<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T16:37:17.578886+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-359461</id>
    <title>EUVD-2026-359461</title>
    <updated>2026-10-05T16:37:18.739367+00:00</updated>
    <content>EUVD-2026-359461</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-359461"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71366</id>
    <title>fkie_cve-2026-71366</title>
    <updated>2026-10-05T16:37:18.739409+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates pointing to internal or loopback addresses, causing the AWX control node to issue HTTP requests to services that are not externally accessible. Additionally, the webhook notification backend follows HTTP redirects and resends configured Basic Authentication credentials to redirect targets regardless of host change, allowing an attacker to exfiltrate notification credentials by redirecting to an attacker-controlled host. The Grafana backend sends its API key in the Authorization header to the configured target URL.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-71366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8vqh-rjh4-52qh</id>
    <title>GHSA-8vqh-rjh4-52qh</title>
    <updated>2026-10-05T16:37:18.739452+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates pointing to internal or loopback addresses, causing the AWX control node to issue HTTP requests to services that are not externally accessible. Additionally, the webhook notification backend follows HTTP redirects and resends configured Basic Authentication credentials to redirect targets regardless of host change, allowing an attacker to exfiltrate notification credentials by redirecting to an attacker-controlled host. The Grafana backend sends its API key in the Authorization header to the configured target URL.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8vqh-rjh4-52qh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:59135</id>
    <title>RHSA-2026:59135 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update</title>
    <updated>2026-10-05T16:37:18.739474+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>django: Django: Remote code execution via GeoDjango spatial lookups aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens tmp: path Traversal via unsanitized prefix/postfix enables directory escape awxkit: path traversal via YAML !include directive pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options gitpython: GitPython: Arbitrary Code Execution via Joined Short Options Bypass gitpython: GitPython: Command Injection via Git option prefix abbreviation aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses awx: project archive extraction allows path traversal file writes awx: webhook status callback SSRF leaks the Git PAT awx: notification backends allow SSRF and credential leakage gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding GitPython: GitPython: Arbitrary file read via TagReference.create()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:59135"/>
  </entry>
</feed>
