<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:44:13.512237+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343532</id>
    <title>EUVD-2026-343532</title>
    <updated>2026-10-04T01:44:13.592355+00:00</updated>
    <content>EUVD-2026-343532</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343532"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63223</id>
    <title>fkie_cve-2026-63223</title>
    <updated>2026-10-04T01:44:13.592401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads using is_image or mime_in without an independent safe extension check (such as ext_in on patched versions), save uploaded files using the client-supplied filename, and place uploads in a web-accessible directory where PHP files can execute. This issue is fixed in version 4.7.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mmj4-63m4-r6h5</id>
    <title>GHSA-mmj4-63m4-r6h5 — CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules</title>
    <updated>2026-10-04T01:44:13.592437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: codeigniter4/framework</p>
<p>### Impact
This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations.</p>
<p>Applications are impacted when they:
- validate uploads using `is_image` or `mime_in` without an independent safe extension check, such as `ext_in` on patched versions
- save uploaded files using the client-supplied filename
- place uploads in a web-accessible directory where PHP files can execute</p>
<p>### Patches
Upgrade to v4.7.4 or later.</p>
<p>### Workarounds
- Save uploads outside the public web root, preferably under `writable/uploads`.
- Use `$file-&gt;store()` or `$file-&gt;move($path, $file-&gt;getRandomName())` instead of preserving the original client filename.
- Disable script execution in any public upload directory.
- Manually verify the client filename extension before moving the file.
- For image uploads, reject files when `$file-&gt;getClientExtension()` is not an allowed image extension.
- For exact MIME-type validation, reject files when `$file-&gt;getClientExtension()` does not match `$file-&gt;guessExtension()`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mmj4-63m4-r6h5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63223</id>
    <title>UBUNTU-CVE-2026-63223</title>
    <updated>2026-10-04T01:44:13.592472+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: php-codeigniter-framework, Ubuntu:26.04:LTS: php-codeigniter-framework</p>
<p>CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads using is_image or mime_in without an independent safe extension check (such as ext_in on patched versions), save uploaded files using the client-supplied filename, and place uploads in a web-accessible directory where PHP files can execute. This issue is fixed in version 4.7.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63223"/>
  </entry>
</feed>
