<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:29:41 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0652 — Une vulnérabilité a été découverte dans  dans le greffon "WASM Client" pour Traefik. Elle permet à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0652</link>
      <description>certfr-2025-avi-0652</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0652</guid>
    </item>
    <item>
      <title>EUVD-2026-248956</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248956</link>
      <description>EUVD-2026-248956</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248956</guid>
    </item>
    <item>
      <title>fkie_cve-2025-54386</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54386</link>
      <description>&lt;p&gt;Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability was discovered in WASM Traefik’s plugin installation mechanism. By supplying a maliciously crafted ZIP archive containing file paths with ../ sequences, an attacker can overwrite arbitrary files on the system outside of the intended plugin directory. This can lead to remote code execution (RCE), privilege escalation, persistence, or denial of service. This is fixed in versions 2.11.28, 3.4.5 and 3.5.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability was discovered in WASM Traefik’s plugin installation mechanism. By supplying a maliciously crafted ZIP archive containing file paths with ../ sequences, an attacker can overwrite arbitrary files on the system outside of the intended plugin directory. This can lead to remote code execution (RCE), privilege escalation, persistence, or denial of service. This is fixed in versions 2.11.28, 3.4.5 and 3.5.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-54386</guid>
    </item>
    <item>
      <title>GHSA-q6gg-9f92-r9wg — Traefik Client Plugin's Path Traversal Vulnerability Allows Arbitrary File Overwrite and Remote Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q6gg-9f92-r9wg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;### Summary
A path traversal vulnerability was discovered in WASM Traefik’s plugin installation mechanism. By supplying a maliciously crafted ZIP archive containing file paths with `../` sequences, an attacker can overwrite arbitrary files on the system outside of the intended plugin directory. This can lead to remote code execution (RCE), privilege escalation, persistence, or denial of service.
 **✅ After investigation, it is confirmed that no plugins on the [Catalog](https://plugins.traefik.io/plugins) were affected. There is no known impact.**&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability resides in the WASM plugin extraction logic, specifically in the `unzipFile` function (`/plugins/client.go`). The application constructs file paths during ZIP extraction using `filepath.Join(destDir, f.Name)` without validating or sanitizing `f.Name`. If the ZIP archive contains entries with `../`, the resulting path can escape the intended directory, allowing writes to arbitrary locations on the host filesystem.&lt;/p&gt;
&lt;p&gt;### Attack Requirements
There are several requirements needed to make this attack possible:
- The Traefik server should be deployed with [plugins enabled](https://doc.traefik.io/traefik/plugins/) with a WASM plugin (yaegi plugins are not impacted).
- The attacker should have write access to a remote plugin asset loaded by the Traefik server
- The attacker should craft a malicious version of this plugin&lt;/p&gt;
&lt;p&gt;### Warning
As clearly stated in the [documentation](https://doc.traefik.io/traefik/plugin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;### Summary
A path traversal vulnerability was discovered in WASM Traefik’s plugin installation mechanism. By supplying a maliciously crafted ZIP archive containing file paths with `../` sequences, an attacker can overwrite arbitrary files on the system outside of the intended plugin directory. This can lead to remote code execution (RCE), privilege escalation, persistence, or denial of service.
 **✅ After investigation, it is confirmed that no plugins on the [Catalog](https://plugins.traefik.io/plugins) were affected. There is no known impact.**&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability resides in the WASM plugin extraction logic, specifically in the `unzipFile` function (`/plugins/client.go`). The application constructs file paths during ZIP extraction using `filepath.Join(destDir, f.Name)` without validating or sanitizing `f.Name`. If the ZIP archive contains entries with `../`, the resulting path can escape the intended directory, allowing writes to arbitrary locations on the host filesystem.&lt;/p&gt;
&lt;p&gt;### Attack Requirements
There are several requirements needed to make this attack possible:
- The Traefik server should be deployed with [plugins enabled](https://doc.traefik.io/traefik/plugins/) with a WASM plugin (yaegi plugins are not impacted).
- The attacker should have write access to a remote plugin asset loaded by the Traefik server
- The attacker should craft a malicious version of this plugin&lt;/p&gt;
&lt;p&gt;### Warning
As clearly stated in the [documentation](https://doc.traefik.io/traefik/plugin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q6gg-9f92-r9wg</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15434-1 — govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15434-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15434-1</guid>
    </item>
    <item>
      <title>RHSA-2026:6192 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.27.0 Release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:6192</link>
      <description>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions traefik: Traefik&amp;#39;s Client Plugin is Vulnerable to Path Traversal, Arbitrary File Overwrites and Remote Code Execution golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate glob: glob: Command Injection Vulnerability via Malicious Filenames crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption ajv: ReDoS via $data reference io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files traefik: Traefik: Denial of Service via ACME TLS-ALPN fast path resource exhaustion node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check Fastify: Fastify: Validation bypass due to malformed Content-Type header leading to integrity impact axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig github.com/traefik/traefik: Traefik: Denial of Service via stalled STARTTLS requests node-tar: node-ta…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lodash: prototype pollution in _.unset and _.omit functions traefik: Traefik&amp;#39;s Client Plugin is Vulnerable to Path Traversal, Arbitrary File Overwrites and Remote Code Execution golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate glob: glob: Command Injection Vulnerability via Malicious Filenames crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption ajv: ReDoS via $data reference io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files traefik: Traefik: Denial of Service via ACME TLS-ALPN fast path resource exhaustion node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check Fastify: Fastify: Validation bypass due to malformed Content-Type header leading to integrity impact axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig github.com/traefik/traefik: Traefik: Denial of Service via stalled STARTTLS requests node-tar: node-ta…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:6192</guid>
    </item>
  </channel>
</rss>
