<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:54:50.806008+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-35490</id>
    <title>CVE-2026-35490 — changedetection.io has an Authentication Bypass via Decorator Ordering</title>
    <updated>2026-10-02T13:54:50.807648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> dgtlmoon changedetection.io</p>
<p>changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route() must be the outermost decorator because it registers the function it receives. When the order is reversed, @route() registers the original undecorated function, and the auth wrapper is never in the call chain. This silently disables authentication on these routes. This vulnerability is fixed in 0.54.8.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-35490"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jmrh-xmgh-x9j4</id>
    <title>GHSA-jmrh-xmgh-x9j4 — changedetection.io Vulnerable to Authentication Bypass via Decorator Ordering</title>
    <updated>2026-10-02T13:54:50.807709+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: changedetection.io</p>
<p>### Summary</p>
<p>On 13 routes across 5 blueprint files, the `@login_optionally_required` decorator is placed **before** (outer to) `@blueprint.route()` instead of after it. In Flask, `@route()` must be the outermost decorator because it registers the function it receives. When the order is reversed, `@route()` registers the **original undecorated function**, and the auth wrapper is never in the call chain. This silently disables authentication on these routes.</p>
<p>The developer correctly uses the decorator on 30+ other routes with the proper order, making this a classic consistency gap.</p>
<p>### Details</p>
<p>**Correct order (used on 30+ routes):**
```python
@blueprint.route('/settings', methods=['GET'])
@login_optionally_required
def settings():
    ...
```</p>
<p>**Incorrect order (13 vulnerable routes):**
```python
@login_optionally_required          # ← Applied to return value of @route, NOT the view
@blueprint.route('/backups/download/&lt;filename&gt;')  # ← Registers raw function
def download_backup(filename):
    ...
```</p>
<p>## POC
```
=== PHASE 1: Confirm Authentication is Required ===</p>
<p>$ curl -s -o /dev/null -w "%{http_code}" http://127.0.0.1:5557/
Main page:     HTTP 302 -&gt; http://127.0.0.1:5557/login?next=/
$ curl -s -o /dev/null -w "%{http_code}" http://127.0.0.1:5557/settings
Settings page: HTTP 302 (auth required, redirects to login)</p>
<p>Password is set. Unauthenticated requests to / and /settings
are properly redirected to /login.</p>
<p>=== PHASE 2: Authentication Bypass on Backup Routes ===
(All r…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jmrh-xmgh-x9j4"/>
  </entry>
</feed>
