<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:51:54.364780+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-375235</id>
    <title>EUVD-2026-375235</title>
    <updated>2026-10-04T06:51:54.539601+00:00</updated>
    <content>EUVD-2026-375235</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-375235"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84721</id>
    <title>fkie_cve-2026-84721</title>
    <updated>2026-10-04T06:51:54.539671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A server-side request forgery flaw was found in the Ansible Automation Platform
automation-controller email notification backend. The email backend passes the user-supplied SMTP
host and port from a notification template directly to the SMTP client without validating that
the target is not an internal, loopback, link-local, or reserved address. An authenticated user
with organization notification-admin permission can create or modify an email notification
template pointing at an arbitrary internal address, trigger a test, and have the controller task
process open a raw TCP connection to that address. The resulting connection error is reflected
back through the notification record, providing a three-state internal port-scan oracle (open,
closed, filtered) over the control-plane's cluster network, including the in-cluster Kubernetes
API. When a shared organization template holds a stored SMTP password, redirecting the host can
also cause that credential to be transmitted to an attacker-controlled server.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-84721"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pm79-7whg-hpfr</id>
    <title>GHSA-pm79-7whg-hpfr</title>
    <updated>2026-10-04T06:51:54.539744+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A server-side request forgery flaw was found in the Ansible Automation Platform
automation-controller email notification backend. The email backend passes the user-supplied SMTP
host and port from a notification template directly to the SMTP client without validating that
the target is not an internal, loopback, link-local, or reserved address. An authenticated user
with organization notification-admin permission can create or modify an email notification
template pointing at an arbitrary internal address, trigger a test, and have the controller task
process open a raw TCP connection to that address. The resulting connection error is reflected
back through the notification record, providing a three-state internal port-scan oracle (open,
closed, filtered) over the control-plane's cluster network, including the in-cluster Kubernetes
API. When a shared organization template holds a stored SMTP password, redirecting the host can
also cause that credential to be transmitted to an attacker-controlled server.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pm79-7whg-hpfr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71177</id>
    <title>RHSA-2026:71177 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update</title>
    <updated>2026-10-04T06:51:54.539769+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing sqlparse: sqlparse: Denial of Service via inefficient SQL parsing automation-controller: automation-controller-container: automation-controller: Named-URL 404 body oracle enables cross-tenant resource name enumeration automation-controller: automation-controller-container: automation-controller: JobJobEventsChildrenSummary               RBAC bypass exposes cross-tenant job event tree structure automation-controller: automation-controller-container: automation-controller: Any authenticated user reads Red Hat subscription/license details via /config/ automation-controller: automation-controller-container: automation-controller: Verbose internal exception               disclosure via HostList bare-Exception handler automation-controller: automation-controller-container: automation-controller: CUSTOM_VENV_PATH setting provides filesystem path-existence oracle on co…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</id>
    <title>WID-SEC-W-2026-3555 — Red Hat Ansible Automation Platform (automation-controller): Mehrere Schwachstellen</title>
    <updated>2026-10-04T06:51:54.539900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555"/>
  </entry>
</feed>
