<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:36:37 +0000</lastBuildDate>
    <item>
      <title>BREW-git-annex-CVE-2018-10859 — git-annex GPG decryption attack via compromised remote</title>
      <link>https://cve.radiocsirt.org/vuln/brew-git-annex-cve-2018-10859</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* GPG decryption attack via compromised remote&lt;/p&gt;
&lt;p&gt;A malicious server for a special remote could trick `git-annex` into
decrypting a file that was encrypted to the user&amp;#39;s GPG key.  This
attack could be used to expose encrypted data that was never stored
in *git-annex*.  Daniel Dent discovered this attack in collaboration
with Joey Hess.&lt;/p&gt;
&lt;p&gt;To perform this attack the attacker needs control of a server
hosting an *encrypted* special remote used by the victim&amp;#39;s
*git-annex* repository.  The attacker uses `git annex addurl
--relaxed` with an innocuous URL, and waits for the user&amp;#39;s
`git-annex` to download it, and upload an (encrypted) copy to the
special remote they also control.  At some later point, when the
user downloads the content from the special remote, the attacker
instead sends them the content of the GPG-encrypted file that they
wish to have decrypted in its place (which may have been exfiltrated
from the victim&amp;#39;s system via the attack described in
**HSEC-2023-0010** / **CVE-2018-10857**, or acquired by other
means).  Finally, the attacker drops their own copy of the original
innocuous URL, and waits for the victim `git-annex` to send them the
accidentially decrypted file.&lt;/p&gt;
&lt;p&gt;The issue was fixed by making `git-annex` refuse to download
encrypted content from special remotes, unless it knows the hash of
the expected content.  When the attacker provides some other
GPG-encrypted content, it will fail the hash check and be discarded.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* GPG decryption attack via compromised remote&lt;/p&gt;
&lt;p&gt;A malicious server for a special remote could trick `git-annex` into
decrypting a file that was encrypted to the user&amp;#39;s GPG key.  This
attack could be used to expose encrypted data that was never stored
in *git-annex*.  Daniel Dent discovered this attack in collaboration
with Joey Hess.&lt;/p&gt;
&lt;p&gt;To perform this attack the attacker needs control of a server
hosting an *encrypted* special remote used by the victim&amp;#39;s
*git-annex* repository.  The attacker uses `git annex addurl
--relaxed` with an innocuous URL, and waits for the user&amp;#39;s
`git-annex` to download it, and upload an (encrypted) copy to the
special remote they also control.  At some later point, when the
user downloads the content from the special remote, the attacker
instead sends them the content of the GPG-encrypted file that they
wish to have decrypted in its place (which may have been exfiltrated
from the victim&amp;#39;s system via the attack described in
**HSEC-2023-0010** / **CVE-2018-10857**, or acquired by other
means).  Finally, the attacker drops their own copy of the original
innocuous URL, and waits for the victim `git-annex` to send them the
accidentially decrypted file.&lt;/p&gt;
&lt;p&gt;The issue was fixed by making `git-annex` refuse to download
encrypted content from special remotes, unless it knows the hash of
the expected content.  When the attacker provides some other
GPG-encrypted content, it will fail the hash check and be discarded.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-git-annex-cve-2018-10859</guid>
    </item>
    <item>
      <title>cnvd-2018-13686</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-13686</link>
      <description>cnvd-2018-13686</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-13686</guid>
    </item>
    <item>
      <title>EUVD-2026-64850</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-64850</link>
      <description>EUVD-2026-64850</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-64850</guid>
    </item>
    <item>
      <title>fkie_cve-2018-10859</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-10859</link>
      <description>&lt;p&gt;git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user&amp;#39;s gpg key. This attack could be used to expose encrypted data that was never stored in git-annex&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user&amp;#39;s gpg key. This attack could be used to expose encrypted data that was never stored in git-annex&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-10859</guid>
    </item>
    <item>
      <title>GHSA-j24g-q5jp-xg4v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j24g-q5jp-xg4v</link>
      <description>&lt;p&gt;git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user&amp;#39;s gpg key. This attack could be used to expose encrypted data that was never stored in git-annex&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user&amp;#39;s gpg key. This attack could be used to expose encrypted data that was never stored in git-annex&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j24g-q5jp-xg4v</guid>
    </item>
    <item>
      <title>gsd-2018-10859</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-10859</link>
      <description>gsd-2018-10859</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-10859</guid>
    </item>
    <item>
      <title>HSEC-2023-0011 — git-annex GPG decryption attack via compromised remote</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2023-0011</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* GPG decryption attack via compromised remote&lt;/p&gt;
&lt;p&gt;A malicious server for a special remote could trick `git-annex` into
decrypting a file that was encrypted to the user&amp;#39;s GPG key.  This
attack could be used to expose encrypted data that was never stored
in *git-annex*.  Daniel Dent discovered this attack in collaboration
with Joey Hess.&lt;/p&gt;
&lt;p&gt;To perform this attack the attacker needs control of a server
hosting an *encrypted* special remote used by the victim&amp;#39;s
*git-annex* repository.  The attacker uses `git annex addurl
--relaxed` with an innocuous URL, and waits for the user&amp;#39;s
`git-annex` to download it, and upload an (encrypted) copy to the
special remote they also control.  At some later point, when the
user downloads the content from the special remote, the attacker
instead sends them the content of the GPG-encrypted file that they
wish to have decrypted in its place (which may have been exfiltrated
from the victim&amp;#39;s system via the attack described in
**HSEC-2023-0010** / **CVE-2018-10857**, or acquired by other
means).  Finally, the attacker drops their own copy of the original
innocuous URL, and waits for the victim `git-annex` to send them the
accidentially decrypted file.&lt;/p&gt;
&lt;p&gt;The issue was fixed by making `git-annex` refuse to download
encrypted content from special remotes, unless it knows the hash of
the expected content.  When the attacker provides some other
GPG-encrypted content, it will fail the hash check and be discarded.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: git-annex&lt;/p&gt;
&lt;p&gt;# *git-annex* GPG decryption attack via compromised remote&lt;/p&gt;
&lt;p&gt;A malicious server for a special remote could trick `git-annex` into
decrypting a file that was encrypted to the user&amp;#39;s GPG key.  This
attack could be used to expose encrypted data that was never stored
in *git-annex*.  Daniel Dent discovered this attack in collaboration
with Joey Hess.&lt;/p&gt;
&lt;p&gt;To perform this attack the attacker needs control of a server
hosting an *encrypted* special remote used by the victim&amp;#39;s
*git-annex* repository.  The attacker uses `git annex addurl
--relaxed` with an innocuous URL, and waits for the user&amp;#39;s
`git-annex` to download it, and upload an (encrypted) copy to the
special remote they also control.  At some later point, when the
user downloads the content from the special remote, the attacker
instead sends them the content of the GPG-encrypted file that they
wish to have decrypted in its place (which may have been exfiltrated
from the victim&amp;#39;s system via the attack described in
**HSEC-2023-0010** / **CVE-2018-10857**, or acquired by other
means).  Finally, the attacker drops their own copy of the original
innocuous URL, and waits for the victim `git-annex` to send them the
accidentially decrypted file.&lt;/p&gt;
&lt;p&gt;The issue was fixed by making `git-annex` refuse to download
encrypted content from special remotes, unless it knows the hash of
the expected content.  When the attacker provides some other
GPG-encrypted content, it will fail the hash check and be discarded.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2023-0011</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-10859</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-10859</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: git-annex, Ubuntu:18.04:LTS: git-annex&lt;/p&gt;
&lt;p&gt;git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user&amp;#39;s gpg key. This attack could be used to expose encrypted data that was never stored in git-annex&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: git-annex, Ubuntu:18.04:LTS: git-annex&lt;/p&gt;
&lt;p&gt;git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user&amp;#39;s gpg key. This attack could be used to expose encrypted data that was never stored in git-annex&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-10859</guid>
    </item>
  </channel>
</rss>
