<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T15:44:51.649026+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343794</id>
    <title>EUVD-2026-343794</title>
    <updated>2026-10-06T15:44:51.651693+00:00</updated>
    <content>EUVD-2026-343794</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343794"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57232</id>
    <title>fkie_cve-2026-57232</title>
    <updated>2026-10-06T15:44:51.651724+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderController::getResponse() to feedIo-&gt;read() without scheme or private-address validation, allowing a backend user with module-edit permissions to make the server request internal network services, loopback addresses, or cloud metadata endpoints. In core-bundle/src/Controller/FrontendModule/FeedReaderController.php, the getResponse() function iterates over the configured feed URLs and passes each one directly to the HTTP client (via $this-&gt;feedIo-&gt;read($url, new Feed())) with no validation, while the DCA field definition for rss_feed in tl_module.php carries no URL scheme or host validation and the HTTP client is wired as @psr18.http_client (Symfony HttpClient) with no SSRF protection configured, since NoPrivateNetworkHttpClient is not used. This issue is fixed in versions 5.3.48.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-57232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-87mg-5grr-rhwh</id>
    <title>GHSA-87mg-5grr-rhwh — Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module</title>
    <updated>2026-10-06T15:44:51.651761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: contao/contao, Packagist: contao/core-bundle</p>
<p>### Summary</p>
<p>The Feed Reader front-end module passes RSS feed URLs from its configuration directly to `$this-&gt;feedIo-&gt;read($url)` without any scheme validation or private-IP blocklist. A backend user with module-edit permissions can configure an arbitrary URL pointing to internal network services, cloud-provider metadata endpoints, or loopback addresses, causing the server to fetch those resources unconditionally. Confirmed live: the server successfully reaches the internal MySQL database container and its own loopback Apache instance.</p>
<p>---</p>
<p>### Details</p>
<p>In `core-bundle/src/Controller/FrontendModule/FeedReaderController.php`, the `getResponse()` function iterates over the configured feed URLs and passes each one directly to the HTTP client with no validation:</p>
<p>```php
// Line 50-55
foreach (StringUtil::trimsplit('[\n\t ]', trim($model-&gt;rss_feed)) as $url) {
    try {
        $feed = $this-&gt;cache-&gt;get(
            'feed_reader_'.$model-&gt;id.'_'.md5($url),
            function (ItemInterface $item) use ($url, $model) {
                $readerResult = $this-&gt;feedIo-&gt;read($url, new Feed()); // &lt;-- no validation
```</p>
<p>The DCA field definition for `rss_feed` in `tl_module.php` carries no URL scheme or host validation:
```php
'eval' =&gt; array('mandatory'=&gt;true, 'decodeEntities'=&gt;true, 'style'=&gt;'height:60px')
```</p>
<p>The HTTP client is wired as `@psr18.http_client` (Symfony HttpClient) with no SSRF protection configured (`NoPrivateNetworkHttpClient` is not used).</p>
<p>---</p>
<p>### Impact</p>
<p>This is…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-87mg-5grr-rhwh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2287</id>
    <title>WID-SEC-W-2026-2287 — Contao: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-06T15:44:51.651817+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Contao ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2287"/>
  </entry>
</feed>
