<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T08:44:49.766847+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290514</id>
    <title>EUVD-2026-290514</title>
    <updated>2026-10-06T08:44:49.826185+00:00</updated>
    <content>EUVD-2026-290514</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39429</id>
    <title>fkie_cve-2026-39429</title>
    <updated>2026-10-06T08:44:49.826223+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can access the root shard to read and write to the cache server. This vulnerability is fixed in 0.30.3 and 0.29.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39429"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3j3q-wp9x-585p</id>
    <title>GHSA-3j3q-wp9x-585p — kcp's cache server is accessible without authentication or authorization checks</title>
    <updated>2026-10-06T08:44:49.826257+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/kcp-dev/kcp</p>
<p>### Summary</p>
<p>The cache server is directly exposed by the root shard and has no authentication or authorization in place.
This allows anyone who can access the root shard to read and write to the cache server.</p>
<p>### Details</p>
<p>The cache server is routed in the pre-mux chain in the shard code. 
The preHandlerChainMux is handled before any authn/authz in the cache server: 
https://github.com/kcp-dev/kcp/blob/aaf93d59cbcd0cefb70d94bd8959ce390547c4a2/pkg/server/config.go#L514-L518</p>
<p>This results in the cache server being proxied before any authn/authz in the handler chain takes place.</p>
<p>### Attack Vectors</p>
<p>#### 1. Unauthenticated Read Access (Primary)
An attacker can read all replicated resources from the cache without any credentials. This exposes:</p>
<p>| Category | Resources | Severity | Reason |
|---|---|---|---|
| RBAC | clusterroles, clusterrolebindings (filtered by annotation) | High | Only subset with `internal.kcp.io/replicate` annotation: access rules, APIExport bind/content rules, WorkspaceType use rules. Reveals permission structure for API access and tenancy. Roles/RoleBindings NOT replicated. |
| Infrastructure | logicalclusters, shards | High | Reveals full cluster topology and shard configuration |
| API surface | apiexports, apiexportendpointslices, apiresourceschemas | High | Reveals all exported APIs and their network endpoints |
| Admission control | mutatingwebhookconfigurations, validatingwebhookconfigurations, validatingadmissionpolicies | High | Reveals admission po…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3j3q-wp9x-585p"/>
  </entry>
</feed>
