<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:16:09.087382+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-357245</id>
    <title>EUVD-2026-357245</title>
    <updated>2026-10-04T15:16:09.090588+00:00</updated>
    <content>EUVD-2026-357245</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-357245"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67448</id>
    <title>fkie_cve-2026-67448</title>
    <updated>2026-10-04T15:16:09.090633+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path, and server/websockets/client.go configures websocket.Upgrader.CheckOrigin to return true. A malicious website can request /%61pi/events, skip corsOriginAccessControl(), reach the /api/events WebSocket handler, and receive live message IDs, Message-Id values, sender and recipient fields, subjects, tags, and body snippets from an unauthenticated default Mailpit instance after the user visits the site. This is a regression of the earlier WebSocket origin protection and does not affect deployments protected by --ui-auth-file. This issue is fixed in version 1.30.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-67448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8r62-w5wh-fc5m</id>
    <title>GHSA-8r62-w5wh-fc5m — Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)</title>
    <updated>2026-10-04T15:16:09.090674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/axllent/mailpit</p>
<p>## Summary</p>
<p>The cross-site WebSocket hijacking fix was reimplemented as an origin check gated on a raw-URI prefix test, but Go's ServeMux routes on the percent-decoded path, so requesting /%61pi/events reaches the WebSocket handler while skipping the only origin control, and the upgrader itself accepts every origin. Confirmed at HEAD 408b30d. Affects 1.29.0 through 1.30.5.</p>
<p>## The defect</p>
<p>Two halves that were each correct in isolation. server/websockets/client.go accepts any origin and delegates the check elsewhere:</p>
<p>```go
var upgrader = websocket.Upgrader{                       // line 33
    ...
    CheckOrigin: func(_ *http.Request) bool {            // line 37
        // origin is checked via server.go's CORS settings
        return true                                      // line 39
    },
}
```</p>
<p>server/server.go performs that check but keys it on the RAW request target:</p>
<p>```go
if strings.HasPrefix(r.RequestURI, config.Webroot+"api/") || htmlPreviewRouteRe.MatchString(r.RequestURI) {   // line 320
    if allowed := corsOriginAccessControl(r); !allowed {
        http.Error(w, "Blocked due to CORS violation", http.StatusForbidden)
        return
    }
```</p>
<p>r.RequestURI is the untouched wire target; Go's ServeMux routes on the percent-DECODED path. So for /%61pi/events: `strings.HasPrefix("/%61pi/events", "/api/")` is FALSE (origin check skipped), ServeMux decodes %61 to "a" and routes to /api/events, and the upgrader's CheckOrigin returns true.</p>
<p>Measured, default config,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8r62-w5wh-fc5m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2556</id>
    <title>WID-SEC-W-2026-2556 — MailPit: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-04T15:16:09.090733+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in MailPit ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2556"/>
  </entry>
</feed>
