<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 15:16:46 +0000</lastBuildDate>
    <item>
      <title>cnvd-2021-95242</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-95242</link>
      <description>cnvd-2021-95242</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-95242</guid>
    </item>
    <item>
      <title>EUVD-2026-32608</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-32608</link>
      <description>EUVD-2026-32608</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-32608</guid>
    </item>
    <item>
      <title>fkie_cve-2021-43780</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43780</link>
      <description>&lt;p&gt;Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading data sources like JSON, CSV, or Excel is vulnerable to advanced methods of Server Side Request Forgery (SSRF). These vulnerabilities are only exploitable on installations where a URL-loading data source is enabled. As of time of publication, the `master` and `release/10.x.x` branches address this by applying the Advocate library for making http requests instead of the requests library directly. Users should upgrade to version 10.0.1 to receive this patch. There are a few workarounds for mitigating the vulnerability without upgrading. One can disable the vulnerable data sources entirely, by adding the following env variable to one&amp;#39;s configuration, making them unavailable inside the webapp. One can switch any data source of certain types (viewable in the GitHub Security Advisory) to be `View Only` for all groups on the Settings &amp;gt; Groups &amp;gt; Data Sources screen. For users unable to update an admin may modify Redash&amp;#39;s configuration through environment variables to mitigate this issue. Depending on the version of Redash, an admin may also need to run a CLI command to re-encrypt some fields in the database. The `master` and `release/10.x.x` branches as of time of publication have removed the default value for `REDASH_COOKIE_SECRET`. All future releases will also require this to be set explicitly. For existing installations, one will need to ensure that explicit value…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading data sources like JSON, CSV, or Excel is vulnerable to advanced methods of Server Side Request Forgery (SSRF). These vulnerabilities are only exploitable on installations where a URL-loading data source is enabled. As of time of publication, the `master` and `release/10.x.x` branches address this by applying the Advocate library for making http requests instead of the requests library directly. Users should upgrade to version 10.0.1 to receive this patch. There are a few workarounds for mitigating the vulnerability without upgrading. One can disable the vulnerable data sources entirely, by adding the following env variable to one&amp;#39;s configuration, making them unavailable inside the webapp. One can switch any data source of certain types (viewable in the GitHub Security Advisory) to be `View Only` for all groups on the Settings &amp;gt; Groups &amp;gt; Data Sources screen. For users unable to update an admin may modify Redash&amp;#39;s configuration through environment variables to mitigate this issue. Depending on the version of Redash, an admin may also need to run a CLI command to re-encrypt some fields in the database. The `master` and `release/10.x.x` branches as of time of publication have removed the default value for `REDASH_COOKIE_SECRET`. All future releases will also require this to be set explicitly. For existing installations, one will need to ensure that explicit value…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-43780</guid>
    </item>
    <item>
      <title>gsd-2021-43780</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-43780</link>
      <description>gsd-2021-43780</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-43780</guid>
    </item>
  </channel>
</rss>
