<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T23:33:57.799805+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-321543</id>
    <title>EUVD-2026-321543</title>
    <updated>2026-10-05T23:33:57.846271+00:00</updated>
    <content>EUVD-2026-321543</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-321543"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46430</id>
    <title>fkie_cve-2026-46430</title>
    <updated>2026-10-05T23:33:57.846311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent host default in engine/flags.go:39-46 set host = "" for non-Windows, and utils.JoinHostPort("", ":5553") resolves to ":5553". This vulnerability is fixed in 1.17.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46430"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gj84-924c-48fx</id>
    <title>GHSA-gj84-924c-48fx — Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS</title>
    <updated>2026-10-05T23:33:57.846348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/xyproto/algernon</p>
<p>### Summary</p>
<p>The SSE event server bound to `0.0.0.0:5553` on Linux/macOS by default because the platform-dependent host default in `engine/flags.go:39-46` set `host = ""` for non-Windows, and `utils.JoinHostPort("", ":5553")` resolves to `":5553"` — a Go `http.Server.Addr` of `":5553"` listens on every interface. On Windows the same code chose `"localhost"`, binding loopback only.</p>
<p>The result was a platform split where the OS Algernon's dev workflow is most often used on (Linux/macOS) got the network-exposed default, and only Windows users got the loopback-safe one. A LAN peer with no developer interaction could connect to `&lt;dev-laptop-ip&gt;:5553` and read the file-change stream.</p>
<p>This advisory covers the bind-address default in isolation. The fix is independent of authentication (#2a) and CORS (#2b) — switching the default to loopback can be done without touching either.</p>
<p>### Details</p>
<p>#### Root cause — platform-dependent `host` default in `handleFlags`</p>
<p>```go
// engine/flags.go:39-46  (1.17.6)
host := ""
if runtime.GOOS == "windows" {
    host = "localhost"
    // Default Bolt database file
    ac.defaultBoltFilename = filepath.Join(serverTempDir, "algernon.db")
    // Default log file
    ac.defaultLogFile = filepath.Join(serverTempDir, "algernon.log")
}
```</p>
<p>```go
// engine/config.go:388-391  (1.17.6, finalConfiguration)
if ac.eventAddr == "" {
    ac.eventAddr = utils.JoinHostPort(host, ac.defaultEventColonPort)
}
```</p>
<p>Result tabulated:</p>
<p>| Platform | `host` | `eventAddr` a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gj84-924c-48fx"/>
  </entry>
</feed>
