<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:53:18 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-22200</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-22200</link>
      <description>EUVD-2026-22200</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-22200</guid>
    </item>
    <item>
      <title>fkie_cve-2021-21428</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-21428</link>
      <description>&lt;p&gt;Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. openapi-generator-online creates insecure temporary folders with File.createTempFile during the code generation process. The insecure temporary folders store the auto-generated files which can be read and appended to by any users on the system. The issue has been patched with `Files.createTempFile` and released in the v5.1.0 stable version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. openapi-generator-online creates insecure temporary folders with File.createTempFile during the code generation process. The insecure temporary folders store the auto-generated files which can be read and appended to by any users on the system. The issue has been patched with `Files.createTempFile` and released in the v5.1.0 stable version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-21428</guid>
    </item>
    <item>
      <title>GHSA-23x4-m842-fmwf — Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generator</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-23x4-m842-fmwf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.openapitools:openapi-generator-online&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;On Unix like systems, the system&amp;#39;s temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory.&lt;/p&gt;
&lt;p&gt;This vulnerability is local privilege escalation because the contents of the outputFolder can be appended to by an attacker. As such, code written to this directory, when executed can be attacker controlled.&lt;/p&gt;
&lt;p&gt;openapi-generator-online creates insecure temporary folders with `File.createTempFile` during the code generation process. The insecure temporary folders store the auto-generated files which can be read and appended to by any users on the system.&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;https://github.com/OpenAPITools/openapi-generator/blob/c6530519975341d7784a252132b2f0854f488901/modules/openapi-generator-online/src/main/java/org/openapitools/codegen/online/service/Generator.java#L184-L187&lt;/p&gt;
&lt;p&gt;This vulnerability exists due to a race condition between the deletion of the randomly generated temporary file and the creation of the temporary directory.&lt;/p&gt;
&lt;p&gt;```java
File outputFolder = File.createTempFile(&amp;#34;codegen-&amp;#34;, &amp;#34;-tmp&amp;#34;); // Attacker knows the full path of the file that will be generated
// delete the file that was created
outputFolder.delete(); // Attacker sees file is deleted and begins a race to create their own directory before the code generator
// and make a directory of the same name
// SECURITY VULNERAB…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.openapitools:openapi-generator-online&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;On Unix like systems, the system&amp;#39;s temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to complete the creation of the temporary subdirectory.&lt;/p&gt;
&lt;p&gt;This vulnerability is local privilege escalation because the contents of the outputFolder can be appended to by an attacker. As such, code written to this directory, when executed can be attacker controlled.&lt;/p&gt;
&lt;p&gt;openapi-generator-online creates insecure temporary folders with `File.createTempFile` during the code generation process. The insecure temporary folders store the auto-generated files which can be read and appended to by any users on the system.&lt;/p&gt;
&lt;p&gt;### Vulnerable Code&lt;/p&gt;
&lt;p&gt;https://github.com/OpenAPITools/openapi-generator/blob/c6530519975341d7784a252132b2f0854f488901/modules/openapi-generator-online/src/main/java/org/openapitools/codegen/online/service/Generator.java#L184-L187&lt;/p&gt;
&lt;p&gt;This vulnerability exists due to a race condition between the deletion of the randomly generated temporary file and the creation of the temporary directory.&lt;/p&gt;
&lt;p&gt;```java
File outputFolder = File.createTempFile(&amp;#34;codegen-&amp;#34;, &amp;#34;-tmp&amp;#34;); // Attacker knows the full path of the file that will be generated
// delete the file that was created
outputFolder.delete(); // Attacker sees file is deleted and begins a race to create their own directory before the code generator
// and make a directory of the same name
// SECURITY VULNERAB…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-23x4-m842-fmwf</guid>
    </item>
    <item>
      <title>gsd-2021-21428</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-21428</link>
      <description>gsd-2021-21428</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-21428</guid>
    </item>
  </channel>
</rss>
