<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:55:58.607598+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10713</id>
    <title>bdu:2026-10713</title>
    <updated>2026-10-02T16:55:58.613894+00:00</updated>
    <content>bdu:2026-10713</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10713"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0948</id>
    <title>certfr-2026-avi-0948 — Une vulnérabilité a été découverte dans Ruby on Rails activestorage. Elle permet à un attaquant de provoquer une exécut…</title>
    <updated>2026-10-02T16:55:58.613928+00:00</updated>
    <content>certfr-2026-avi-0948</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0948"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-348505</id>
    <title>EUVD-2026-348505</title>
    <updated>2026-10-02T16:55:58.613947+00:00</updated>
    <content>EUVD-2026-348505</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-348505"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66066</id>
    <title>fkie_cve-2026-66066</title>
    <updated>2026-10-02T16:55:58.613959+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-66066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xr9x-r78c-5hrm</id>
    <title>GHSA-xr9x-r78c-5hrm — Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing</title>
    <updated>2026-10-02T16:55:58.613988+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: activestorage</p>
<p>### Impact
In its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds `secret_key_base` and often credentials for external systems, which
may in turn allow escalation to remote code execution or lateral movement to those systems.</p>
<p>### Details
libvips reads and writes file formats through "loaders" and "savers" (or more generally
"operations"), many of which are backed by third-party libraries. It marks some of these operations
as "unfuzzed", meaning they are unsafe for untrusted content, and several handle formats unrelated
to web images. Active Storage did not disable the unfuzzed operations, so an attacker who can upload
a crafted file and cause a variant to be generated from it may be able to invoke one.</p>
<p>We are aware of a mechanism by which an attacker, by uploading a crafted file, is able to cause
disclosure of the contents of arbitrary files accessible on the filesystem of the targeted
application. One specific attack chain has been reported to us (see "Disclosure" below), but we do
not assume it is the only one that exists.</p>
<p>### Affected applications
An application is affected if it meets all of these requirements:
- Uses libvips for Active Storage image processing. This is `config.active_storage.variant_processor = :vips`,
  which `load_defaults 7.0` set and no later default has changed.
- Allows image…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xr9x-r78c-5hrm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-66066</id>
    <title>UBUNTU-CVE-2026-66066</title>
    <updated>2026-10-02T16:55:58.614043+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:26.04:LTS: rails</p>
<p>Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-66066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2574</id>
    <title>WID-SEC-W-2026-2574 — Ruby on Rails: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-02T16:55:58.614072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby on Rails ausnutzen, um Informationen offenzulegen, was möglicherweise zur Remote-Codeausführung oder zu lateraler Bewegung führen kann.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2574"/>
  </entry>
</feed>
