<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 05:33:58 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-17196</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-17196</link>
      <description>cnvd-2020-17196</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-17196</guid>
    </item>
    <item>
      <title>EUVD-2026-57898</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-57898</link>
      <description>EUVD-2026-57898</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-57898</guid>
    </item>
    <item>
      <title>fkie_cve-2019-16676</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-16676</link>
      <description>&lt;p&gt;Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-16676</guid>
    </item>
    <item>
      <title>GHSA-r74q-gxcg-73hx — Improper Input Validation in simple_form</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r74q-gxcg-73hx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: simple_form&lt;/p&gt;
&lt;p&gt;## Incorrect Access Control in `file_method?` in `lib/simple_form/form_builder.rb`; a user-supplied string is invoked as a method call&lt;/p&gt;
&lt;p&gt;### Impact
For pages that build a form using user input, it is possible for an attacker to manipulate the input and send any method present in the form object. For example:&lt;/p&gt;
&lt;p&gt;```erb
&amp;lt;%= simple_form_for @user do |f| %&amp;gt;
  &amp;lt;%= f.label @user_supplied_string %&amp;gt;
  ...
&amp;lt;% end %&amp;gt;
```&lt;/p&gt;
&lt;p&gt;The string provided in the variable `@user_supplied_string` would be invoked as a method call inside the `@user` object (unless the string contains any of the following: `password`, `time_zone`, `country`, `email`, `phone` and `url`).&lt;/p&gt;
&lt;p&gt;By manipulation that input, an attacker could do any of the following:&lt;/p&gt;
&lt;p&gt;- Code execution (call actions like `#destroy`)
- Denial of Service (by executing a computation intensive method)
- Information Disclosure (check the presence of methods, leak user information)&lt;/p&gt;
&lt;p&gt;### Patches
The problem was fixed in version `5.0`. Although it&amp;#39;s a major version, there should be no issues with upgrading for `4.x`. The reason it was released in a major version is that the configuration `SimpleForm.file_methods` was deprecated in order to fix the problem.&lt;/p&gt;
&lt;p&gt;### Workarounds
The issue only happens with pages that build forms based on user-provided input. If your application doesn&amp;#39;t do that, you&amp;#39;re not affected.
A workaround is to explicitly pass which type you want for an input since the issue lies on Simple Form&amp;#39;s automatically discovery of input types. This…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: simple_form&lt;/p&gt;
&lt;p&gt;## Incorrect Access Control in `file_method?` in `lib/simple_form/form_builder.rb`; a user-supplied string is invoked as a method call&lt;/p&gt;
&lt;p&gt;### Impact
For pages that build a form using user input, it is possible for an attacker to manipulate the input and send any method present in the form object. For example:&lt;/p&gt;
&lt;p&gt;```erb
&amp;lt;%= simple_form_for @user do |f| %&amp;gt;
  &amp;lt;%= f.label @user_supplied_string %&amp;gt;
  ...
&amp;lt;% end %&amp;gt;
```&lt;/p&gt;
&lt;p&gt;The string provided in the variable `@user_supplied_string` would be invoked as a method call inside the `@user` object (unless the string contains any of the following: `password`, `time_zone`, `country`, `email`, `phone` and `url`).&lt;/p&gt;
&lt;p&gt;By manipulation that input, an attacker could do any of the following:&lt;/p&gt;
&lt;p&gt;- Code execution (call actions like `#destroy`)
- Denial of Service (by executing a computation intensive method)
- Information Disclosure (check the presence of methods, leak user information)&lt;/p&gt;
&lt;p&gt;### Patches
The problem was fixed in version `5.0`. Although it&amp;#39;s a major version, there should be no issues with upgrading for `4.x`. The reason it was released in a major version is that the configuration `SimpleForm.file_methods` was deprecated in order to fix the problem.&lt;/p&gt;
&lt;p&gt;### Workarounds
The issue only happens with pages that build forms based on user-provided input. If your application doesn&amp;#39;t do that, you&amp;#39;re not affected.
A workaround is to explicitly pass which type you want for an input since the issue lies on Simple Form&amp;#39;s automatically discovery of input types. This…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r74q-gxcg-73hx</guid>
    </item>
    <item>
      <title>gsd-2019-16676</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-16676</link>
      <description>gsd-2019-16676</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-16676</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-16676</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16676</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-simple-form, Ubuntu:18.04:LTS: ruby-simple-form&lt;/p&gt;
&lt;p&gt;Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-simple-form, Ubuntu:18.04:LTS: ruby-simple-form&lt;/p&gt;
&lt;p&gt;Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16676</guid>
    </item>
  </channel>
</rss>
