<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T13:43:46.908176+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352296</id>
    <title>EUVD-2026-352296</title>
    <updated>2026-10-05T13:43:46.972702+00:00</updated>
    <content>EUVD-2026-352296</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352296"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73652</id>
    <title>fkie_cve-2026-73652</title>
    <updated>2026-10-05T13:43:46.972737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm developer to alter another developer's algorithm while it is pending or under review. The attacker can change metadata including the algorithm image or image tag, causing reviewers and nodes to trust a different image from the one originally submitted for approval. No fixed version is available as of this review.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73652"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-47w6-gwp4-w6vc</id>
    <title>GHSA-47w6-gwp4-w6vc — vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review</title>
    <updated>2026-10-05T13:43:46.972770+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vantage6</p>
<p>### Impact
Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes.</p>
<p>Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review</p>
<p>### Patches
No</p>
<p>### Workarounds
No</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-47w6-gwp4-w6vc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3703</id>
    <title>PYSEC-2026-3703 — vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review</title>
    <updated>2026-10-05T13:43:46.972800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vantage6</p>
<p>### Impact
Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes.</p>
<p>Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review</p>
<p>### Patches
No</p>
<p>### Workarounds
No</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3703"/>
  </entry>
</feed>
