<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:08:27.550626+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362063</id>
    <title>EUVD-2026-362063</title>
    <updated>2026-10-03T04:08:27.553256+00:00</updated>
    <content>EUVD-2026-362063</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55247</id>
    <title>fkie_cve-2026-55247</title>
    <updated>2026-10-03T04:08:27.553290+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in editor can make the server request internal network resources or local calendar files, exhaust resources and take the site offline, and store a malicious event URL that executes script in another user's browser. The fix restricts accepted URLs, applies MAXIMUM_ICAL_IMPORT_SIZE_BYTES and MAXIMUM_ICAL_IMPORT_EVENTS limits, uses transaction savepoints, and validates event URLs. This issue is fixed in versions 5.2.4 and 6.0.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r82h-mqw3-fc56</id>
    <title>GHSA-r82h-mqw3-fc56 — plone.app.event vulnerable to denial of service via iCalendar import</title>
    <updated>2026-10-03T04:08:27.553326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: plone.app.event</p>
<p>### Impact
By abusing the iCalendar import functionality, a logged-in editor could take the whole site offline, make the server reach into the internal network and read calendar files off disk (SSRF), and store XSS.</p>
<p>### Patches
The problem has been patched in `plone.app.event`.</p>
<p>* For Plone 6.2: upgrade to `plone.app.event` 6.0.1
* For Plone 6.1: upgrade to `plone.app.event` 5.2.4
* For Plone 6.0: upgrade to `plone.app.event` 5.2.4</p>
<p>### Workarounds
In the site root, go to the Security tab of the Zope Management Interface (`manage_access`), look for the "plone.app.event: Import Ical" permission, and grant this only to the Manager role.  Then only users with the Manager role can use the ical import form.</p>
<p>There is no workaround for the stored XSS in the URL field of events.</p>
<p>The vulnerabilities were discovered by Timothy Dudley and responsibly reported to the [Plone Security Team](mailto:security@plone.org). Thank you!</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r82h-mqw3-fc56"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3883</id>
    <title>PYSEC-2026-3883 — plone.app.event vulnerable to denial of service via iCalendar import</title>
    <updated>2026-10-03T04:08:27.553362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: plone-app-event</p>
<p>### Impact
By abusing the iCalendar import functionality, a logged-in editor could take the whole site offline, make the server reach into the internal network and read calendar files off disk (SSRF), and store XSS.</p>
<p>### Patches
The problem has been patched in `plone.app.event`.</p>
<p>* For Plone 6.2: upgrade to `plone.app.event` 6.0.1
* For Plone 6.1: upgrade to `plone.app.event` 5.2.4
* For Plone 6.0: upgrade to `plone.app.event` 5.2.4</p>
<p>### Workarounds
In the site root, go to the Security tab of the Zope Management Interface (`manage_access`), look for the "plone.app.event: Import Ical" permission, and grant this only to the Manager role.  Then only users with the Manager role can use the ical import form.</p>
<p>There is no workaround for the stored XSS in the URL field of events.</p>
<p>The vulnerabilities were discovered by Timothy Dudley and responsibly reported to the [Plone Security Team](mailto:security@plone.org). Thank you!</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3883"/>
  </entry>
</feed>
