<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T11:00:21.581154+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-42303</id>
    <title>CVE-2026-42303 — Fides: Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection</title>
    <updated>2026-10-04T11:00:21.582810+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> ethyca fides</p>
<p>Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request whose identity was never verified. For erasure policies, this can result in unauthorized deletion of a data subject's records across every integration configured in the affected deployment. This vulnerability is fixed in 2.83.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-42303"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qx5f-ghc2-7g5c</id>
    <title>GHSA-qx5f-ghc2-7g5c — Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection</title>
    <updated>2026-10-04T11:00:21.582862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ethyca-fides</p>
<p>### Summary</p>
<p>Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request whose identity was never verified. For erasure policies, this can result in unauthorized deletion of a data subject's records across every integration configured in the affected deployment.</p>
<p>A related lower-severity denial-of-service issue, in which an unauthenticated attacker could prevent a legitimate data subject from completing their own privacy requests, is also patched in the fix for this vulnerability.</p>
<p>### Am I affected?</p>
<p>This vulnerability only affects deployments that use Fides's privacy request (data subject request) features, also known collectively as "Lethe". Deployments that do not submit, process, or manage privacy requests through Fides are not affected.</p>
<p>Within deployments that do use privacy request features, your deployment is affected if both of the following settings are effectively set to `true`:</p>
<p>- `subject_identity_verification_required`
- `privacy_request_duplicate_detection.enabled`</p>
<p>Both settings default to `false`.</p>
<p>Each setting can be configured in multiple places. If the same setting is configured in more than one place, Fides resolves conflicts in the following precedence order, highest priority first:</p>
<p>1. **Admin UI / configuration API** - stored in the application database and applied at runtime
2. **Environment variables** - read at webse…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qx5f-ghc2-7g5c"/>
  </entry>
</feed>
