<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:40:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-11514</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-11514</link>
      <description>bdu:2024-11514</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-11514</guid>
    </item>
    <item>
      <title>EUVD-2026-186175</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-186175</link>
      <description>EUVD-2026-186175</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-186175</guid>
    </item>
    <item>
      <title>fkie_cve-2024-45816</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45816</link>
      <description>&lt;p&gt;Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage. This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage. This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package. All users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-45816</guid>
    </item>
    <item>
      <title>GHSA-39v3-f278-vj3g — @backstage/plugin-techdocs-backend storage bucket Directory Traversal vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-39v3-f278-vj3g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @backstage/plugin-techdocs-backend&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;Open an issue in the [Backstage repository](https://github.com/backstage/backstage)
Visit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @backstage/plugin-techdocs-backend&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;Open an issue in the [Backstage repository](https://github.com/backstage/backstage)
Visit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-39v3-f278-vj3g</guid>
    </item>
    <item>
      <title>RHBA-2024:11265 — Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.4.0 release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2024:11265</link>
      <description>&lt;p&gt;http-proxy-middleware: http-proxy-middleware: Denial of Service via unhandled error during path matching cross-spawn: regular expression denial of service path-to-regexp: Backtracking regular expressions cause ReDoS body-parser: Denial of Service Vulnerability in body-parser plugin-catalog-backend: prototype pollution vulnerability plugin-techdocs-backend: storage bucket directory traversal in TechDocs plugin-techdocs-backend: circumvention of XSS protection in TechDocs backstage/plugin-app-backend: Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;http-proxy-middleware: http-proxy-middleware: Denial of Service via unhandled error during path matching cross-spawn: regular expression denial of service path-to-regexp: Backtracking regular expressions cause ReDoS body-parser: Denial of Service Vulnerability in body-parser plugin-catalog-backend: prototype pollution vulnerability plugin-techdocs-backend: storage bucket directory traversal in TechDocs plugin-techdocs-backend: circumvention of XSS protection in TechDocs backstage/plugin-app-backend: Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2024:11265</guid>
    </item>
  </channel>
</rss>
