<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T01:08:49.634716+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-349344</id>
    <title>EUVD-2026-349344</title>
    <updated>2026-10-06T01:08:49.695338+00:00</updated>
    <content>EUVD-2026-349344</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-349344"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45378</id>
    <title>fkie_cve-2026-45378</title>
    <updated>2026-10-06T01:08:49.695378+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin UI embeds verification_attachment blobs through reusable signed Active Storage disk URLs, allowing anyone who obtains a URL to download the scanned document without an authenticated Decidim session until the signature expires. Verification-document images are rendered with variant_url(...), which produces signed /rails/active_storage/disk/... links instead of routing the file through an authorization-checking controller. Because Decidim configures Active Storage service URLs to remain valid for seven days, the URL itself becomes the credential for that period. The affected files are verification_attachment blobs on Decidim::Authorization, and the admin review pages embed those signed URLs directly into the HTML for pending and confirmation views. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45378"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3mvf-82qp-8qh5</id>
    <title>GHSA-3mvf-82qp-8qh5 — Decidim: Verification documents can be downloaded through reusable links</title>
    <updated>2026-10-06T01:08:49.695415+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: decidim-verifications</p>
<p>## Description</p>
<p>Scanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed `/rails/active_storage/disk/` URLs that can be fetched without any authenticated session.</p>
<p>Anyone who obtains one of those URLs can retrieve the document until the signature expires.</p>
<p>## Technical description</p>
<p>This issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with `variant_url(...)`, which produces signed `/rails/active_storage/disk/...` links instead of routing the file through an authorization-checking controller. Because Decidim configures Active Storage service URLs to remain valid for seven days, the URL itself becomes the credential for that period.</p>
<p>The affected files are `verification_attachment` blobs on Decidim::Authorization, and the admin review pages embed those signed URLs directly into the HTML for pending and confirmation views.</p>
<p>Reproduction steps:</p>
<p>1. Create a fresh verification document as a normal user.
1.1. Open http://localhost:3001/users/sign_in.
1.2. Open http://localhost:3001/id_documents/authorizations/new.
1.3. Submit an id_documents verification request with an image attachment.</p>
<p>2. Open the admin review page that renders the attachment.
2.1. Sign out.
2.2. Sign back in as admin@example.org.
2.3. Try http://localhost:3001/admin/id_documents.</p>
<p>3. Harvest the signed Active Storage URL.
3.1. Open D…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3mvf-82qp-8qh5"/>
  </entry>
</feed>
