<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T21:58:03.295313+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326980</id>
    <title>EUVD-2026-326980</title>
    <updated>2026-10-05T21:58:03.344071+00:00</updated>
    <content>EUVD-2026-326980</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326980"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45013</id>
    <title>fkie_cve-2026-45013</title>
    <updated>2026-10-05T21:58:03.344107+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the reset URL using `req.hostname`, which is derived directly from the attacker-controlled HTTP `Host` header when `apos.baseUrl` is not explicitly configured. An unauthenticated attacker who knows a victim's email address can send a crafted reset request that causes the application to email the victim a reset link pointing to the attacker's domain. When the victim clicks the link, the valid reset token is delivered to the attacker, enabling full account takeover. As of time of publication, no known patched versions are available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gf43-24g3-5hw2</id>
    <title>GHSA-gf43-24g3-5hw2 — Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation</title>
    <updated>2026-10-05T21:58:03.344143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: apostrophe</p>
<p>## Summary</p>
<p>ApostropheCMS's password reset flow constructs the reset URL using `req.hostname`, 
which is derived directly from the attacker-controlled HTTP `Host` header when 
`apos.baseUrl` is not explicitly configured. An unauthenticated attacker who knows 
a victim's email address can send a crafted reset request that causes the application 
to email the victim a reset link pointing to the attacker's domain. When the victim 
clicks the link, the valid reset token is delivered to the attacker, enabling full 
account takeover.</p>
<p>## Affected Component</p>
<p>`modules/@apostrophecms/login/index.js` — `resetRequest` route  
Precondition: `passwordReset: true` is set **and** `apos.baseUrl` is not configured.</p>
<p>## Vulnerability Details</p>
<p>The `setPrefixUrls` middleware (i18n layer) builds `req.baseUrl` using `req.hostname`:</p>
<p>```js
// Simplified from i18n middleware
req.baseUrl = `${req.protocol}://${req.hostname}`;
req.absoluteUrl = req.baseUrl + req.url;
```</p>
<p>The `resetRequest` handler then passes this tainted value directly into URL construction:</p>
<p>```js
const parsed = new URL(
  req.absoluteUrl,           // ← tainted by attacker's Host header
  self.apos.baseUrl
    ? undefined
    : `${req.protocol}://${req.hostname}${port}`  // ← also tainted
);
parsed.pathname = '/login';
parsed.searchParams.append('reset', reset);   // real, valid token
parsed.searchParams.append('email', user.email);
await self.email(..., { url: parsed.toString() }, ...);
// Email sent to victim with URL pointing…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gf43-24g3-5hw2"/>
  </entry>
</feed>
