<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:17:36 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-4680</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-4680</link>
      <description>EUVD-2026-4680</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-4680</guid>
    </item>
    <item>
      <title>fkie_cve-2024-29886</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-29886</link>
      <description>&lt;p&gt;Serverpod is an app and web server, built for the Flutter and Dart ecosystem. An issue was identified with the old password hash algorithm that made it susceptible to rainbow attacks if the database was compromised. This vulnerability is fixed by 1.2.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Serverpod is an app and web server, built for the Flutter and Dart ecosystem. An issue was identified with the old password hash algorithm that made it susceptible to rainbow attacks if the database was compromised. This vulnerability is fixed by 1.2.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-29886</guid>
    </item>
    <item>
      <title>GHSA-r75m-26cq-mjxc — Serverpod improved security for stored password hashes</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r75m-26cq-mjxc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Pub: serverpod_auth_server&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;### Improved security for stored password hashes
Serverpod now uses the OWASP, [source](https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#introduction), recommended Argon2Id password hash algorithm to store password hashes for the email authentication module.&lt;/p&gt;
&lt;p&gt;Starting from Serverpod `1.2.6` all users that either creates an account or authenticates with the server will have their password stored using the safer algorithm. No changes are required from the developer to start storing passwords using the safer algorithm.&lt;/p&gt;
&lt;p&gt;### Why did we change how passwords are stored?
An issue was identified with the old password hash algorithm that made it susceptible to rainbow attacks if the database was compromised.&lt;/p&gt;
&lt;p&gt;It is strongly recommended to migrate your existing password hashes.&lt;/p&gt;
&lt;p&gt;### Migrate existing password hashes
The email authentication module provides a helper method to migrate all the existing legacy password hashes in the database. Simply call  `Emails.migrateLegacyPasswordHashes(...)` with a session instance as an argument to migrate the password hashes.&lt;/p&gt;
&lt;p&gt;The method is implemented as an idempotent operation and will yield the same result regardless of how many times it is called.&lt;/p&gt;
&lt;p&gt;We recommend either implementing a web server route that can be called remotely or by calling the method as part of starting the server.&lt;/p&gt;
&lt;p&gt;Following is example code for implementing a web server route.&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;&amp;lt;summary&amp;gt;&amp;lt;h4&amp;gt;Web server route code&amp;lt;/h4&amp;gt;&amp;lt;/su…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Pub: serverpod_auth_server&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;### Improved security for stored password hashes
Serverpod now uses the OWASP, [source](https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#introduction), recommended Argon2Id password hash algorithm to store password hashes for the email authentication module.&lt;/p&gt;
&lt;p&gt;Starting from Serverpod `1.2.6` all users that either creates an account or authenticates with the server will have their password stored using the safer algorithm. No changes are required from the developer to start storing passwords using the safer algorithm.&lt;/p&gt;
&lt;p&gt;### Why did we change how passwords are stored?
An issue was identified with the old password hash algorithm that made it susceptible to rainbow attacks if the database was compromised.&lt;/p&gt;
&lt;p&gt;It is strongly recommended to migrate your existing password hashes.&lt;/p&gt;
&lt;p&gt;### Migrate existing password hashes
The email authentication module provides a helper method to migrate all the existing legacy password hashes in the database. Simply call  `Emails.migrateLegacyPasswordHashes(...)` with a session instance as an argument to migrate the password hashes.&lt;/p&gt;
&lt;p&gt;The method is implemented as an idempotent operation and will yield the same result regardless of how many times it is called.&lt;/p&gt;
&lt;p&gt;We recommend either implementing a web server route that can be called remotely or by calling the method as part of starting the server.&lt;/p&gt;
&lt;p&gt;Following is example code for implementing a web server route.&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;&amp;lt;summary&amp;gt;&amp;lt;h4&amp;gt;Web server route code&amp;lt;/h4&amp;gt;&amp;lt;/su…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r75m-26cq-mjxc</guid>
    </item>
    <item>
      <title>gsd-2024-29886</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-29886</link>
      <description>gsd-2024-29886</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-29886</guid>
    </item>
  </channel>
</rss>
