<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T08:26:09.550754+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-52600</id>
    <title>EUVD-2026-52600</title>
    <updated>2026-10-09T08:26:09.616144+00:00</updated>
    <content>EUVD-2026-52600</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-52600"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-9153</id>
    <title>fkie_cve-2019-9153</title>
    <updated>2026-10-09T08:26:09.616186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper Verification of a Cryptographic Signature in OpenPGP.js &lt;=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-9153"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qwqc-28w3-fww6</id>
    <title>GHSA-qwqc-28w3-fww6 — Message Signature Bypass in openpgp</title>
    <updated>2026-10-09T08:26:09.616221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openpgp</p>
<p>Versions of `openpgp` prior to 4.2.0 are vulnerable to Message Signature Bypass. The package fails to verify that a message signature is of type `text`. This allows an attacker to to construct a message with a signature type that only verifies subpackets without additional input (such as `standalone` or `timestamp`). For example, an attacker that captures a `standalone` signature packet from a victim can construct arbitrary signed messages that would be verified correctly.</p>
<p>## Recommendation</p>
<p>Upgrade to version 4.2.0 or later.
If you are upgrading from a version &lt;4.0.0 it is highly recommended to read the `High-Level API Changes` section of the `openpgp` 4.0.0 release: https://github.com/openpgpjs/openpgpjs/releases/tag/v4.0.0</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qwqc-28w3-fww6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-9153</id>
    <title>gsd-2019-9153</title>
    <updated>2026-10-09T08:26:09.616253+00:00</updated>
    <content>gsd-2019-9153</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-9153"/>
  </entry>
</feed>
