<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:51:19.420874+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-travis-cve-2013-0263</id>
    <title>BREW-travis-CVE-2013-0263 — Rack arbitrary code execution via timing attack</title>
    <updated>2026-10-03T18:51:19.585598+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: travis</p>
<p>Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-travis-cve-2013-0263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-104566</id>
    <title>EUVD-2026-104566</title>
    <updated>2026-10-03T18:51:19.585659+00:00</updated>
    <content>EUVD-2026-104566</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-104566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2013-0263</id>
    <title>fkie_cve-2013-0263</title>
    <updated>2026-10-03T18:51:19.585675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2013-0263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xc85-32mf-xpv8</id>
    <title>GHSA-xc85-32mf-xpv8 — Rack arbitrary code execution via timing attack</title>
    <updated>2026-10-03T18:51:19.585699+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: rack</p>
<p>Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xc85-32mf-xpv8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2013-0263</id>
    <title>gsd-2013-0263</title>
    <updated>2026-10-03T18:51:19.585722+00:00</updated>
    <content>gsd-2013-0263</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2013-0263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10115-1</id>
    <title>openSUSE-SU-2024:10115-1 — ruby2.2-rubygem-rack-1_4-1.4.7-1.8 on GA media</title>
    <updated>2026-10-03T18:51:19.585734+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby2.2-rubygem-rack-1_4-1.4.7-1.8 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10115-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2013:0638</id>
    <title>RHSA-2013:0638 — Red Hat Security Advisory: Red Hat OpenShift Enterprise 1.1.2 update</title>
    <updated>2026-10-03T18:51:19.585751+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygem-rack: Path sanitization information disclosure rubygem-rack: Timing attack in cookie sessions jenkins: cross-site request forgery (CSRF) on Jenkins master jenkins: XSS jenkins: cross-site request forgery (CSRF) protection mechanism bypass jenkins: cause building jobs without direct access jenkins: denial of service attack by feeding a carefully crafted payload to Jenkins</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2013:0638"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-0263</id>
    <title>UBUNTU-CVE-2013-0263</title>
    <updated>2026-10-03T18:51:19.585773+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: ruby-rack</p>
<p>Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-0263"/>
  </entry>
</feed>
