<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T17:37:21.108414+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275136</id>
    <title>EUVD-2026-275136</title>
    <updated>2026-10-06T17:37:21.155393+00:00</updated>
    <content>EUVD-2026-275136</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30223</id>
    <title>fkie_cve-2026-30223</title>
    <updated>2026-10-06T17:37:21.155429+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKeyPath" (local RSA public key) or "authJwtHmacSecret" (HMAC secret), the configured audience value (authJwtAud) is not enforced during token parsing. As a result, validly signed JWT tokens with an incorrect aud claim are accepted for authentication. This allows authentication using tokens intended for a different audience/service. This issue has been patched in version 3000.11.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-30223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g962-2j28-3cg9</id>
    <title>GHSA-g962-2j28-3cg9 — OliveTin has JWT Audience Validation Bypass in Local Key and HMAC Modes</title>
    <updated>2026-10-06T17:37:21.155466+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/OliveTin/OliveTin</p>
<p>### Summary</p>
<p>When JWT authentication is configured using either:</p>
<p>- `authJwtPubKeyPath` (local RSA public key), or
- `authJwtHmacSecret` (HMAC secret),</p>
<p>the configured audience value (`authJwtAud`) is not enforced during token parsing.
As a result, validly signed JWT tokens with an incorrect `aud` claim are accepted for authentication.
This allows authentication using tokens intended for a different audience/service.</p>
<p>### Details</p>
<p>**Affected Code**</p>
<p>File: `jwt.go`
Lines: 51–59, 144–157, 161–168</p>
<p>**Current Behavior**</p>
<p>Remote JWKS Mode (Correct):
```go
return jwt.Parse(jwtToken, jwksVerifier.Keyfunc, jwt.WithAudience(cfg.AuthJwtAud))
```
Audience validation is enforced.</p>
<p>Local Public Key Mode (Vulnerable):
```go
return jwt.Parse(jwtString, func(token *jwt.Token) (interface{}, error) { ... })
```
No `jwt.WithAudience()` option is provided.</p>
<p>HMAC Mode (Vulnerable):
```go
return jwt.Parse(jwtString, func(token *jwt.Token) (interface{}, error) { ... })
```
No `jwt.WithAudience()` option is provided.</p>
<p>**Why This Is Vulnerable:** `authJwtAud` is ignored for `authJwtPubKeyPath` and `authJwtHmacSecret` modes, so wrong-audience tokens are accepted.</p>
<p>### PoC</p>
<p>1. **Configure OliveTin**</p>
<p>Use a minimal config with JWT local key authentication:
   ```yaml
   authJwtPubKeyPath: ./public.pem
   authJwtHeader: Authorization
   authJwtClaimUsername: sub
   authJwtAud: expected-audience</p>
<p>authRequireGuestsToLogin: true
   ```</p>
<p>2. **Generate a Wrong-Audience Token**
   ```python
   python3 -…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g962-2j28-3cg9"/>
  </entry>
</feed>
