<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T05:48:25.793186+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-267791</id>
    <title>EUVD-2026-267791</title>
    <updated>2026-10-07T05:48:25.845517+00:00</updated>
    <content>EUVD-2026-267791</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-267791"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25598</id>
    <title>fkie_cve-2026-25598</title>
    <updated>2026-10-07T05:48:25.845555+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections to evade audit logging. Specifically, outbound traffic using the sendto, sendmsg, and sendmmsg socket system calls can bypass detection and logging when using egress-policy: audit. This vulnerability is fixed in 2.14.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25598"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cpmj-h4f6-r6pq</id>
    <title>GHSA-cpmj-h4f6-r6pq — Harden-Runner: Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Communit…</title>
    <updated>2026-10-07T05:48:25.845597+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> GitHub Actions: step-security/harden-runner</p>
<p>## Summary</p>
<p>A security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections to evade audit logging. Specifically, outbound traffic using the `sendto`, `sendmsg`, and `sendmmsg` socket system calls can bypass detection and logging when using `egress-policy: audit`.</p>
<p>**Note:** This vulnerability only affects audit mode. When using `egress-policy: block`, these connections are properly blocked. It requires the attacker to already have code execution capabilities within the GitHub Actions workflow (e.g., through workflow injection or compromised dependencies)</p>
<p>## Affected Versions</p>
<p>- Harden-Runner Community Tier: All versions prior to v2.14.2 
- Harden-Runner Enterprise Tier: **NOT AFFECTED**</p>
<p>## Severity</p>
<p>**Medium** - This vulnerability affects audit logging capabilities but requires the attacker to already have code execution within the workflow.</p>
<p>## Impact</p>
<p>When Harden-Runner is configured in audit mode (`egress-policy: audit`), attackers with the ability to execute arbitrary code in a workflow can: 
- Send outbound network traffic without generating audit logs 
- Bypass network monitoring for UDP-based communications</p>
<p>**Important:** This vulnerability requires the attacker to already have code execution capabilities within the GitHub Actions workflow (e.g., through workflow injection or compromised dependencies).</p>
<p>## Technical Details</p>
<p>The vulnerability stems from incomplete monitoring covera…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cpmj-h4f6-r6pq"/>
  </entry>
</feed>
