<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T16:36:14.528150+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264139</id>
    <title>EUVD-2026-264139</title>
    <updated>2026-10-09T16:36:14.530720+00:00</updated>
    <content>EUVD-2026-264139</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264139"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68279</id>
    <title>fkie_cve-2025-68279</title>
    <updated>2026-10-09T16:36:14.530752+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g925-f788-4jh7</id>
    <title>GHSA-g925-f788-4jh7 — Weblate has an arbitrary file read via symbolic links</title>
    <updated>2026-10-09T16:36:14.530782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Weblate</p>
<p>### Impact
It was possible to read arbitrary files from the server file system using crafted symbolic links in the repository.</p>
<p>### Resources</p>
<p>Thanks to Jason Marcello for responsible disclosure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g925-f788-4jh7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2040</id>
    <title>PYSEC-2026-2040 — Weblate has an arbitrary file read via symbolic links</title>
    <updated>2026-10-09T16:36:14.530806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: weblate</p>
<p>### Impact
It was possible to read arbitrary files from the server file system using crafted symbolic links in the repository.</p>
<p>### Resources</p>
<p>Thanks to Jason Marcello for responsible disclosure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2040"/>
  </entry>
</feed>
