<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T11:53:50.725855+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-06479</id>
    <title>cnvd-2022-06479</title>
    <updated>2026-10-08T11:53:50.840909+00:00</updated>
    <content>cnvd-2022-06479</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-06479"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234496</id>
    <title>EUVD-2026-234496</title>
    <updated>2026-10-08T11:53:50.840950+00:00</updated>
    <content>EUVD-2026-234496</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21694</id>
    <title>fkie_cve-2022-21694</title>
    <updated>2026-10-08T11:53:50.840964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare allows to use a hardened CSP, which will block any scripts and external resources. It is not possible to configure this CSP for individual pages and therefore the security enhancement cannot be used for websites using javascript or external resources like fonts or images.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-21694"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h29c-wcm8-883h</id>
    <title>GHSA-h29c-wcm8-883h — Incorrect Permission Assignment for Critical Resource in OnionShare</title>
    <updated>2026-10-08T11:53:50.840995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: onionshare-cli</p>
<p>Between September 26, 2021 and October 8, 2021, [Radically Open Security](https://www.radicallyopensecurity.com/) conducted a penetration test of OnionShare 2.4, funded by the Open Technology Fund's [Red Team lab](https://www.opentech.fund/labs/red-team-lab/). This is an issue from that penetration test.</p>
<p>- Vulnerability ID: OTF-006
- Vulnerability type: Broken Website Hardening Control
- Threat level: Low</p>
<p>## Description:</p>
<p>The CSP can be turned on or off but not configured for the specific needs of the website.</p>
<p>## Technical description:</p>
<p>The website mode of the application allows to use a hardened CSP, which will block any scripts and external resources. It is not possible to configure this CSP for individual pages and therefore the security enhancement cannot be used for websites using javascript or external resources like fonts or images.</p>
<p>If CSP were configurable, the website creator could harden it accordingly to the needs of the application.</p>
<p>As this issue correlates with the Github issue for exposing the flask application directly (https://github.com/onionshare/ onionshare/issues/1389), it can be assumed that this can be solved by either changing to a well-known webserver, which supports this kind of configuration, or enhancing the status quo by making the CSP a configurable part of each website.</p>
<p>We believe that bundling the nginx or apache webserver would add complexity and dependencies to the application that could result in a larger attack surface - as these pack…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h29c-wcm8-883h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-21694</id>
    <title>gsd-2022-21694</title>
    <updated>2026-10-08T11:53:50.841041+00:00</updated>
    <content>gsd-2022-21694</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-21694"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11983-1</id>
    <title>openSUSE-SU-2024:11983-1 — python-onionshare-2.5-1.1 on GA media</title>
    <updated>2026-10-08T11:53:50.841054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-onionshare-2.5-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11983-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2022-45</id>
    <title>PYSEC-2022-45</title>
    <updated>2026-10-08T11:53:50.841074+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: onionshare-cli</p>
<p>OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare allows to use a hardened CSP, which will block any scripts and external resources. It is not possible to configure this CSP for individual pages and therefore the security enhancement cannot be used for websites using javascript or external resources like fonts or images.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2022-45"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21694</id>
    <title>UBUNTU-CVE-2022-21694</title>
    <updated>2026-10-08T11:53:50.841094+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: onionshare, Ubuntu:22.04:LTS: onionshare</p>
<p>OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare allows to use a hardened CSP, which will block any scripts and external resources. It is not possible to configure this CSP for individual pages and therefore the security enhancement cannot be used for websites using javascript or external resources like fonts or images.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21694"/>
  </entry>
</feed>
