<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T02:01:51.447254+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-349351</id>
    <title>EUVD-2026-349351</title>
    <updated>2026-10-04T02:01:51.528665+00:00</updated>
    <content>EUVD-2026-349351</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-349351"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-62996</id>
    <title>fkie_cve-2026-62996</title>
    <updated>2026-10-04T02:01:51.528710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped resource name to be used to read the contents of arbitrary local files accessible to the PHP process. An attacker able to author or influence a template's resource reference could exploit this to disclose sensitive file contents outside the intended template/config scope. This issue is fixed in version 5.8.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-62996"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rjhh-76wf-8xmw</id>
    <title>GHSA-rjhh-76wf-8xmw — Smarty Security stream restriction bypass through stream: resource</title>
    <updated>2026-10-04T02:01:51.528749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: smarty/smarty</p>
<p>`smarty/smarty` version `5.8.0` can read local files through PHP stream wrappers even when Smarty Security is enabled and all streams are disabled with `Security::$streams = null`.</p>
<p>The bypass uses Smarty's built-in `stream:` resource type. A template such as:</p>
<p>```smarty
{include file="stream:php://filter/read=convert.base64-encode/resource=/tmp/secret.tpl"}
```</p>
<p>is handled as Smarty resource type `stream`, so the security check that would normally reject the underlying `php` wrapper is not applied. `StreamPlugin` then opens the nested `php://filter/...` URI directly.</p>
<p>For comparison, the direct resource:</p>
<p>```smarty
{include file="php://filter/read=convert.base64-encode/resource=/tmp/secret.tpl"}
```</p>
<p>is blocked with `stream 'php' not allowed by security setting`.</p>
<p>Affected package:</p>
<p>- Ecosystem: Packagist / Composer
- Package: `smarty/smarty`
- Confirmed affected version: `5.8.0`
- Confirmed source reference from Composer lock: `78d259d3b971c59a0cd719c270cc5cbb740c36a7`
- Current stable version on Packagist at review time: `v5.8.0`
- Packagist usage at review time: 41,113,855 total downloads and 840,604 monthly downloads</p>
<p>Relevant code paths:</p>
<p>- `Smarty\Resource\BasePlugin::load(...)`
- `Smarty\Resource\StreamPlugin::getContent(...)`
- `Smarty\Security::isTrustedStream(...)`</p>
<p>`BasePlugin::load()` maps the built-in resource name `stream` directly to `StreamPlugin` before the code path that checks PHP stream wrappers with `stream_get_wrappers()` and `Security::isTrustedStream…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rjhh-76wf-8xmw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-62996</id>
    <title>UBUNTU-CVE-2026-62996</title>
    <updated>2026-10-04T02:01:51.528813+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: smarty3, Ubuntu:Pro:18.04:LTS: smarty3, Ubuntu:Pro:20.04:LTS: smarty3, Ubuntu:22.04:LTS: smarty3, Ubuntu:24.04:LTS: smarty3, Ubuntu:24.04:LTS: smarty4, Ubuntu:26.04:LTS: smarty3, Ubuntu:26.04:LTS: smarty4</p>
<p>Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped resource name to be used to read the contents of arbitrary local files accessible to the PHP process. An attacker able to author or influence a template's resource reference could exploit this to disclose sensitive file contents outside the intended template/config scope. This issue is fixed in version 5.8.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-62996"/>
  </entry>
</feed>
