentials` tokens. the league/oauth2-server library sets the JWT sub claim to the client identifier (since there's no user). The token guard then passes this value to retrieveById() without validating it's actually a user identifier, potentially resolving an unrelated real user. Any machine-to-machine token can inadvertently authenticate as an actual user.</p>
<p>Usage of `EnsureClientIsResourceOwner` middleware together with `Passport::$clientUuids` set to `false`, can result in resolving the user instead, as stated in the [documentation](https://laravel.com/docs/13.x/passport#:~:text=The%20underlying%20OAuth2,client%20credentials%20token).</p>
<p>&gt; The [underlying OAuth2 server](https://oauth2.thephpleague.com/database-setup/#:~:text=Please%20note%20that,the%20bearer%20token.) sets the token's sub claim to the client's identifier for client credentials tokens. By default, Passport uses UUIDs for clients, so this cannot collide with a user's integer primary key. However, if you have set Passport::$clientUuids to false, a client credentials token may inadvertently resolve a user whose ID matches the client's ID. In such cases, using this middleware cannot guarantee that the incoming token is a client credentials token.</p>
<p>### Patches
Patched in v13.7.1</p>
<p>### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
Disallow usage of `client_credentials`.</p>
<p>### References
- https://github.com/laravel/pas…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-349c-2h2f-mxf6"/>
  </entry>
</feed>
