<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T03:40:51.273734+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275126</id>
    <title>EUVD-2026-275126</title>
    <updated>2026-10-07T03:40:51.277288+00:00</updated>
    <content>EUVD-2026-275126</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275126"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30242</id>
    <title>fkie_cve-2026-30242</title>
    <updated>2026-10-07T03:40:51.277329+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only checks ip.is_loopback, allowing attackers with workspace ADMIN role to create webhooks pointing to private/internal network addresses (10.x.x.x, 172.16.x.x, 192.168.x.x, 169.254.169.254, etc.). When webhook events fire, the server makes requests to these internal addresses and stores the response — enabling SSRF with full response read-back. This issue has been patched in version 1.2.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-30242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fpx8-73gf-7x73</id>
    <title>GHSA-fpx8-73gf-7x73 — Plane has SSRF via Incomplete IP Validation in Webhook URL Serializer</title>
    <updated>2026-10-07T03:40:51.277389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: plane</p>
<p>### Summary
The webhook URL validation in `plane/app/serializers/webhook.py` only checks `ip.is_loopback`, allowing attackers with workspace ADMIN role to create webhooks pointing to private/internal network addresses (`10.x.x.x`, `172.16.x.x`, `192.168.x.x`, `169.254.169.254`, etc.). When webhook events fire, the server makes requests to these internal addresses and stores the response — enabling SSRF with full response read-back.</p>
<p>### Impact
- **Cloud metadata exfiltration**: Access AWS/GCP/Azure instance metadata (IAM credentials, tokens)
- **Internal service scanning**: Probe internal network services not exposed to the internet
- **Data exfiltration via response logs**: Full response body from internal services is stored and returned to the attacker through the webhook logs API
- Bypass vectors: `10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`, `169.254.0.0/16`, `0.0.0.0`, `::ffff:` mapped addresses</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fpx8-73gf-7x73"/>
  </entry>
</feed>
