<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:10:15.230614+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-13744</id>
    <title>bdu:2026-13744</title>
    <updated>2026-10-03T15:10:15.338223+00:00</updated>
    <content>bdu:2026-13744</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-13744"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0690</id>
    <title>certfr-2026-avi-0690 — De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un contourne…</title>
    <updated>2026-10-03T15:10:15.338269+00:00</updated>
    <content>certfr-2026-avi-0690</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0690"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-qi45196</id>
    <title>Withdrawn: CLEANSTART-2026-QI45196 — Security fixes in forecastle 1.0.159-r1</title>
    <updated>2026-10-03T15:10:15.338301+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: forecastle</p>
<p>Package forecastle version 1.0.159-r1 fixes 43 vulnerabilities: CVE-2026-40611, CVE-2026-34986, CVE-2026-48020, CVE-2026-26999, CVE-2026-29054...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-qi45196"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362919</id>
    <title>EUVD-2026-362919</title>
    <updated>2026-10-03T15:10:15.338353+00:00</updated>
    <content>EUVD-2026-362919</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362919"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48020</id>
    <title>fkie_cve-2026-48020</title>
    <updated>2026-10-03T15:10:15.338380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authentication and authorization. When a public router matches on a PathPrefix rule and applies the StripPrefix middleware, a request path containing .. or its percent-encoded form %2e%2e can match the public route at routing time and then, after the prefix is stripped and the path is normalized, resolve to a path served by a separate, authenticated router. As a result, an attacker can reach protected backend paths — such as admin or internal configuration endpoints — without satisfying the authentication middleware attached to the protected router. This vulnerability is fixed in 2.11.48, 3.6.19, and 3.7.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48020"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xf64-8mw2-4gr2</id>
    <title>GHSA-xf64-8mw2-4gr2 — Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization</title>
    <updated>2026-10-03T15:10:15.338439+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3</p>
<p>## Summary</p>
<p>There is a high severity vulnerability in Traefik's `StripPrefix` middleware that allows an unauthenticated attacker to bypass route-level authentication and authorization. When a public router matches on a `PathPrefix` rule and applies the `StripPrefix` middleware, a request path containing `..` or its percent-encoded form `%2e%2e` can match the public route at routing time and then, after the prefix is stripped and the path is normalized, resolve to a path served by a separate, authenticated router. As a result, an attacker can reach protected backend paths — such as admin or internal configuration endpoints — without satisfying the authentication middleware attached to the protected router.</p>
<p>## Patches</p>
<p>- https://github.com/traefik/traefik/releases/tag/v2.11.48
- https://github.com/traefik/traefik/releases/tag/v3.6.19
- https://github.com/traefik/traefik/releases/tag/v3.7.3</p>
<p>## For more information</p>
<p>If there are any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).</p>
<p>&lt;details&gt;
&lt;summary&gt;Original Description&lt;/summary&gt;</p>
<p># Traefik StripPrefix Route-Level Auth Bypass via Path Normalization (/api../)</p>
<p>## Summary</p>
<p>A route-level authentication/authorization bypas was found in Traefik when `PathPrefix`-based public routes are combined with `StripPrefix`.</p>
<p>A request using `/api../` or `/api%2e%2e/` can avoid protected router rules at the routing stage, but after `StripPrefix`, the path is normalized and forwarde…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xf64-8mw2-4gr2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11045-1</id>
    <title>openSUSE-SU-2026:11045-1 — traefik2-2.11.50-1.1 on GA media</title>
    <updated>2026-10-03T15:10:15.338593+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>traefik2-2.11.50-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11045-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:62260</id>
    <title>RHSA-2026:62260 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.30.0 Release.</title>
    <updated>2026-10-03T15:10:15.338632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability curl: curl: Insecure connection establishment due to TLS configuration mismatch shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators curl: curl: Man-in-the-middle attack via SSH host key bypass org.eclipse.parsson/parsson: Eclipse Parsson: Denial of Service via uncontrolled resource consumption in JSON parsing jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections form-data: form-data: Form field override via CRLF injection undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects io.vertx/vertx-web: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object net/mail: golang: Go net/mail: Denial of Service via crafted email inputs golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check golang.org/x/cryp…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:62260"/>
  </entry>
</feed>
