<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:39:16 +0000</lastBuildDate>
    <item>
      <title>BREW-travis-CVE-2013-0263 — Rack arbitrary code execution via timing attack</title>
      <link>https://cve.radiocsirt.org/vuln/brew-travis-cve-2013-0263</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: travis&lt;/p&gt;
&lt;p&gt;Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: travis&lt;/p&gt;
&lt;p&gt;Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-travis-cve-2013-0263</guid>
    </item>
    <item>
      <title>EUVD-2026-104566</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-104566</link>
      <description>EUVD-2026-104566</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-104566</guid>
    </item>
    <item>
      <title>fkie_cve-2013-0263</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2013-0263</link>
      <description>&lt;p&gt;Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2013-0263</guid>
    </item>
    <item>
      <title>GHSA-xc85-32mf-xpv8 — Rack arbitrary code execution via timing attack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xc85-32mf-xpv8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rack&lt;/p&gt;
&lt;p&gt;Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: rack&lt;/p&gt;
&lt;p&gt;Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xc85-32mf-xpv8</guid>
    </item>
    <item>
      <title>gsd-2013-0263</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2013-0263</link>
      <description>gsd-2013-0263</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2013-0263</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10115-1 — ruby2.2-rubygem-rack-1_4-1.4.7-1.8 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10115-1</link>
      <description>&lt;p&gt;ruby2.2-rubygem-rack-1_4-1.4.7-1.8 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby2.2-rubygem-rack-1_4-1.4.7-1.8 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10115-1</guid>
    </item>
    <item>
      <title>RHSA-2013:0638 — Red Hat Security Advisory: Red Hat OpenShift Enterprise 1.1.2 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2013:0638</link>
      <description>&lt;p&gt;rubygem-rack: Path sanitization information disclosure rubygem-rack: Timing attack in cookie sessions jenkins: cross-site request forgery (CSRF) on Jenkins master jenkins: XSS jenkins: cross-site request forgery (CSRF) protection mechanism bypass jenkins: cause building jobs without direct access jenkins: denial of service attack by feeding a carefully crafted payload to Jenkins&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rubygem-rack: Path sanitization information disclosure rubygem-rack: Timing attack in cookie sessions jenkins: cross-site request forgery (CSRF) on Jenkins master jenkins: XSS jenkins: cross-site request forgery (CSRF) protection mechanism bypass jenkins: cause building jobs without direct access jenkins: denial of service attack by feeding a carefully crafted payload to Jenkins&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2013:0638</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2013-0263</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-0263</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-rack&lt;/p&gt;
&lt;p&gt;Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: ruby-rack&lt;/p&gt;
&lt;p&gt;Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-0263</guid>
    </item>
  </channel>
</rss>
