<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T19:35:18.945551+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292521</id>
    <title>EUVD-2026-292521</title>
    <updated>2026-10-08T19:35:18.948152+00:00</updated>
    <content>EUVD-2026-292521</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39413</id>
    <title>fkie_cve-2026-39413</title>
    <updated>2026-10-08T19:35:18.948184+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since the jwt.decode() call does not explicitly deny the 'none' algorithm, a crafted token without a signature will be accepted as valid, leading to unauthorized access. This vulnerability is fixed in 1.4.14.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39413"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8ffj-4hx4-9pgf</id>
    <title>GHSA-8ffj-4hx4-9pgf — lightrag-hku: JWT Algorithm Confusion Vulnerability</title>
    <updated>2026-10-08T19:35:18.948217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lightrag-hku</p>
<p>## Summary
The LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since the `jwt.decode()` call does not explicitly deny the 'none' algorithm, a crafted token without a signature will be accepted as valid, leading to unauthorized access.</p>
<p>## Details
In `lightrag/api/auth.py` at line 128, the `validate_token` method calls:</p>
<p>```python
payload = jwt.decode(token, self.secret, algorithms=[self.algorithm])
```</p>
<p>This allows any algorithm listed in the token's header to be processed, including 'none'. The code does not explicitly specify that 'none' is not allowed, making it possible for an attacker to bypass authentication.</p>
<p>## PoC
An attacker can generate a JWT with the following structure:</p>
<p>```json
{
  "header": {
    "alg": "none",
    "typ": "JWT"
  },
  "payload": {
    "sub": "admin",
    "exp": 1700000000,
    "role": "admin"
  }
}
```</p>
<p>Then send a request like:</p>
<p>```bash
curl -H "Authorization: Bearer eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJhZG1pbiIsImV4cCI6MTcwMDAwMDAwMCwicm9sZSI6ImFkbWluIn0." http://localhost:8000/api/protected-endpoint
```</p>
<p>## Impact
An attacker can impersonate any user, including administrators, by forging a JWT with 'alg': 'none', gaining full access to protected resources without needing valid credentials.</p>
<p>## Recommended Fix
Explicitly specify allowed algorithms and exclude 'none'. Modify the `validate_token` method to:</p>
<p>```python
allowed_algorithms =…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8ffj-4hx4-9pgf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2592</id>
    <title>PYSEC-2026-2592 — lightrag-hku: JWT Algorithm Confusion Vulnerability</title>
    <updated>2026-10-08T19:35:18.948265+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lightrag-hku</p>
<p>## Summary
The LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since the `jwt.decode()` call does not explicitly deny the 'none' algorithm, a crafted token without a signature will be accepted as valid, leading to unauthorized access.</p>
<p>## Details
In `lightrag/api/auth.py` at line 128, the `validate_token` method calls:</p>
<p>```python
payload = jwt.decode(token, self.secret, algorithms=[self.algorithm])
```</p>
<p>This allows any algorithm listed in the token's header to be processed, including 'none'. The code does not explicitly specify that 'none' is not allowed, making it possible for an attacker to bypass authentication.</p>
<p>## PoC
An attacker can generate a JWT with the following structure:</p>
<p>```json
{
  "header": {
    "alg": "none",
    "typ": "JWT"
  },
  "payload": {
    "sub": "admin",
    "exp": 1700000000,
    "role": "admin"
  }
}
```</p>
<p>Then send a request like:</p>
<p>```bash
curl -H "Authorization: Bearer eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJhZG1pbiIsImV4cCI6MTcwMDAwMDAwMCwicm9sZSI6ImFkbWluIn0." http://localhost:8000/api/protected-endpoint
```</p>
<p>## Impact
An attacker can impersonate any user, including administrators, by forging a JWT with 'alg': 'none', gaining full access to protected resources without needing valid credentials.</p>
<p>## Recommended Fix
Explicitly specify allowed algorithms and exclude 'none'. Modify the `validate_token` method to:</p>
<p>```python
allowed_algorithms =…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2592"/>
  </entry>
</feed>
