<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T20:18:40.218037+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362061</id>
    <title>EUVD-2026-362061</title>
    <updated>2026-10-06T20:18:40.268601+00:00</updated>
    <content>EUVD-2026-362061</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362061"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55891</id>
    <title>fkie_cve-2026-55891</title>
    <updated>2026-10-06T20:18:40.268651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which does not remove quotation marks, angle brackets, or apostrophes, and Controller::_init() stores the attacker-controlled value in Controller::$_urlBase. Controller::_jsonld() in lib/Controller.php then uses str_replace() to insert that value without JSON escaping into js/types.jsonld, js/paste.jsonld, and the other JSON-LD templates used by /?jsonld= and /?pasteid. A raw quotation mark delivered by an HTTP client, proxy, or structured-data crawler that does not normalize the request target can break out of the JSON string and inject arbitrary key-value data into a CORS-open application/ld+json response. The jsonld branch in Controller::__construct() returns before _setCacheHeaders(), so the response also lacks X-Content-Type-Options: nosniff, Content Security Policy, X-Frame-Options, and Referrer-Policy. Direct script execution was not demonstrated, but manipulated responses can affect structured-data consumers or combine with less strict clients. This issue is fixed in version 2.0.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55891"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xrjc-c68j-hp7w</id>
    <title>GHSA-xrjc-c68j-hp7w — PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI</title>
    <updated>2026-10-06T20:18:40.268695+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: privatebin/privatebin</p>
<p>## Vulnerability Details</p>
<p>A reflected JSON injection allows an attacker to return arbitrary data in the JSON endpoints (like ` /?jsonld=` and `/?pasteid`).</p>
<p>### Root Cause</p>
<p>`Request::getRequestUri()` sanitizes `$_SERVER['REQUEST_URI']` with `FILTER_SANITIZE_URL`:</p>
<p>```php
public function getRequestUri()
{
    $uri = array_key_exists('REQUEST_URI', $_SERVER) ? filter_var($_SERVER['REQUEST_URI'], FILTER_SANITIZE_URL) : '';
    return empty($uri) ? '/' : $uri;
}
```</p>
<p>`FILTER_SANITIZE_URL` does **not** strip `"`, `'`, `&lt;`, `&gt;` characters (per the PHP manual's allowed-character list for this filter). So the raw, attacker-controlled request URI (including query string) passes through almost unmodified into `Controller::$_urlBase` (set in `_init()`).</p>
<p>In `Controller::_jsonld()`, `$_urlBase` is spliced directly into one of the static `.jsonld` templates (`js/types.jsonld`, `js/paste.jsonld`, etc.) with a plain `str_replace()`, without any JSON-escaping:</p>
<p>```php
$content = str_replace(
    '?jsonld=',
    $this-&gt;_urlBase . '?jsonld=',
    file_get_contents($file)
);
...
header('Content-type: application/ld+json');
header('Access-Control-Allow-Origin: *');
header('Access-Control-Allow-Methods: GET');
echo $content;
```</p>
<p>A request URI containing a literal `"` therefore breaks out of the JSON string in the `"@context"."pb"` value and injects arbitrary attacker-controlled key/value pairs into the response body, which is served with `Content-Type: application/ld+json` and `Access-Control-A…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xrjc-c68j-hp7w"/>
  </entry>
</feed>
