<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:43:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-226328</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-226328</link>
      <description>EUVD-2026-226328</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-226328</guid>
    </item>
    <item>
      <title>fkie_cve-2025-31116</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-31116</link>
      <description>&lt;p&gt;Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to SSRF abuse using DNS rebinding technique. This vulnerability is fixed in 4.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to SSRF abuse using DNS rebinding technique. This vulnerability is fixed in 4.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-31116</guid>
    </item>
    <item>
      <title>GHSA-fcfq-m8p6-gw56 — Mobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS Rebinding</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fcfq-m8p6-gw56</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The latest deployed fix for the SSRF vulnerability is through the use of the call `valid_host()`. The code available at lines [/ae34f7c055aa64fca58e995b70bc7f19da6ca33a/mobsf/MobSF/utils.py#L907-L957](https://github.com/MobSF/Mobile-Security-Framework-MobSF/blob/ae34f7c055aa64fca58e995b70bc7f19da6ca33a/mobsf/MobSF/utils.py#L907-L957) is vulnerable to SSRF abuse using DNS rebinding technique.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The following proof of concept:&lt;/p&gt;
&lt;p&gt;```python
def valid_host(host):
    &amp;#34;&amp;#34;&amp;#34;Check if host is valid.&amp;#34;&amp;#34;&amp;#34;
    try:
        prefixs = (&amp;#39;http://&amp;#39;, &amp;#39;https://&amp;#39;)
        if not host.startswith(prefixs):
            host = f&amp;#39;http://{host}&amp;#39;
        parsed = urlparse(host)
        domain = parsed.netloc
        path = parsed.path
        if len(domain) == 0:
            # No valid domain
            return False, None
        if len(path) &amp;gt; 0:
            # Only host is allowed
            return False, None
        if &amp;#39;:&amp;#39; in domain:
            # IPv6
            return False, None
        # Local network
        invalid_prefix = (
            &amp;#39;100.64.&amp;#39;,
            &amp;#39;127.&amp;#39;,
            &amp;#39;192.&amp;#39;,
            &amp;#39;198.&amp;#39;,
            &amp;#39;10.&amp;#39;,
            &amp;#39;172.&amp;#39;,
            &amp;#39;169.&amp;#39;,
            &amp;#39;0.&amp;#39;,
            &amp;#39;203.0.&amp;#39;,
            &amp;#39;224.0.&amp;#39;,
            &amp;#39;240.0&amp;#39;,
            &amp;#39;255.255.&amp;#39;,
            &amp;#39;localhost&amp;#39;,
            &amp;#39;::1&amp;#39;,
            &amp;#39;64::ff9b::&amp;#39;,
            &amp;#39;100::&amp;#39;,
            &amp;#39;2001::&amp;#39;,
            &amp;#39;2002::&amp;#39;,
            &amp;#39;fc00::&amp;#39;,
            &amp;#39;fe80::&amp;#39;,
            &amp;#39;ff00::&amp;#39;)…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The latest deployed fix for the SSRF vulnerability is through the use of the call `valid_host()`. The code available at lines [/ae34f7c055aa64fca58e995b70bc7f19da6ca33a/mobsf/MobSF/utils.py#L907-L957](https://github.com/MobSF/Mobile-Security-Framework-MobSF/blob/ae34f7c055aa64fca58e995b70bc7f19da6ca33a/mobsf/MobSF/utils.py#L907-L957) is vulnerable to SSRF abuse using DNS rebinding technique.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;The following proof of concept:&lt;/p&gt;
&lt;p&gt;```python
def valid_host(host):
    &amp;#34;&amp;#34;&amp;#34;Check if host is valid.&amp;#34;&amp;#34;&amp;#34;
    try:
        prefixs = (&amp;#39;http://&amp;#39;, &amp;#39;https://&amp;#39;)
        if not host.startswith(prefixs):
            host = f&amp;#39;http://{host}&amp;#39;
        parsed = urlparse(host)
        domain = parsed.netloc
        path = parsed.path
        if len(domain) == 0:
            # No valid domain
            return False, None
        if len(path) &amp;gt; 0:
            # Only host is allowed
            return False, None
        if &amp;#39;:&amp;#39; in domain:
            # IPv6
            return False, None
        # Local network
        invalid_prefix = (
            &amp;#39;100.64.&amp;#39;,
            &amp;#39;127.&amp;#39;,
            &amp;#39;192.&amp;#39;,
            &amp;#39;198.&amp;#39;,
            &amp;#39;10.&amp;#39;,
            &amp;#39;172.&amp;#39;,
            &amp;#39;169.&amp;#39;,
            &amp;#39;0.&amp;#39;,
            &amp;#39;203.0.&amp;#39;,
            &amp;#39;224.0.&amp;#39;,
            &amp;#39;240.0&amp;#39;,
            &amp;#39;255.255.&amp;#39;,
            &amp;#39;localhost&amp;#39;,
            &amp;#39;::1&amp;#39;,
            &amp;#39;64::ff9b::&amp;#39;,
            &amp;#39;100::&amp;#39;,
            &amp;#39;2001::&amp;#39;,
            &amp;#39;2002::&amp;#39;,
            &amp;#39;fc00::&amp;#39;,
            &amp;#39;fe80::&amp;#39;,
            &amp;#39;ff00::&amp;#39;)…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fcfq-m8p6-gw56</guid>
    </item>
    <item>
      <title>PYSEC-2025-48</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2025-48</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to SSRF abuse using DNS rebinding technique. This vulnerability is fixed in 4.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mobsf&lt;/p&gt;
&lt;p&gt;Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to SSRF abuse using DNS rebinding technique. This vulnerability is fixed in 4.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2025-48</guid>
    </item>
  </channel>
</rss>
