<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T10:42:17.226107+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-274831</id>
    <title>EUVD-2026-274831</title>
    <updated>2026-10-07T10:42:17.271569+00:00</updated>
    <content>EUVD-2026-274831</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-274831"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28789</id>
    <title>fkie_cve-2026-28789</title>
    <updated>2026-10-07T10:42:17.271613+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2 login flow. Concurrent requests to /oauth/login can trigger unsynchronized access to a shared registeredStates map, causing a Go runtime panic (fatal error: concurrent map writes) and process termination. This allows remote attackers to crash the service when OAuth2 is enabled. This issue has been patched in version 3000.10.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-28789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-45m3-398w-m2m9</id>
    <title>GHSA-45m3-398w-m2m9 — OliveTin has unauthenticated DoS via concurrent map writes in OAuth2 state handling</title>
    <updated>2026-10-07T10:42:17.271680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/OliveTin/OliveTin</p>
<p>### Summary
An unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2 login flow. Concurrent requests to /oauth/login can trigger unsynchronized access to a shared registeredStates map, causing a Go runtime panic (fatal
  error: concurrent map writes) and process termination. This allows remote attackers to crash the service when OAuth2 is enabled.</p>
<p>### Details
The OAuth2 handler stores per-login state in a shared map without synchronization:</p>
<p>- service/internal/auth/otoauth2/restapi_auth_oauth2.go:24
    registeredStates map[string]*oauth2State
  - Unlocked write in login handler: .../restapi_auth_oauth2.go:141
  - Unlocked read in callback check: .../restapi_auth_oauth2.go:174
  - Unlocked writes in callback flow: .../restapi_auth_oauth2.go:284-285
  - Unlocked read in auth chain check: .../restapi_auth_oauth2.go:376</p>
<p>These paths are network reachable via publicly registered routes:
```bash
  - service/internal/httpservers/frontend.go:71 → /oauth/login
  - service/internal/httpservers/frontend.go:72 → /oauth/callback
```
  Because Go HTTP handlers run concurrently, high parallel traffic to /oauth/login causes concurrent map access and runtime panic.</p>
<p>Tested on:</p>
<p>- Container image: ghcr.io/olivetin/olivetin:3000.10.0
  - Source also contains same pattern at commit/tag eb42029b5d0c0633551621288180dd4566b913f7 (3000.10.1)</p>
<p>### PoC
1. Start OliveTin with OAuth2 provider configured (example github), exposing port 1337.
  2. Confirm baseline:
```ba…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-45m3-398w-m2m9"/>
  </entry>
</feed>
