<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:56:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-31633</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-31633</link>
      <description>EUVD-2026-31633</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-31633</guid>
    </item>
    <item>
      <title>fkie_cve-2021-41275</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41275</link>
      <description>&lt;p&gt;spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by using an underlying Devise authentication framework. In affected versions spree_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of spree_auth_devise are affected if protect_from_forgery method is both: Executed whether as: A before_action callback (the default). A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find). Configured to use :null_session or :reset_session strategies (:null_session is the default in case the no strategy is given, but rails --new generated skeleton use :exception). Users are advised to update their spree_auth_devise gem. For users unable to update it may be possible to change your strategy to :exception. Please see the linked GHSA for more workaround details. ### Impact CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of `spree_auth_devise` are affected if `protect_from_forgery` method is both: * Executed whether as: * A before_action callback (the default) * A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find). * Configured to use :null_session or :reset_session strategies (:null_sessio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by using an underlying Devise authentication framework. In affected versions spree_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of spree_auth_devise are affected if protect_from_forgery method is both: Executed whether as: A before_action callback (the default). A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find). Configured to use :null_session or :reset_session strategies (:null_session is the default in case the no strategy is given, but rails --new generated skeleton use :exception). Users are advised to update their spree_auth_devise gem. For users unable to update it may be possible to change your strategy to :exception. Please see the linked GHSA for more workaround details. ### Impact CSRF vulnerability that allows user account takeover. All applications using any version of the frontend component of `spree_auth_devise` are affected if `protect_from_forgery` method is both: * Executed whether as: * A before_action callback (the default) * A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find). * Configured to use :null_session or :reset_session strategies (:null_sessio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-41275</guid>
    </item>
    <item>
      <title>GHSA-26xx-m4q2-xhq8 — Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-26xx-m4q2-xhq8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: spree_auth_devise&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;CSRF vulnerability that allows user account takeover.&lt;/p&gt;
&lt;p&gt;All applications using any version of the frontend component of `spree_auth_devise` are affected if `protect_from_forgery` method is both:&lt;/p&gt;
&lt;p&gt;* Executed whether as:
  * A before_action callback (the default)
  * A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find).
* Configured to use :null_session or :reset_session strategies (:null_session is the default in case the no strategy is given, but rails --new generated skeleton use :exception).&lt;/p&gt;
&lt;p&gt;That means that applications that haven&amp;#39;t been configured differently from what it&amp;#39;s generated with Rails aren&amp;#39;t affected.&lt;/p&gt;
&lt;p&gt;Thanks @waiting-for-dev for reporting and providing a patch 👏&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Spree 4.3 users should update to spree_auth_devise 4.4.1
Spree 4.2 users should update to spree_auth_devise 4.2.1
Spree 4.1 users should update to spree_auth_devise 4.1.1
Older Spree version users should update to spree_auth_devise 4.0.1
 
### Workarounds&lt;/p&gt;
&lt;p&gt;If possible, change your strategy to :exception:&lt;/p&gt;
&lt;p&gt;```ruby
class ApplicationController &amp;lt; ActionController::Base
  protect_from_forgery with: :exception
end
```&lt;/p&gt;
&lt;p&gt;Add the following to`config/application.rb `to at least run the `:exception` strategy on the affected controller:&lt;/p&gt;
&lt;p&gt;```ruby
config.after_initialize do
  Spree::UsersController.protect_from_forgery with: :exception
end
```&lt;/p&gt;
&lt;p&gt;### References
https://github.com/solidusio/solidus_auth_devise/se…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: spree_auth_devise&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;CSRF vulnerability that allows user account takeover.&lt;/p&gt;
&lt;p&gt;All applications using any version of the frontend component of `spree_auth_devise` are affected if `protect_from_forgery` method is both:&lt;/p&gt;
&lt;p&gt;* Executed whether as:
  * A before_action callback (the default)
  * A prepend_before_action (option prepend: true given) before the :load_object hook in Spree::UserController (most likely order to find).
* Configured to use :null_session or :reset_session strategies (:null_session is the default in case the no strategy is given, but rails --new generated skeleton use :exception).&lt;/p&gt;
&lt;p&gt;That means that applications that haven&amp;#39;t been configured differently from what it&amp;#39;s generated with Rails aren&amp;#39;t affected.&lt;/p&gt;
&lt;p&gt;Thanks @waiting-for-dev for reporting and providing a patch 👏&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Spree 4.3 users should update to spree_auth_devise 4.4.1
Spree 4.2 users should update to spree_auth_devise 4.2.1
Spree 4.1 users should update to spree_auth_devise 4.1.1
Older Spree version users should update to spree_auth_devise 4.0.1
 
### Workarounds&lt;/p&gt;
&lt;p&gt;If possible, change your strategy to :exception:&lt;/p&gt;
&lt;p&gt;```ruby
class ApplicationController &amp;lt; ActionController::Base
  protect_from_forgery with: :exception
end
```&lt;/p&gt;
&lt;p&gt;Add the following to`config/application.rb `to at least run the `:exception` strategy on the affected controller:&lt;/p&gt;
&lt;p&gt;```ruby
config.after_initialize do
  Spree::UsersController.protect_from_forgery with: :exception
end
```&lt;/p&gt;
&lt;p&gt;### References
https://github.com/solidusio/solidus_auth_devise/se…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-26xx-m4q2-xhq8</guid>
    </item>
    <item>
      <title>gsd-2021-41275</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-41275</link>
      <description>gsd-2021-41275</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-41275</guid>
    </item>
  </channel>
</rss>
