<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T19:29:05.212264+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265764</id>
    <title>EUVD-2026-265764</title>
    <updated>2026-10-06T19:29:05.265739+00:00</updated>
    <content>EUVD-2026-265764</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22819</id>
    <title>fkie_cve-2026-22819</title>
    <updated>2026-10-06T19:29:05.265774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Outray openSource ngrok alternative. Prior to 0.1.5, this vulnerability allows a user i.e a free plan user to get more than the desired subdomains due to lack of db transaction lock mechanisms in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts. This vulnerability is fixed in 0.1.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22819"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-45hj-9x76-wp9g</id>
    <title>GHSA-45hj-9x76-wp9g — Outray has a Race Condition in the cli's webapp</title>
    <updated>2026-10-06T19:29:05.265803+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: outray</p>
<p>### Summary
This vulnerability allows a user i.e a free plan user to get more than the desired subdomains due to lack of db transaction lock mechanisms in `https://github.com/akinloluwami/outray/blob/main/apps/web/src/routes/api/%24orgSlug/subdomains/index.ts`</p>
<p>### Details
- The affected code-:</p>
<p>```ts
//Race condition
        const [subscription] = await db
          .select()
          .from(subscriptions)
          .where(eq(subscriptions.organizationId, organization.id));</p>
<p>const currentPlan = subscription?.plan || "free";
        const planLimits = getPlanLimits(currentPlan as any);
        const subdomainLimit = planLimits.maxSubdomains;</p>
<p>const existingSubdomains = await db
          .select()
          .from(subdomains)
          .where(eq(subdomains.organizationId, organization.id));</p>
<p>if (existingSubdomains.length &gt;= subdomainLimit) {
          return json(
            {
              error: `Subdomain limit reached. The ${currentPlan} plan allows ${subdomainLimit} subdomain${subdomainLimit &gt; 1 ? "s" : ""}.`,
            },
            { status: 403 },
          );
        }</p>
<p>const existing = await db
          .select()
          .from(subdomains)
          .where(eq(subdomains.subdomain, subdomain))
          .limit(1);</p>
<p>if (existing.length &gt; 0) {
          return json({ error: "Subdomain already taken" }, { status: 409 });
        }</p>
<p>const [newSubdomain] = await db
          .insert(subdomains)
          .values({…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-45hj-9x76-wp9g"/>
  </entry>
</feed>
