<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T16:09:04.951481+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318138</id>
    <title>EUVD-2026-318138</title>
    <updated>2026-10-07T16:09:04.998395+00:00</updated>
    <content>EUVD-2026-318138</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42180</id>
    <title>fkie_cve-2026-42180</title>
    <updated>2026-10-07T16:09:04.998435+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-privileged user to create a link post through POST /api/v3/post. When a post is created in a public community, the backend asynchronously sends a Webmention to the attacker-controlled link target. The submitted URL is checked for syntax and scheme, but the audited code path does not reject loopback, private, or link-local destinations before the Webmention request is issued. This lets a normal user trigger server-side HTTP requests toward internal services. This issue has been patched in version 0.19.18.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3jvj-v6w2-h948</id>
    <title>GHSA-3jvj-v6w2-h948 — Lemmy has SSRF in /api/v3/post via Webmention dispatch</title>
    <updated>2026-10-07T16:09:04.998470+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: lemmy_api_common</p>
<p>### Summary
Lemmy allows an authenticated low-privileged user to create a link post through `POST /api/v3/post`. When a post is created in a public community, the backend asynchronously sends a Webmention to the attacker-controlled link target.</p>
<p>The submitted URL is checked for syntax and scheme, but the audited code path does not reject loopback, private, or link-local destinations before the Webmention request is issued. This lets a normal user trigger server-side HTTP requests toward internal services.</p>
<p>### Details
The entry point is the normal post creation API. The user-controlled `url` field is accepted, normalized with `diesel_url_create()`, and only validated with `is_valid_url()`. That validation allows `http` and `https` but does not implement internal address rejection.</p>
<p>The post creation flow then schedules Webmention delivery for public communities. This creates a direct source-to-sink path from an externally supplied post URL to a server-side outbound HTTP request.</p>
<p>Core vulnerable code path:</p>
<p>```rust
// crates/api_crud/src/post/create.rs
let url = diesel_url_create(data.url.as_deref())?;
if let Some(url) = &amp;url {
  is_url_blocked(url, &amp;url_blocklist)?;
  is_valid_url(url)?;
}
```</p>
<p>```rust
// crates/utils/src/utils/validation.rs
pub fn is_valid_url(url: &amp;Url) -&gt; LemmyResult&lt;()&gt; {
  let is_valid = ["http", "https", "magnet"].contains(&amp;url.scheme());
  if !is_valid {
    Err(LemmyErrorType::InvalidUrl)?
  }
  Ok(())
}
```</p>
<p>```rust
// crates/api_crud/src/post/crea…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3jvj-v6w2-h948"/>
  </entry>
</feed>
