<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:20:09.432381+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15798</id>
    <title>bdu:2026-15798</title>
    <updated>2026-10-06T16:20:09.525316+00:00</updated>
    <content>bdu:2026-15798</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-379728</id>
    <title>EUVD-2026-379728</title>
    <updated>2026-10-06T16:20:09.525358+00:00</updated>
    <content>EUVD-2026-379728</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-379728"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-102991</id>
    <title>fkie_cve-2026-102991</title>
    <updated>2026-10-06T16:20:09.525373+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py validates them with os.path, which uses ntpath. A URI beginning with a drive designator causes ntpath to absorb the traversal segments before the leading dot-dot check, while posixpath resolution can escape the configured template directory. An application that passes attacker-controlled template names or include paths can disclose process-readable files on the same volume, and a targeted file containing Mako template syntax may also be parsed and executed as a template. Raw URL paths are generally normalized before reaching this form, but query strings, form or JSON bodies, route parameters, and dynamic include expressions can preserve it. This issue is fixed in version 1.4.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-102991"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5639-2j2p-m4mx</id>
    <title>GHSA-5639-2j2p-m4mx — Mako: Path traversal via drive-letter URI on Windows in TemplateLookup</title>
    <updated>2026-10-06T16:20:09.525405+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Mako</p>
<p>## Summary</p>
<p>On Windows, a `TemplateLookup` URI beginning with a drive designator (e.g. `C:/../../secret.txt` or `C:\..\..\secret.txt`) bypasses the directory traversal check in `Template.__init__`, allowing reads of files outside the configured template directory.</p>
<p>This is a third, independent instance of the root cause behind CVE-2026-41205 (the `//` prefix) and CVE-2026-44307 (the backslash form). Both of those fixes normalized a separator *spelling*. Neither addressed the other way `posixpath` and `ntpath` disagree: the drive designator. Both prior fixes remain effective on their own terms; this variant survives them for an independent reason.</p>
<p>## Details</p>
<p>The root cause is the same `posixpath` / `os.path` mismatch: resolution is done with `posixpath`, confinement is checked with `os.path`, which is `ntpath` on Windows.</p>
<p>```
# mako/lookup.py -- resolution
247:  srcfile = posixpath.normpath(posixpath.join(dir_, u))   # posixpath, always
248:  if os.path.isfile(srcfile):                             # ntpath on Windows</p>
<p># mako/template.py -- confinement
268:  u_norm = os.path.normpath(u_norm)                       # ntpath on Windows
269:  if u_norm.startswith(".."):                             # never true for a drive URI
```</p>
<p>`posixpath` has no concept of a drive, so it treats `C:` as an ordinary path component; the `..` segments pop `C:` and then escape the template root. `ntpath`, by contrast, splits the drive off and treats the remainder as rooted, discarding the `..` e…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5639-2j2p-m4mx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-102991</id>
    <title>msrc_CVE-2026-102991 — Mako: Path traversal via drive-letter URI on Windows in TemplateLookup</title>
    <updated>2026-10-06T16:20:09.525463+00:00</updated>
    <content>msrc_CVE-2026-102991</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-102991"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102991</id>
    <title>UBUNTU-CVE-2026-102991</title>
    <updated>2026-10-06T16:20:09.525480+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: mako, Ubuntu:Pro:18.04:LTS: mako, Ubuntu:Pro:20.04:LTS: mako, Ubuntu:22.04:LTS: mako, Ubuntu:24.04:LTS: mako, Ubuntu:26.04:LTS: mako</p>
<p>Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py validates them with os.path, which uses ntpath. A URI beginning with a drive designator causes ntpath to absorb the traversal segments before the leading dot-dot check, while posixpath resolution can escape the configured template directory. An application that passes attacker-controlled template names or include paths can disclose process-readable files on the same volume, and a targeted file containing Mako template syntax may also be parsed and executed as a template. Raw URL paths are generally normalized before reaching this form, but query strings, form or JSON bodies, route parameters, and dynamic include expressions can preserve it. This issue is fixed in version 1.4.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-102991"/>
  </entry>
</feed>
