<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:14:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-4497</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-4497</link>
      <description>EUVD-2026-4497</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-4497</guid>
    </item>
    <item>
      <title>fkie_cve-2024-28232</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-28232</link>
      <description>&lt;p&gt;Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in version 0.4.8 but that version has not yet been uploaded to Go&amp;#39;s package manager.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in version 0.4.8 but that version has not yet been uploaded to Go&amp;#39;s package manager.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-28232</guid>
    </item>
    <item>
      <title>GHSA-hcw2-2r9c-gc6p — CasaOS Username Enumeration - Bypass of CVE-2024-24766</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hcw2-2r9c-gc6p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/IceWhaleTech/CasaOS-UserService&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in `CasaOS  v0.4.7`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;It is observed that the attacker can enumerate the CasaOS username using the application response. If the username is incorrect the application gives the error &amp;#34;**User does not exist**&amp;#34; with success code &amp;#34;**10006**&amp;#34;, If the password is incorrect the application gives the error &amp;#34;**User does not exist or password is invalid**&amp;#34; with success code &amp;#34;**10013**&amp;#34;.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. If the Username is invalid application gives &amp;#34;User does not exist&amp;#34; with success code &amp;#34;**10006**&amp;#34;.&lt;/p&gt;
&lt;p&gt;![1](https://github.com/IceWhaleTech/CasaOS-UserService/assets/63414468/a6eb4321-b2f3-4fba-aa8e-e1d0fbf58187)&lt;/p&gt;
&lt;p&gt;2. If the Password is invalid application gives  &amp;#34;**User does not exist or password is invalid**&amp;#34; with success code &amp;#34;**10013**&amp;#34;.&lt;/p&gt;
&lt;p&gt;![2](https://github.com/IceWhaleTech/CasaOS-UserService/assets/63414468/126eff54-eeb0-4ee6-bc46-695376b5e5cd)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Using this error attacker can enumerate the username of CasaOS.&lt;/p&gt;
&lt;p&gt;### The logic behind the issue&lt;/p&gt;
&lt;p&gt;The logic behind the issue
If the username is incorrect, then throw an error  &amp;#34;**User does not exist**&amp;#34; with success code &amp;#34;**10006**&amp;#34;, else throw an error &amp;#34;**User does not exist or password is invalid**&amp;#34; with success code &amp;#34;**10013**&amp;#34;.&lt;/p&gt;
&lt;p&gt;This condition can be vice versa like:&lt;/p&gt;
&lt;p&gt;If the password is incorrect, then throw an error &amp;#34;**User does not exist or password is invalid**&amp;#34; with success code &amp;#34;**10013**&amp;#34;, e…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/IceWhaleTech/CasaOS-UserService&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in `CasaOS  v0.4.7`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;It is observed that the attacker can enumerate the CasaOS username using the application response. If the username is incorrect the application gives the error &amp;#34;**User does not exist**&amp;#34; with success code &amp;#34;**10006**&amp;#34;, If the password is incorrect the application gives the error &amp;#34;**User does not exist or password is invalid**&amp;#34; with success code &amp;#34;**10013**&amp;#34;.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. If the Username is invalid application gives &amp;#34;User does not exist&amp;#34; with success code &amp;#34;**10006**&amp;#34;.&lt;/p&gt;
&lt;p&gt;![1](https://github.com/IceWhaleTech/CasaOS-UserService/assets/63414468/a6eb4321-b2f3-4fba-aa8e-e1d0fbf58187)&lt;/p&gt;
&lt;p&gt;2. If the Password is invalid application gives  &amp;#34;**User does not exist or password is invalid**&amp;#34; with success code &amp;#34;**10013**&amp;#34;.&lt;/p&gt;
&lt;p&gt;![2](https://github.com/IceWhaleTech/CasaOS-UserService/assets/63414468/126eff54-eeb0-4ee6-bc46-695376b5e5cd)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Using this error attacker can enumerate the username of CasaOS.&lt;/p&gt;
&lt;p&gt;### The logic behind the issue&lt;/p&gt;
&lt;p&gt;The logic behind the issue
If the username is incorrect, then throw an error  &amp;#34;**User does not exist**&amp;#34; with success code &amp;#34;**10006**&amp;#34;, else throw an error &amp;#34;**User does not exist or password is invalid**&amp;#34; with success code &amp;#34;**10013**&amp;#34;.&lt;/p&gt;
&lt;p&gt;This condition can be vice versa like:&lt;/p&gt;
&lt;p&gt;If the password is incorrect, then throw an error &amp;#34;**User does not exist or password is invalid**&amp;#34; with success code &amp;#34;**10013**&amp;#34;, e…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hcw2-2r9c-gc6p</guid>
    </item>
    <item>
      <title>gsd-2024-28232</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-28232</link>
      <description>gsd-2024-28232</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-28232</guid>
    </item>
  </channel>
</rss>
