<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T16:08:00.290056+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322956</id>
    <title>EUVD-2026-322956</title>
    <updated>2026-10-08T16:08:00.345970+00:00</updated>
    <content>EUVD-2026-322956</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322956"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44885</id>
    <title>fkie_cve-2026-44885</title>
    <updated>2026-10-08T16:08:00.346014+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's backup restore feature accepts a .tar.gz archive and extracts it to a target directory on the server. The extraction function (ExtractTarGz in api/archive/targz.go) constructed output paths using filepath.Clean(filepath.Join(outputDirPath, header.Name)). This combination does not prevent directory traversal — a tar entry named ../../etc/cron.d/evil resolves to a path outside the extraction root, so a crafted archive can write files to arbitrary locations on the server filesystem. This vulnerability is fixed in 2.33.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44885"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m8fg-67j7-cx4v</id>
    <title>GHSA-m8fg-67j7-cx4v — Portainer has a path traversal in backup archive extraction that allows arbitrary file write</title>
    <updated>2026-10-08T16:08:00.346057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/portainer/portainer</p>
<p>### Summary
Portainer's backup restore feature accepts a `.tar.gz` archive and extracts it to a target directory on the server. The extraction function (`ExtractTarGz` in `api/archive/targz.go`) constructed output paths using `filepath.Clean(filepath.Join(outputDirPath, header.Name))`. This combination does not prevent directory traversal — a tar entry named `../../etc/cron.d/evil` resolves to a path outside the extraction root, so a crafted archive can write files to arbitrary locations on the server filesystem.</p>
<p>## Severity</p>
<p>**Medium**</p>
<p>**CWE-22** — Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal')</p>
<p>Exploitation requires administrator access to Portainer's backup restore endpoint. An administrator who is deceived into restoring a malicious archive, or whose credentials are compromised, can use this path to write files outside the Portainer data directory.</p>
<p>## Affected Versions</p>
<p>The vulnerability exists in every Portainer release prior to 2.39.0 — `ExtractTarGz` has used `filepath.Clean(filepath.Join())` since it was introduced.  The fix shipped with 2.39.0 (patched on `develop` before the 2.39 branch cut); 2.34.x–2.38.x STS releases are also affected but are end-of-life and will not receive a fix.</p>
<p>| Branch       | First vulnerable | Fixed in   |
|--------------|------------------|------------|
| 2.33.x (LTS) | 2.33.0           | **2.33.8** |</p>
<p>Portainer 2.39.0 and later are not affected — the fix was present from the initial 2.39.0 release. All…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m8fg-67j7-cx4v"/>
  </entry>
</feed>
