<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:51:19.155706+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-21728</id>
    <title>CVE-2026-21728 — Tempo query limit results in unbounded memory allocation</title>
    <updated>2026-10-04T21:51:19.285341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Grafana Tempo, Grafana Enterprise Traces (GET), Red Hat Multicluster Global Hub 1.3.4, Red Hat Multicluster Global Hub 1.4.5, Red Hat Multicluster Global Hub 1.6.5, Red Hat Multicluster Global Hub 1.7.0, Red Hat multicluster global hub 1.5.3, Red Hat Logging Subsystem for Red Hat OpenShift, Red Hat Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2 and 6 more</p>
<p>Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.</p>
<p>Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-21728"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r277-6w6q-xmqw</id>
    <title>GHSA-r277-6w6q-xmqw — kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default</title>
    <updated>2026-10-04T21:51:19.285430+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/getkin/kin-openapi</p>
<p>### Summary
`ValidationHandler.Load()` in `getkin/kin-openapi` silently replaces a nil `AuthenticationFunc` with `NoopAuthenticationFunc`, which always returns `nil` without performing any credential check. Because this substitution happens unconditionally when the caller omits the field, every OpenAPI `security` requirement declared in the spec is silently satisfied for unauthenticated requests. An unauthenticated remote attacker can reach handlers for routes whose OpenAPI operation requires an API key, OAuth token, or any other security scheme if the application relies on `ValidationHandler` as its enforcement middleware.</p>
<p>### Details
`ValidationHandler` is an HTTP middleware exported by `openapi3filter` that validates incoming requests and responses against a loaded OpenAPI specification. Its `Load()` method initialises default fields before the handler begins serving:</p>
<p>```go
// openapi3filter/validation_handler.go:47-49
if h.AuthenticationFunc == nil {
    h.AuthenticationFunc = NoopAuthenticationFunc
}
```</p>
<p>`NoopAuthenticationFunc` is defined as:</p>
<p>```go
// openapi3filter/validation_handler.go:17-18
func NoopAuthenticationFunc(context.Context, *AuthenticationInput) error { return nil }
```</p>
<p>It always returns `nil`, meaning every security scheme check it handles is automatically approved.</p>
<p>When a request arrives, `ServeHTTP` → `before` → `validateRequest` assembles a `RequestValidationInput` with the current `AuthenticationFunc` (now the no-op) injected into `Options`:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r277-6w6q-xmqw"/>
  </entry>
</feed>
