<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T09:29:24.419520+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322086</id>
    <title>EUVD-2026-322086</title>
    <updated>2026-10-08T09:29:24.471547+00:00</updated>
    <content>EUVD-2026-322086</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42184</id>
    <title>fkie_cve-2026-42184</title>
    <updated>2026-10-08T09:29:24.471589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme protocols to http://&lt;scheme&gt;.localhost/ because those platforms' WebView implementations cannot serve custom URI schemes directly. The issue is that Tauri's check to see if the origin is local, only checks the first subdomain of the URL. An attacker can abuse this by hosting a page on a domain whose subdomain matches the custom scheme of the application. This vulnerability is fixed in 2.10.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7gmj-67g7-phm9</id>
    <title>GHSA-7gmj-67g7-phm9 — Tauri has an Origin Confusion Issue that Allows Remote Pages to Invoke Local-Only IPC Commands</title>
    <updated>2026-10-08T09:29:24.471629+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: tauri</p>
<p>### Summary
A flaw in Tauri's `is_local_url()` function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme protocols to `http://&lt;scheme&gt;.localhost/` because those platforms' WebView implementations cannot serve custom URI schemes directly.</p>
<p>The issue is that Tauri's check to see if the origin is local, only checks the first subdomain of the URL. An attacker can abuse this by hosting a page on a domain whose subdomain matches the custom scheme of the application (e.g. http://app.attacker.com/)."</p>
<p>Example:
- Local URL: `app://localhost/` → on Android/Windows: `http://app.localhost/`
- The check passes for any URL starting with `http://app.`, including `http://app.evil.com/`</p>
<p>As a result, the attacker page can invoke backend commands that the developer intended to be accessible only to the app's own frontend and that are explicitly restricted from being called by external or remote origins.</p>
<p>### Details
Vulnerable function:</p>
<p>```rust
#[cfg(any(windows, target_os = "android"))]
let local = {
  let protocol_url = self.manager().tauri_protocol_url(uses_https);
  let maybe_protocol = current_url
    .domain()
    .and_then(|d| d.split_once('.'))  // BUG: only splits on first dot
    .unwrap_or_default()
    .0;</p>
<p>protocols.contains_key(maybe_protocol) &amp;&amp; scheme == protocol_url.scheme()
};
```</p>
<p>Link: https://github.com/tauri-apps/tauri/blob/1ef6a119b1571d1da0acc08bdb7fd5521a4c6d52/crates/tauri…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7gmj-67g7-phm9"/>
  </entry>
</feed>
