<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T04:18:28.728012+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-361459</id>
    <title>EUVD-2026-361459</title>
    <updated>2026-10-08T04:18:28.778703+00:00</updated>
    <content>EUVD-2026-361459</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-361459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55108</id>
    <title>fkie_cve-2026-55108</title>
    <updated>2026-10-08T04:18:28.778748+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones a repository supplied through a core.oam.dev/v1beta1 ComponentDefinition and follows repository-controlled variables.tf or main.tf symlinks. A user with permission to create or update ComponentDefinition objects can point variables.tf to /dev/zero through terraform.path, after which os.Stat and os.ReadFile follow the link and read an unbounded stream before ParseTerraformVariables or HCL parsing can reject the content. The read can exhaust memory, OOM-kill the cluster-wide vela-core controller, cause repeated Pod restarts, and pressure node memory when no effective container limit is configured. This issue is fixed in versions 1.9.14, 1.10.9, and 1.11.0-alpha.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fmgp-q6jx-gg3x</id>
    <title>GHSA-fmgp-q6jx-gg3x — KubeVela Terraform remote loader DoS via unbounded file read</title>
    <updated>2026-10-08T04:18:28.778788+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/oam-dev/kubevela</p>
<p>### Summary</p>
<p>KubeVela's Terraform remote configuration loader can be abused to make `vela-core` read an unbounded byte stream into memory, causing an out-of-memory kill and a control-plane denial of service.</p>
<p>The issue is reachable when a user with permission to create or update a `core.oam.dev/v1beta1` `ComponentDefinition` registers a Terraform `remote` schematic that points to a malicious or compromised git repository. The repository can contain a `variables.tf` symlink that resolves to `/dev/zero` after checkout. `vela-core` follows the symlink and calls `os.ReadFile` before HCL parsing, so memory grows until the controller is OOM killed.</p>
<p>### Details</p>
<p>The affected code is in `pkg/controller/utils/capability.go`, inside `GetTerraformConfigurationFromRemote`:</p>
<p>https://github.com/kubevela/kubevela/blob/a24d3a9c6/pkg/controller/utils/capability.go#L231-L242</p>
<p>```go
tfPath := filepath.Join(cachePath, remotePath, "variables.tf")
if _, err := os.Stat(tfPath); err != nil {
    tfPath = filepath.Join(cachePath, remotePath, "main.tf")
    if _, err := os.Stat(tfPath); err != nil {
        return "", errors.Wrap(err, "failed to find main.tf or variables.tf in Terraform configurations of the remote repository")
    }
}
conf, err := os.ReadFile(filepath.Clean(tfPath))
if err != nil {
    return "", errors.Wrap(err, "failed to read Terraform configuration")
}
```</p>
<p>When a `ComponentDefinition` uses:</p>
<p>```yaml
schematic:
  terraform:
    type: remote
    configuration: &lt;git repository UR…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fmgp-q6jx-gg3x"/>
  </entry>
</feed>
