<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:38:36.093876+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-fx79373</id>
    <title>CLEANSTART-2026-FX79373 — Security fix for CVE-2026-48816 applied in: pulumi 3.248.0-r0, renovate 44.31.0-r2, renovate 44.32.4-r1, renovate 44.32…</title>
    <updated>2026-10-03T00:38:36.143928+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: pulumi, CleanStart: renovate</p>
<p>CVE-2026-48816 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-fx79373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337995</id>
    <title>EUVD-2026-337995</title>
    <updated>2026-10-03T00:38:36.143992+00:00</updated>
    <content>EUVD-2026-337995</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337995"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48816</id>
    <title>fkie_cve-2026-48816</title>
    <updated>2026-10-03T00:38:36.144009+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind integratedTime, allowing an attacker who can supply an untrusted bundle to influence certificate validity and timestampThreshold verification decisions. This issue is fixed in version 3.1.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48816"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xgjw-pm74-86q4</id>
    <title>GHSA-xgjw-pm74-86q4 — sigstore-js has Insufficient Verification of Data Authenticity</title>
    <updated>2026-10-03T00:38:36.144035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @sigstore/verify</p>
<p>sigstore-js derives a transparency-log timestamp from `tlogEntries[].integratedTime` and uses it to validate certificate validity windows and satisfy `timestampThreshold`. For bundle v0.2, a tlog entry can be inclusionProof-only (no signed inclusionPromise/set), and the inclusion proof path does not cryptographically bind `integratedTime`. As a result, an attacker who can supply an untrusted bundle can influence time-based verification decisions by choosing `integratedTime`.</p>
<p>## impact
If a consumer accepts attacker-provided bundle v0.2 inputs and relies on tlog-derived timestamps for certificate validity checks, verification can be influenced by an unauthenticated timestamp value. This is a trust gap: `integratedTime` is treated as a trusted observer timestamp under inclusionProof-only mode even though only the signed inclusionPromise/set path binds it.</p>
<p>## affected code
- `packages/verify/src/bundle/index.ts` (adds a transparency-log timestamp whenever `integratedTime != 0`)
- `packages/verify/src/timestamp/index.ts` (converts `integratedTime` to a `Date`)
- `packages/verify/src/verifier.ts` (verifies timestamps before verifying tlog inclusion)
- `packages/verify/src/tlog/index.ts` + `packages/verify/src/tlog/set.ts` (only the inclusionPromise/set path binds `integratedTime`)</p>
<p>## proof of concept
The attached `poc.zip` contains a self-contained harness that reproduces the behavior on the pinned commit and includes both a canonical test and a negative control.</p>
<p>repro:
1) ex…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xgjw-pm74-86q4"/>
  </entry>
</feed>
