<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T01:43:07.903826+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261762</id>
    <title>EUVD-2026-261762</title>
    <updated>2026-10-07T01:43:07.974949+00:00</updated>
    <content>EUVD-2026-261762</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-65109</id>
    <title>fkie_cve-2025-65109</title>
    <updated>2026-10-07T01:43:07.974992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access to. This issue has been patched in Minder Helm version 0.20250203.3849+ref.fdc94f0 and Minder Go version 0.0.84.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-65109"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6xvf-4vh9-mw47</id>
    <title>GHSA-6xvf-4vh9-mw47 — Minder does not sandbox http.send in Rego programs</title>
    <updated>2026-10-07T01:43:07.975028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/mindersec/minder</p>
<p>### Impact</p>
<p>Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access to (for example, if the Minder server is behind a firewall or other network partition).</p>
<p>### Patches</p>
<p>https://github.com/mindersec/minder/commit/f770400923984649a287d7215410ef108e845af8</p>
<p>### Workarounds</p>
<p>Users should avoid deploying Minder with access to sensitive resources.  Unfortunately, this could include access to systems like OpenFGA or Keycloak, depending on the deployment configuration.</p>
<p>### References</p>
<p>Sample ruletype:</p>
<p>```yaml
version: v1
type: rule-type
name: test-http-send
display_name: Test that we can call http.send
short_failure_message: Failed http.send
severity:
  value: medium
context:
  provider: github
description: |
  ...
guidance: |
  ....
def:
  in_entity: repository
  rule_schema:
    type: object
    properties: {}
  ingest:
    type: git
    git: {}
  eval:
    type: rego
    violation_format: text
    rego:
      type: constraints
      def: |
        package minder</p>
<p>import rego.v1</p>
<p>violations contains {"msg": "Check-execution"}</p>
<p>resp := http.send({
          "method": "GET",
          "url": "http://openfga:8080/",
          "raise_error": false,
        })</p>
<p>violations contains {"msg": sprintf("Response: %s", [resp.status])}</p>
<p>details := sprintf("High score: %s", [resp.body.summary])</p>
<p>violations contains {"msg": sprintf("Response body: %s", [resp.body]) }…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6xvf-4vh9-mw47"/>
  </entry>
</feed>
