<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 04:08:30 +0000</lastBuildDate>
    <item>
      <title>cnvd-2022-06471</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-06471</link>
      <description>cnvd-2022-06471</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-06471</guid>
    </item>
    <item>
      <title>EUVD-2026-234504</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-234504</link>
      <description>EUVD-2026-234504</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-234504</guid>
    </item>
    <item>
      <title>fkie_cve-2022-21696</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21696</link>
      <description>&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an additional space character at the end of the name string. An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an additional space character at the end of the name string. An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-21696</guid>
    </item>
    <item>
      <title>GHSA-68vr-8f46-vc9f — Username spoofing in OnionShare</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-68vr-8f46-vc9f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;Between September 26, 2021 and October 8, 2021, [Radically Open Security](https://www.radicallyopensecurity.com/) conducted a penetration test of OnionShare 2.4, funded by the Open Technology Fund&amp;#39;s [Red Team lab](https://www.opentech.fund/labs/red-team-lab/). This is an issue from that penetration test.&lt;/p&gt;
&lt;p&gt;- Vulnerability ID: OTF-005
- Vulnerability type: Improper Input Sanitization
- Threat level: Low&lt;/p&gt;
&lt;p&gt;## Description:&lt;/p&gt;
&lt;p&gt;It is possible to change the username to that of another chat participant with an additional space character at the end of the name string.&lt;/p&gt;
&lt;p&gt;## Technical description:&lt;/p&gt;
&lt;p&gt;Assumed users in Chat:&lt;/p&gt;
&lt;p&gt;- Alice
- Bob
- Mallory&lt;/p&gt;
&lt;p&gt;1. Mallory renames to `Alice `.
2. Mallory sends message as `Alice `.
3. Alice and Bob receive a message from Mallory disguised as `Alice `, which is hard to distinguish from the `Alice`
in the web interface.&lt;/p&gt;
&lt;p&gt;![otf-005-a](https://user-images.githubusercontent.com/156128/140666112-8febd4d8-6761-41aa-955c-48be76f3c657.png)
![otf-005-b](https://user-images.githubusercontent.com/156128/140666113-1713ddf7-cef6-4dac-b718-9af1dc4ffdcd.png)&lt;/p&gt;
&lt;p&gt;Other (invisible) whitespace characters were found to be working as well.&lt;/p&gt;
&lt;p&gt;## Impact:&lt;/p&gt;
&lt;p&gt;An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username.&lt;/p&gt;
&lt;p&gt;## Recommendation:&lt;/p&gt;
&lt;p&gt;- Remove non-visible characters from the username&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;Between September 26, 2021 and October 8, 2021, [Radically Open Security](https://www.radicallyopensecurity.com/) conducted a penetration test of OnionShare 2.4, funded by the Open Technology Fund&amp;#39;s [Red Team lab](https://www.opentech.fund/labs/red-team-lab/). This is an issue from that penetration test.&lt;/p&gt;
&lt;p&gt;- Vulnerability ID: OTF-005
- Vulnerability type: Improper Input Sanitization
- Threat level: Low&lt;/p&gt;
&lt;p&gt;## Description:&lt;/p&gt;
&lt;p&gt;It is possible to change the username to that of another chat participant with an additional space character at the end of the name string.&lt;/p&gt;
&lt;p&gt;## Technical description:&lt;/p&gt;
&lt;p&gt;Assumed users in Chat:&lt;/p&gt;
&lt;p&gt;- Alice
- Bob
- Mallory&lt;/p&gt;
&lt;p&gt;1. Mallory renames to `Alice `.
2. Mallory sends message as `Alice `.
3. Alice and Bob receive a message from Mallory disguised as `Alice `, which is hard to distinguish from the `Alice`
in the web interface.&lt;/p&gt;
&lt;p&gt;![otf-005-a](https://user-images.githubusercontent.com/156128/140666112-8febd4d8-6761-41aa-955c-48be76f3c657.png)
![otf-005-b](https://user-images.githubusercontent.com/156128/140666113-1713ddf7-cef6-4dac-b718-9af1dc4ffdcd.png)&lt;/p&gt;
&lt;p&gt;Other (invisible) whitespace characters were found to be working as well.&lt;/p&gt;
&lt;p&gt;## Impact:&lt;/p&gt;
&lt;p&gt;An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username.&lt;/p&gt;
&lt;p&gt;## Recommendation:&lt;/p&gt;
&lt;p&gt;- Remove non-visible characters from the username&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-68vr-8f46-vc9f</guid>
    </item>
    <item>
      <title>gsd-2022-21696</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-21696</link>
      <description>gsd-2022-21696</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-21696</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11983-1 — python-onionshare-2.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11983-1</link>
      <description>&lt;p&gt;python-onionshare-2.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-onionshare-2.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11983-1</guid>
    </item>
    <item>
      <title>PYSEC-2022-47</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2022-47</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an additional space character at the end of the name string. An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an additional space character at the end of the name string. An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2022-47</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2022-21696</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21696</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: onionshare, Ubuntu:24.04:LTS: onionshare, Ubuntu:25.04: onionshare&lt;/p&gt;
&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an additional space character at the end of the name string. An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: onionshare, Ubuntu:24.04:LTS: onionshare, Ubuntu:25.04: onionshare&lt;/p&gt;
&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an additional space character at the end of the name string. An adversary with access to the chat environment can use the rename feature to impersonate other participants by adding whitespace characters at the end of the username.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21696</guid>
    </item>
  </channel>
</rss>
