<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:48:01.165112+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-13686</id>
    <title>bdu:2026-13686</title>
    <updated>2026-10-03T12:48:01.228802+00:00</updated>
    <content>bdu:2026-13686</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-13686"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362075</id>
    <title>EUVD-2026-362075</title>
    <updated>2026-10-03T12:48:01.228838+00:00</updated>
    <content>EUVD-2026-362075</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362075"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-82659</id>
    <title>fkie_cve-2026-82659</title>
    <updated>2026-10-03T12:48:01.228852+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-82659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p6gq-j5cr-w38f</id>
    <title>GHSA-p6gq-j5cr-w38f — Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full…</title>
    <updated>2026-10-03T12:48:01.228883+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: nodemailer</p>
<p># Message-level `raw` option bypasses `disableFileAccess` / `disableUrlAccess`, enabling arbitrary file read and full-response SSRF in the sent message</p>
<p>- **Target:** nodemailer/nodemailer, npm `nodemailer` **v9.0.0** (HEAD `4e58450eb490e5097a74b2b2cce35a8d9e21856e`)
- **Verdict:** CONFIRMED (local PoC, no network)</p>
<p>## Summary</p>
<p>Nodemailer exposes `disableFileAccess` and `disableUrlAccess` so an application that passes
**untrusted** message data to the library can forbid that data from reading local files or
fetching URLs. Every attachment, alternative, `html`/`text`/`watchHtml`/`amp` and `icalEvent`
content node honors these flags. **The message-level `raw` option does not.**</p>
<p>`MailComposer.compile()` builds the root MIME node for a `raw` message **without** threading the
two flags, so a `raw: { path: '/etc/passwd' }` or `raw: { href: 'http://169.254.169.254/…' }`
message is read / fetched anyway, and the file or HTTP-response bytes become the **actual
message that is sent** by every transport (SMTP, SES, sendmail, stream, JSON). An actor whose
input the application intended to sandbox therefore obtains arbitrary local-file disclosure and
a full-response SSRF primitive, delivered to a recipient the same actor can choose.</p>
<p>This is the same vulnerability class as the already-published jsonTransport advisory
**GHSA-wqvq-jvpq-h66f**, but a **distinct code path** (`raw` root node, not `normalize()`), and
strictly higher impact: the jsonTransport bug only affected the locally-retu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p6gq-j5cr-w38f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82659</id>
    <title>UBUNTU-CVE-2026-82659</title>
    <updated>2026-10-03T12:48:01.228967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-nodemailer, Ubuntu:22.04:LTS: node-nodemailer, Ubuntu:24.04:LTS: node-nodemailer, Ubuntu:26.04:LTS: node-nodemailer</p>
<p>nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgoing message to attacker-controlled recipients.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82659"/>
  </entry>
</feed>
