<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:52:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-07268</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-07268</link>
      <description>bdu:2023-07268</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-07268</guid>
    </item>
    <item>
      <title>BIT-wiremock-2023-41327 — Controlled SSRF through URL in the WireMock</title>
      <link>https://cve.radiocsirt.org/vuln/bit-wiremock-2023-41327</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: wiremock&lt;/p&gt;
&lt;p&gt;WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first.&lt;/p&gt;
&lt;p&gt;Until WireMock Webhooks Extension 3.0.0, the filtering of target addresses from the proxy mode DID NOT work for Webhooks, so the users were potentially vulnerable regardless of the `limitProxyTargets` settings. Via the WireMock webhooks configuration, POST requests from a webhook might be forwarded to an arbitrary service reachable from WireMock’s instance. For example, If someone is running the WireMock docker Container inside a private cluster, they can trigger internal POST requests against unsecured APIs or even against secure ones by passing a token, discovered using another exploit, via authentication headers. This issue has been addressed in versions 2.35.1 and 3.0.3 of wiremock. Wiremock studio has been discontinued and will not see a fix. Users unable to upgrade should use external firewall rules to define the list of permitted destinations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: wiremock&lt;/p&gt;
&lt;p&gt;WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first.&lt;/p&gt;
&lt;p&gt;Until WireMock Webhooks Extension 3.0.0, the filtering of target addresses from the proxy mode DID NOT work for Webhooks, so the users were potentially vulnerable regardless of the `limitProxyTargets` settings. Via the WireMock webhooks configuration, POST requests from a webhook might be forwarded to an arbitrary service reachable from WireMock’s instance. For example, If someone is running the WireMock docker Container inside a private cluster, they can trigger internal POST requests against unsecured APIs or even against secure ones by passing a token, discovered using another exploit, via authentication headers. This issue has been addressed in versions 2.35.1 and 3.0.3 of wiremock. Wiremock studio has been discontinued and will not see a fix. Users unable to upgrade should use external firewall rules to define the list of permitted destinations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-wiremock-2023-41327</guid>
    </item>
    <item>
      <title>EUVD-2026-188900</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-188900</link>
      <description>EUVD-2026-188900</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-188900</guid>
    </item>
    <item>
      <title>fkie_cve-2023-41327</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-41327</link>
      <description>&lt;p&gt;WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first.&lt;/p&gt;
&lt;p&gt;Until WireMock Webhooks Extension 3.0.0-beta-15, the filtering of target addresses from the proxy mode DID NOT work for Webhooks, so the users were potentially vulnerable regardless of the `limitProxyTargets` settings. Via the WireMock webhooks configuration, POST requests from a webhook might be forwarded to an arbitrary service reachable from WireMock’s instance. For example, If someone is running the WireMock docker Container inside a private cluster, they can trigger internal POST requests against unsecured APIs or even against secure ones by passing a token, discovered using another exploit, via authentication headers. This issue has been addressed in versions 2.35.1 and 3.0.3 of wiremock. Wiremock studio has been discontinued and will not see a fix. Users unable to upgrade should use external firewall rules to define the list of permitted destinations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WireMock is a tool for mocking HTTP services. WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first.&lt;/p&gt;
&lt;p&gt;Until WireMock Webhooks Extension 3.0.0-beta-15, the filtering of target addresses from the proxy mode DID NOT work for Webhooks, so the users were potentially vulnerable regardless of the `limitProxyTargets` settings. Via the WireMock webhooks configuration, POST requests from a webhook might be forwarded to an arbitrary service reachable from WireMock’s instance. For example, If someone is running the WireMock docker Container inside a private cluster, they can trigger internal POST requests against unsecured APIs or even against secure ones by passing a token, discovered using another exploit, via authentication headers. This issue has been addressed in versions 2.35.1 and 3.0.3 of wiremock. Wiremock studio has been discontinued and will not see a fix. Users unable to upgrade should use external firewall rules to define the list of permitted destinations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-41327</guid>
    </item>
    <item>
      <title>GHSA-hq8w-9w8w-pmx7 — WireMock Controlled Server Side Request Forgery vulnerability through URL</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hq8w-9w8w-pmx7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.wiremock:wiremock-webhooks-extension&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first. [Documentation](https://wiremock.org/docs/configuration/#preventing-proxying-to-and-recording-from-specific-target-addresses).&lt;/p&gt;
&lt;p&gt;Until WireMock Webhooks Extension [3.0.0-beta-15](https://github.com/wiremock/wiremock/releases/tag/3.0.0-beta-15), the filtering of target addresses from the proxy mode DID NOT work for Webhooks, so the users were potentially vulnerable regardless of the `limitProxyTargets` settings.&lt;/p&gt;
&lt;p&gt;Via the WireMock webhooks configuration, POST requests from a webhook might be forwarded to an arbitrary service reachable from WireMock’s instance. For example, If someone is running the WireMock docker Container inside a private cluster, they can trigger internal POST requests against unsecured APIs or even against secure ones by passing a token, discovered using another exploit, via authentication headers.&lt;/p&gt;
&lt;p&gt;### Affected  components&lt;/p&gt;
&lt;p&gt;- WireMock Webhooks Extension 2.x versions until 2.35.1 (security patch)
- WireMock 3.x version until 3.0.3 (security patch)
- All versions of WireMock Studio (discontinued). This distribution bundles the WireMock Webhooks Extension and activates it by default&lt;/p&gt;
&lt;p&gt;### Patches and Mitigation&lt;/p&gt;
&lt;p&gt;- For WireMock 2.x and 3.x - upgrade to the versions with the security patches
- Setup network restrictions s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.wiremock:wiremock-webhooks-extension&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;WireMock can be configured to only permit proxying (and therefore recording) to certain addresses. This is achieved via a list of allowed address rules and a list of denied address rules, where the allowed list is evaluated first. [Documentation](https://wiremock.org/docs/configuration/#preventing-proxying-to-and-recording-from-specific-target-addresses).&lt;/p&gt;
&lt;p&gt;Until WireMock Webhooks Extension [3.0.0-beta-15](https://github.com/wiremock/wiremock/releases/tag/3.0.0-beta-15), the filtering of target addresses from the proxy mode DID NOT work for Webhooks, so the users were potentially vulnerable regardless of the `limitProxyTargets` settings.&lt;/p&gt;
&lt;p&gt;Via the WireMock webhooks configuration, POST requests from a webhook might be forwarded to an arbitrary service reachable from WireMock’s instance. For example, If someone is running the WireMock docker Container inside a private cluster, they can trigger internal POST requests against unsecured APIs or even against secure ones by passing a token, discovered using another exploit, via authentication headers.&lt;/p&gt;
&lt;p&gt;### Affected  components&lt;/p&gt;
&lt;p&gt;- WireMock Webhooks Extension 2.x versions until 2.35.1 (security patch)
- WireMock 3.x version until 3.0.3 (security patch)
- All versions of WireMock Studio (discontinued). This distribution bundles the WireMock Webhooks Extension and activates it by default&lt;/p&gt;
&lt;p&gt;### Patches and Mitigation&lt;/p&gt;
&lt;p&gt;- For WireMock 2.x and 3.x - upgrade to the versions with the security patches
- Setup network restrictions s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hq8w-9w8w-pmx7</guid>
    </item>
    <item>
      <title>gsd-2023-41327</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-41327</link>
      <description>gsd-2023-41327</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-41327</guid>
    </item>
  </channel>
</rss>
