<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T01:15:58.908133+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371971</id>
    <title>EUVD-2026-371971</title>
    <updated>2026-10-07T01:15:58.957012+00:00</updated>
    <content>EUVD-2026-371971</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371971"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63405</id>
    <title>fkie_cve-2026-63405</title>
    <updated>2026-10-07T01:15:58.957050+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-compatible REST API in pusher/http.go includes the caller-supplied body_md5 value in the HMAC input but does not calculate the digest of the received request body or compare it with the signed value. An attacker who obtains a legitimate signed POST request can retain its query parameters and auth_signature while replacing the body, causing Handler and handleEvents to accept and broadcast attacker-selected event content. The absence of an auth_timestamp freshness check also allows the captured signature to be replayed indefinitely. This can forge server-side events, modify application state, or deliver attacker-controlled messages to WebSocket clients within the signed request's application context. This issue is fixed in version 1.6.15.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5p54-whvp-x327</id>
    <title>GHSA-5p54-whvp-x327 — AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body</title>
    <updated>2026-10-07T01:15:58.957088+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/anycable/anycable</p>
<p>### Summary
The Pusher-compatible REST API includes `body_md5` in the HMAC signature string but never computes or verifies the MD5 of the received HTTP body, allowing anyone who observes a signed request to replay it with an entirely different body.</p>
<p>### Details
In `pusher/http.go`, the `Handler` function extracts `body_md5` from the URL query string (line 169) and includes it verbatim in `stringToSign` (line 175). It then verifies `HMAC(stringToSign, secret) == auth_signature`. After verification succeeds, `handleEvents` reads and parses `r.Body` (lines 201-212) without ever computing `md5(body)` and comparing it against the `body_md5` that was signed. The Pusher protocol specification explicitly requires the server to verify this digest to prevent body-substitution attacks. There is also no `auth_timestamp` staleness check, so replays are valid indefinitely.</p>
<p>### PoC
1. Capture a legitimate signed POST to `/apps/&lt;app_id&gt;/events?auth_key=K&amp;auth_timestamp=T&amp;auth_version=1.0&amp;body_md5=LEGIT_MD5&amp;auth_signature=SIG` carrying body `{"name":"safe-event","channel":"ch","data":"..."}` (e.g., from TLS-terminating load-balancer logs).
2. Send a new request with the same query string parameters but a different body:
   `{"name":"injected-event","channel":"admin","data":"malicious-payload"}`
3. The server accepts the request (HMAC over `stringToSign` matches the original) and broadcasts the injected event to all subscribers of `admin`.</p>
<p>### Impact
An attacker who can read any single sig…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5p54-whvp-x327"/>
  </entry>
</feed>
