<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T13:11:02.683023+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265716</id>
    <title>EUVD-2026-265716</title>
    <updated>2026-10-07T13:11:02.740550+00:00</updated>
    <content>EUVD-2026-265716</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265716"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22820</id>
    <title>fkie_cve-2026-22820</title>
    <updated>2026-10-07T13:11:02.740609+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the set number of active tunnels in their subscription plan. This vulnerability is fixed in 0.1.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22820"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3pqc-836w-jgr7</id>
    <title>GHSA-3pqc-836w-jgr7 — Outray cli is vulnerable to race conditions in tunnels creation</title>
    <updated>2026-10-07T13:11:02.740660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: outray</p>
<p>### Summary</p>
<p>A TOCTOU race condition vulnerability allows a user to exceed the set number of active tunnels in their subscription plan.</p>
<p>### Details</p>
<p>Affected conponent: `apps/web/src/routes/api/tunnel/register.ts`
- `/tunnel/register` endpoint code-:</p>
<p>```ts
// Check if tunnel already exists in database
          const [existingTunnel] = await db
            .select()
            .from(tunnels)
            .where(eq(tunnels.url, tunnelUrl));</p>
<p>const isReconnection = !!existingTunnel;</p>
<p>console.log(
            `[TUNNEL LIMIT CHECK] Org: ${organizationId}, Tunnel: ${tunnelId}`,
          );
          console.log(
            `[TUNNEL LIMIT CHECK] Is Reconnection: ${isReconnection}`,
          );
          console.log(
            `[TUNNEL LIMIT CHECK] Plan: ${currentPlan}, Limit: ${tunnelLimit}`,
          );</p>
<p>// Check limits only for NEW tunnels (not reconnections)
          if (!isReconnection) {
            // Count active tunnels from Redis SET
            const activeCount = await redis.scard(setKey);
            console.log(
              `[TUNNEL LIMIT CHECK] Active count in Redis: ${activeCount}`,
            );</p>
<p>// The current tunnel is NOT yet in the online_tunnels set (added after successful registration)
            // So we check if activeCount &gt;= limit (not &gt;)
            if (activeCount &gt;= tunnelLimit) {
              console.log(
                `[TUNNEL LIMIT CHECK] REJECTED - ${activeCount} &gt;= ${tunnelLimit}`,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3pqc-836w-jgr7"/>
  </entry>
</feed>
