<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T13:12:52.617062+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329118</id>
    <title>EUVD-2026-329118</title>
    <updated>2026-10-06T13:12:52.666066+00:00</updated>
    <content>EUVD-2026-329118</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329118"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48794</id>
    <title>fkie_cve-2026-48794</title>
    <updated>2026-10-06T13:12:52.666119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36.0 through 4.39.19, due to lack of canonicalization of domains in very specific edge cases, an access control rule may be skipped when it should match a request. The specific conditions that could lead to a security issue for vulnerability are: 1. The specific target resource of the attack must be using the forwarded authorization integration; 2. The requested domain must have two additional segments compared to a session domain i.e. `a.b.example.com` is requested, but the session domain is `example.com`; 3. There access control rules must specify two separate rules which both contain inexact domain matches such as `*.b.example.com` and `*.example.com` i.e. wildcards, username matches, group matches; 4. The rules must be in order of most specific domain to least specific domain; 5. The second rule must be more permissive than the first rule; 6. The attacker must specifically request a URL for the more specific domain, with the second part containing one or more capitalized letters i.e. `https://a.B.example.com` and no other segment with capitalized letters; 7. The integration used must not be the Envoy ExtAuthz integration; and 8. The proxy must not canonicalize the requested host name in the relevant header before sending it to the relevant authorization endpoint. The kind of configuration used to…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48794"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j748-h363-wqj8</id>
    <title>GHSA-j748-h363-wqj8 — Authelia has an Edge Case Access Control Rule Mismatch</title>
    <updated>2026-10-06T13:12:52.666169+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/authelia/authelia/v4</p>
<p>### Impact</p>
<p>**CVSSv4 Baseline Score:** Low 2.4</p>
<p>**CVSSv4 Weighted Score:** Low 1.3</p>
<p>The full CVSSv4 Vector for this vulnerability is:</p>
<p>&gt; CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:P/CR:H/IR:L/AR:L/MAV:N/MAC:H/MAT:P/MPR:L/MVC:L/MVI:N/MVA:N/MSC:L/MSI:N/MSA:N/S:N/AU:Y/R:U/V:D/RE:L/U:Amber</p>
<p>**CVSSv3.1 Baseline Score:** Low 3.1</p>
<p>**CVSSv3.1 Overall Score:** Low 3.4</p>
<p>The full CVSSv3.1 Vector equivalent for this vulnerability is:</p>
<p>&gt; CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C/CR:H/IR:L/AR:L/MAV:N/MAC:H/MPR:L/MUI:X/MS:U/MC:L/MI:N/MA:N</p>
<p>The weighted severity rating is a result of no indication this is currently being exploited being available at the time of the publish date, in addition to the fact it's unlikely that it is being exploited currently. The vectors have been picked based on the scenario most likely to exist in real configurations.</p>
<p>In addition to the weighting our assessment considers the fact the configuration scenario required for this vulnerability to be exploited is highly unlikely and an attacker is unlikely in most scenarios to be able to determine if the exploit is available and if it was successful except in rare situations. Though the visibility to the attacker was not reflected in our assessment.</p>
<p>### Summary</p>
<p>Due to lack of canonicalization of domains in very specific edge cases an access control rule may be skipped when it should match a request.</p>
<p>### Details</p>
<p>This attack vector must be executed in a highly specific scenar…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j748-h363-wqj8"/>
  </entry>
</feed>
