<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:17:59.906127+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352277</id>
    <title>EUVD-2026-352277</title>
    <updated>2026-10-03T05:17:59.973144+00:00</updated>
    <content>EUVD-2026-352277</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352277"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73563</id>
    <title>fkie_cve-2026-73563</title>
    <updated>2026-10-03T05:17:59.973183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for auth.experimentalDynamicClientRegistration.allowedRedirectUriPatterns and the auth.experimentalClientIdMetadataDocuments allowedClientIdPatterns and allowedRedirectUriPatterns options. A hostname wildcard can match across URL component boundaries, allowing an attacker-controlled redirect URI with a trusted hostname suffix in its path to pass the allowlist and receive an OAuth authorization code after a victim completes the flow. Patterns without an explicit protocol can match unintended protocols, and redirect URIs containing embedded credentials are accepted after user information is stripped for matching. The features are experimental and disabled by default; only deployments that enable them and configure custom wildcard-hostname or protocol-less patterns are affected. This issue is first fixed in prerelease version 0.29.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73563"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-38hq-7x33-php4</id>
    <title>GHSA-38hq-7x33-php4 — @backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass</title>
    <updated>2026-10-03T05:17:59.973222+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @backstage/plugin-auth-backend</p>
<p>### Impact
The allowlist matching used by the experimental dynamic client registration and client ID metadata document (CIMD) features in `@backstage/plugin-auth-backend` matched glob patterns against the full URL string. A * wildcard could therefore match across URL component boundaries: a pattern such as `https://*.example.com/callback`, intended to allow subdomains of a trusted host, would also match an attacker-controlled URL such as `https://attacker.example/x.example.com/callback`. This applies to `auth.experimentalDynamicClientRegistration.allowedRedirectUriPatterns` as well as the `allowedClientIdPatterns` and `allowedRedirectUriPatterns` options of `auth.experimentalClientIdMetadataDocuments`.</p>
<p>An attacker could use this to register an OAuth client whose redirect URI points to a host they control while still passing the allowlist, causing authorization codes to be delivered to the attacker when a victim completes an authorization flow. In addition, allowlist patterns without an explicit protocol could match URLs with any protocol, and redirect URIs containing embedded credentials (user:pass@host) were accepted after the credentials were stripped for matching.</p>
<p>The practical impact is limited. Both features are experimental and disabled by default, and the default allowlist patterns only reference fixed or loopback hosts and are not affected. Deployments are only impacted if they enable one of these features and configure custom allowlist patterns that contain a wild…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-38hq-7x33-php4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:65118</id>
    <title>RHSA-2026:65118 — Red Hat Security Advisory: Ansible plug-ins for Red Hat Developer Hub Product Release Update</title>
    <updated>2026-10-03T05:17:59.973266+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>multer: Multer: Denial of Service via deeply nested field names in multipart form data nanoid: nanoid: Denial of Service via infinite loop in random ID generation nanoid: nanoid: Denial of Service via negative size input in non-secure module functions axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter axios: axios: Denial of Service via object serialization bypass @backstage/plugin-auth-backend: Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass tar: node-tar: Denial of Service via crafted long-path tar archive dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:65118"/>
  </entry>
</feed>
