<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:35:17.755696+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-321461</id>
    <title>EUVD-2026-321461</title>
    <updated>2026-10-06T16:35:17.806437+00:00</updated>
    <content>EUVD-2026-321461</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-321461"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45728</id>
    <title>fkie_cve-2026-45728</title>
    <updated>2026-10-06T16:35:17.806477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled. debugMode activates the PrettyError renderer, which on any Lua or template error response dumps the absolute path of the file that errored, complete byte contents of that file, and exception or parser error text. This response is served with HTTP 200 OK to whoever sent the request that triggered the error. Any client able to reach the server and able to provoke a runtime error in the served script obtains the full server-side source of that script and of any sibling Lua data file consulted during the request. This vulnerability is fixed in 1.17.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45728"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fwqx-8365-9983</id>
    <title>GHSA-fwqx-8365-9983 — Algernon: Single-file mode unconditionally enables debug mode</title>
    <updated>2026-10-06T16:35:17.806514+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/xyproto/algernon</p>
<p>### Summary</p>
<p>When Algernon is invoked with a single file path instead of a directory — the documented "quick demo" workflow (`algernon foo.lua`, `algernon page.po2`, `algernon index.html`, `algernon mywebsite.alg`) — `singleFileMode` is set to true and **`debugMode` is forcibly enabled** with no opt-out:</p>
<p>```go
// engine/config.go:498-502
// Make a few changes to the defaults if we are serving a single file
if ac.singleFileMode {
    ac.debugMode = true
    ac.serveJustHTTP = true
}
```</p>
<p>`debugMode` activates the `PrettyError` renderer, which on any Lua or template error response dumps:</p>
<p>1. The **absolute path** of the file that errored (`Filename` field of the error template).
2. The **complete byte contents** of that file, HTML-escaped, with the offending line wrapped in `&lt;font style='color: red !important'&gt;…&lt;/font&gt;`.
3. The exception or parser error text — which in turn often quotes additional file content (Pongo2 errors include surrounding template lines; Lua tracebacks include argument values).</p>
<p>This response is served with `HTTP 200 OK` to whoever sent the request that triggered the error. There is no authentication, no rate limit specific to errors, no redaction, and no opt-out short of avoiding single-file invocations entirely. Any client able to reach the server and able to provoke a runtime error in the served script obtains the full server-side source of that script and of any sibling Lua data file consulted during the request.</p>
<p>This combines particularly badly wi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fwqx-8365-9983"/>
  </entry>
</feed>
