<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T22:50:22.805139+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277221</id>
    <title>EUVD-2026-277221</title>
    <updated>2026-10-05T22:50:22.850999+00:00</updated>
    <content>EUVD-2026-277221</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33679</id>
    <title>fkie_cve-2026-33679</title>
    <updated>2026-10-05T22:50:22.851033+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client{}` with no SSRF protection when downloading user avatar images from the OpenID Connect `picture` claim URL. An attacker who controls their OIDC profile picture URL can force the Vikunja server to make HTTP GET requests to arbitrary internal or cloud metadata endpoints. This bypasses the SSRF protections that are correctly applied to the webhook system. Version 2.2.1 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g9xj-752q-xh63</id>
    <title>GHSA-g9xj-752q-xh63 — Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download</title>
    <updated>2026-10-05T22:50:22.851067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.vikunja.io/api</p>
<p>## Summary</p>
<p>The `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client{}` with no SSRF protection when downloading user avatar images from the OpenID Connect `picture` claim URL. An attacker who controls their OIDC profile picture URL can force the Vikunja server to make HTTP GET requests to arbitrary internal or cloud metadata endpoints. This bypasses the SSRF protections that are correctly applied to the webhook system.</p>
<p>## Details</p>
<p>When a user authenticates via OpenID Connect, Vikunja extracts the `picture` claim from the ID token or UserInfo endpoint and passes it to `syncUserAvatarFromOpenID`, which calls `utils.DownloadImage` with the attacker-controlled URL:</p>
<p>**Claim extraction** (`pkg/modules/auth/openid/openid.go:70-78`):
```go
type claims struct {
	Email              string                   `json:"email"`
	Name               string                   `json:"name"`
	PreferredUsername   string                   `json:"preferred_username"`
	Nickname           string                   `json:"nickname"`
	VikunjaGroups      []map[string]interface{} `json:"vikunja_groups"`
	Picture            string                   `json:"picture"`
	// ...
}
```</p>
<p>**Avatar sync trigger** (`pkg/modules/auth/openid/openid.go:348-352`):
```go
// Try sync avatar if available
err = syncUserAvatarFromOpenID(s, u, cl.Picture)
if err != nil {
	log.Errorf("Error syncing avatar for user %s: %v", u.Username, err)
}
```</p>
<p>**Vulnerable download** (`pkg/utils/avatar.go:94-115`):
```…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g9xj-752q-xh63"/>
  </entry>
</feed>
