<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:53:50 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-10678</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10678</link>
      <description>bdu:2025-10678</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10678</guid>
    </item>
    <item>
      <title>cnvd-2025-22704</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-22704</link>
      <description>cnvd-2025-22704</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-22704</guid>
    </item>
    <item>
      <title>EUVD-2026-248968</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248968</link>
      <description>EUVD-2026-248968</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248968</guid>
    </item>
    <item>
      <title>fkie_cve-2025-52901</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52901</link>
      <description>&lt;p&gt;File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.9, access tokens are used as GET parameters. The JSON Web Token (JWT) which is used as a session identifier will get leaked to anyone having access to the URLs accessed by the user. This will give an attacker full access to a user&amp;#39;s account and, in consequence, to all sensitive files the user has access to. This issue has been patched in version 2.33.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.9, access tokens are used as GET parameters. The JSON Web Token (JWT) which is used as a session identifier will get leaked to anyone having access to the URLs accessed by the user. This will give an attacker full access to a user&amp;#39;s account and, in consequence, to all sensitive files the user has access to. This issue has been patched in version 2.33.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-52901</guid>
    </item>
    <item>
      <title>GHSA-rmwh-g367-mj4x — File Browser allows sensitive data to be transferred in URL</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rmwh-g367-mj4x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;URLs that are accessed by a user are commonly logged in many locations, both server- and client-side. It is thus good practice to never transmit any secret information as part of a URL. The *Filebrowser* violates this practice, since access tokens are used as GET parameters.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The *JSON Web Token (JWT)* which is used as a session identifier will get leaked to anyone having access to the URLs accessed by the user. This will give the attacker full access to the user&amp;#39;s account and, in consequence, to all sensitive files the user has access to.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;Sensitive information in URLs is logged by several components (see the following examples), even if access is protected by TLS.&lt;/p&gt;
&lt;p&gt;* The browser history
* The access logs on the affected web server
* Proxy servers or reverse proxy servers
* Third-party servers via the HTTP referrer header&lt;/p&gt;
&lt;p&gt;In case attackers can access certain logs, they could read the included sensitive data.&lt;/p&gt;
&lt;p&gt;## Proof of Concept ##&lt;/p&gt;
&lt;p&gt;When a file is downloaded via the web interface, the JWT is part of the URL:&lt;/p&gt;
&lt;p&gt;```http
GET /api/raw/testdir/testfile.txt?auth=eyJh[...]_r4EQ HTTP/1.1
Host: filebrowser.local:8080
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Referer: http://filebrowser.local:8080/files/testdir/
Cookie: auth=eyJh[...]_r4EQ
Upgrad…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;URLs that are accessed by a user are commonly logged in many locations, both server- and client-side. It is thus good practice to never transmit any secret information as part of a URL. The *Filebrowser* violates this practice, since access tokens are used as GET parameters.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;The *JSON Web Token (JWT)* which is used as a session identifier will get leaked to anyone having access to the URLs accessed by the user. This will give the attacker full access to the user&amp;#39;s account and, in consequence, to all sensitive files the user has access to.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;Sensitive information in URLs is logged by several components (see the following examples), even if access is protected by TLS.&lt;/p&gt;
&lt;p&gt;* The browser history
* The access logs on the affected web server
* Proxy servers or reverse proxy servers
* Third-party servers via the HTTP referrer header&lt;/p&gt;
&lt;p&gt;In case attackers can access certain logs, they could read the included sensitive data.&lt;/p&gt;
&lt;p&gt;## Proof of Concept ##&lt;/p&gt;
&lt;p&gt;When a file is downloaded via the web interface, the JWT is part of the URL:&lt;/p&gt;
&lt;p&gt;```http
GET /api/raw/testdir/testfile.txt?auth=eyJh[...]_r4EQ HTTP/1.1
Host: filebrowser.local:8080
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Referer: http://filebrowser.local:8080/files/testdir/
Cookie: auth=eyJh[...]_r4EQ
Upgrad…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rmwh-g367-mj4x</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</guid>
    </item>
  </channel>
</rss>
