<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T06:10:33.722947+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318576</id>
    <title>EUVD-2026-318576</title>
    <updated>2026-10-06T06:10:33.727268+00:00</updated>
    <content>EUVD-2026-318576</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318576"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40893</id>
    <title>fkie_cve-2026-40893</title>
    <updated>2026-10-06T06:10:33.727305+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to move, rename, and change permissions for arbitrary files. This vulnerability is fixed in 8.31.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40893"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-62p3-hvxx-fxg4</id>
    <title>GHSA-62p3-hvxx-fxg4 — Gotenberg has an ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names that Allows Arbitrary File Rename…</title>
    <updated>2026-10-06T06:10:33.727338+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gotenberg/gotenberg/v8</p>
<p>### Summary</p>
<p>Gotenberg blocks certain ExifTool tag names like `FileName` and `Directory` to stop attackers from renaming or moving files on the server. But ExifTool allows a longer form of the same tag — `System:FileName` — which does the exact same thing. Gotenberg only checks if the tag is exactly `FileName`, so `System:FileName` slips right through and ExifTool happily renames the file. No login is needed. One HTTP request is enough.</p>
<p>This bypasses the fix from [GHSA-qmwh-9m9c-h36m](https://github.com/gotenberg/gotenberg/security/advisories/GHSA-qmwh-9m9c-h36m).</p>
<p>### Details</p>
<p>Think of it like a nightclub bouncer with a blocklist of banned names. The blocklist says "Block anyone named **John**." A person shows up and says "I'm **Mr. John**." The bouncer checks — "Mr. John" is not "John" — so he lets them in. But inside the club, everyone knows Mr. John IS John.</p>
<p>That's exactly what happens here:</p>
<p>**The blocklist** (`exiftool.go` line 275-280) blocks these tag names:</p>
<p>```
FileName
Directory
HardLink
SymLink
```</p>
<p>**The check** (`exiftool.go` line 295-301) compares what the user sent against this list:</p>
<p>```go
if strings.EqualFold(key, tag) {   // is "System:FileName" equal to "FileName"?
    delete(metadata, key)            // no — so it's NOT deleted
}
```</p>
<p>`System:FileName` is not equal to `FileName` (one is 16 characters, the other is 8), so it passes through.</p>
<p>**But ExifTool treats them as the same thing.** In ExifTool, `System:` is just a group prefix — like a folder nam…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-62p3-hvxx-fxg4"/>
  </entry>
</feed>
