<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T15:53:26.587673+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-247800</id>
    <title>EUVD-2026-247800</title>
    <updated>2026-10-06T15:53:26.645639+00:00</updated>
    <content>EUVD-2026-247800</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-247800"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54066</id>
    <title>fkie_cve-2025-54066</title>
    <updated>2026-10-06T15:53:26.645677+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>DiracX-Web is a web application that provides an interface to interact with the DiracX services. Prior to version 0.1.0-a8, an attacker can forge a request that they can pass to redirect an authenticated user to another arbitrary website. In the login page, DiracX-Web has a `redirect` field which is the location where the server will redirect the user. This URI is not verified, and can be an arbitrary URI. Paired with a parameter pollution, an attacker can hide their malicious URI. This could be used for phishing, and extract new data (such as redirecting to a new "log in" page, and asking another time credentials). Version 0.1.0-a8 fixes this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-54066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hfj7-542q-8fvv</id>
    <title>GHSA-hfj7-542q-8fvv — DiracX-Web is vulnerable to attack through an Open Redirect on its login page</title>
    <updated>2026-10-06T15:53:26.645753+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @dirac-grid/diracx-web-components</p>
<p>### Summary</p>
<p>An attacker can forge a request to redirect an authenticated user to any arbitrary website.</p>
<p>### Details</p>
<p>On the login page, we have a `redirect` field which is the location where the server will redirect the user. This URI is not verified, and can be an arbitrary URI.</p>
<p>Paired with a parameter pollution, we can hide our malicious URI (ex: `https://dns.com/?param1=im_hidden_if_theres_lot_of_args?param1=bbb`).</p>
<p>### PoC</p>
<p>https://diracx-cert.app.cern.ch/auth?redirect=https://ipcim.com/en/where/?dsdsd=qsqsfsjfnsfniizaeiaapzqlalkqkaizqqijsjaopmqmxna?redirect=https://diracx-cert-app.cern.ch/auth</p>
<p>This POC can leak user's position.</p>
<p>### Impact</p>
<p>This could be used for phishing and extracting new data (such as redirecting to a new "log in" page, and asking users to reenter credentials).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hfj7-542q-8fvv"/>
  </entry>
</feed>
