<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:25:05 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-218617</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-218617</link>
      <description>EUVD-2026-218617</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-218617</guid>
    </item>
    <item>
      <title>fkie_cve-2025-27088</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-27088</link>
      <description>&lt;p&gt;oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, when visited, inject scripts into the web application. This can lead to session hijacking or phishing attacks on a trusted domain, posing a moderate risk to all users. It&amp;#39;s possible to inject html elements, including scripts through the folder-list template. The affected template allows users to interact with the URL path provided by the `Request.URL.Path` variable, which is then rendered directly into the HTML without proper sanitization or escaping. This can be abused by attackers who craft a malicious URL containing injected HTML or JavaScript. When users visit such a URL, the malicious script will be executed in the user&amp;#39;s context. This issue has been addressed in version 4.18.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, when visited, inject scripts into the web application. This can lead to session hijacking or phishing attacks on a trusted domain, posing a moderate risk to all users. It&amp;#39;s possible to inject html elements, including scripts through the folder-list template. The affected template allows users to interact with the URL path provided by the `Request.URL.Path` variable, which is then rendered directly into the HTML without proper sanitization or escaping. This can be abused by attackers who craft a malicious URL containing injected HTML or JavaScript. When users visit such a URL, the malicious script will be executed in the user&amp;#39;s context. This issue has been addressed in version 4.18.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-27088</guid>
    </item>
    <item>
      <title>GHSA-pp9m-qf39-hxjc — S3-Proxy allows Reflected Cross-site Scripting (XSS) in template implementation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pp9m-qf39-hxjc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/oxyno-zeta/s3-proxy/cmd/s3-proxy&lt;/p&gt;
&lt;p&gt;### Summary
A Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, when visited, inject scripts into the web application. This can lead to session hijacking or phishing attacks on a trusted domain, posing a high risk to all users.&lt;/p&gt;
&lt;p&gt;### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._
It&amp;#39;s possible to inject html elements, including scripts through the [folder-list template](https://github.com/oxyno-zeta/s3-proxy/blob/master/templates/folder-list.tpl#L19C21-L19C38). It seems like the `.Request.URL.Path` variable is not escaped.&lt;/p&gt;
&lt;p&gt;I did some research and found it might be due to the `text/template` import being used in [the template implementation](https://github.com/oxyno-zeta/s3-proxy/blob/master/pkg/s3-proxy/utils/templateutils/template.go#L8), instead of the [safer](https://pkg.go.dev/html/template) `html/template`.&lt;/p&gt;
&lt;p&gt;### PoC
_Complete instructions, including specific configuration details, to reproduce the vulnerability._
Using the [default template configuration](https://oxyno-zeta.github.io/s3-proxy/configuration/structure/#targettemplateconfig), the vulnerability can be reproduced with the following steps.&lt;/p&gt;
&lt;p&gt;1. Navigate to `https://your-s3-proxy.com/path-not-found` and confirm the page looks as follows:
![image](https://github.com/user-attachments/assets/1c87e274-18ec-4eb3-94fe-25bb1c0abf37)&lt;/p&gt;
&lt;p&gt;2. Try inserting an HTML element by changing `/path-not-fo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/oxyno-zeta/s3-proxy/cmd/s3-proxy&lt;/p&gt;
&lt;p&gt;### Summary
A Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create malicious URLs that, when visited, inject scripts into the web application. This can lead to session hijacking or phishing attacks on a trusted domain, posing a high risk to all users.&lt;/p&gt;
&lt;p&gt;### Details
_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._
It&amp;#39;s possible to inject html elements, including scripts through the [folder-list template](https://github.com/oxyno-zeta/s3-proxy/blob/master/templates/folder-list.tpl#L19C21-L19C38). It seems like the `.Request.URL.Path` variable is not escaped.&lt;/p&gt;
&lt;p&gt;I did some research and found it might be due to the `text/template` import being used in [the template implementation](https://github.com/oxyno-zeta/s3-proxy/blob/master/pkg/s3-proxy/utils/templateutils/template.go#L8), instead of the [safer](https://pkg.go.dev/html/template) `html/template`.&lt;/p&gt;
&lt;p&gt;### PoC
_Complete instructions, including specific configuration details, to reproduce the vulnerability._
Using the [default template configuration](https://oxyno-zeta.github.io/s3-proxy/configuration/structure/#targettemplateconfig), the vulnerability can be reproduced with the following steps.&lt;/p&gt;
&lt;p&gt;1. Navigate to `https://your-s3-proxy.com/path-not-found` and confirm the page looks as follows:
![image](https://github.com/user-attachments/assets/1c87e274-18ec-4eb3-94fe-25bb1c0abf37)&lt;/p&gt;
&lt;p&gt;2. Try inserting an HTML element by changing `/path-not-fo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pp9m-qf39-hxjc</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14889-1 — govulncheck-vulndb-0.0.20250312T181707-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14889-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250312T181707-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250312T181707-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14889-1</guid>
    </item>
  </channel>
</rss>
