<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 02:51:59 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00007</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00007</link>
      <description>bdu:2026-00007</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00007</guid>
    </item>
    <item>
      <title>EUVD-2026-264845</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264845</link>
      <description>EUVD-2026-264845</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264845</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68926</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68926</link>
      <description>&lt;p&gt;RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `&amp;#34;rustfs rpc&amp;#34;` that is publicly exposed in the source code repository, hardcoded on both client and server sides, non-configurable with no mechanism for token rotation, and universally valid across all RustFS deployments. Any attacker with network access to the gRPC port can authenticate using this publicly known token and execute privileged operations including data destruction, policy manipulation, and cluster configuration changes. Version 1.0.0-alpha.78 contains a fix for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `&amp;#34;rustfs rpc&amp;#34;` that is publicly exposed in the source code repository, hardcoded on both client and server sides, non-configurable with no mechanism for token rotation, and universally valid across all RustFS deployments. Any attacker with network access to the gRPC port can authenticate using this publicly known token and execute privileged operations including data destruction, policy manipulation, and cluster configuration changes. Version 1.0.0-alpha.78 contains a fix for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68926</guid>
    </item>
    <item>
      <title>GHSA-h956-rh7x-ppgj — RustFS has a gRPC Hardcoded Token Authentication Bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h956-rh7x-ppgj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rustfs&lt;/p&gt;
&lt;p&gt;## Vulnerability Overview&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;RustFS implements gRPC authentication using a hardcoded static token `&amp;#34;rustfs rpc&amp;#34;` that is:
1. **Publicly exposed** in the source code repository
2. **Hardcoded** on both client and server sides
3. **Non-configurable** with no mechanism for token rotation
4. **Universally valid** across all RustFS deployments&lt;/p&gt;
&lt;p&gt;Any attacker with network access to the gRPC port can authenticate using this publicly known token and execute privileged operations including data destruction, policy manipulation, and cluster configuration changes.&lt;/p&gt;
&lt;p&gt;### CVSS 3.1 Score&lt;/p&gt;
&lt;p&gt;**Score**: 9.8 (Critical)
**Vector**: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`&lt;/p&gt;
&lt;p&gt;- **Attack Vector (AV)**: Network - Exploitable remotely
- **Attack Complexity (AC)**: Low - No special conditions required
- **Privileges Required (PR)**: None - No authentication needed (bypassed)
- **User Interaction (UI)**: None - Fully automated exploitation
- **Scope (S)**: Unchanged - Impact contained to vulnerable component
- **Confidentiality (C)**: High - Complete data disclosure
- **Integrity (I)**: High - Complete data modification capability
- **Availability (A)**: High - Complete service disruption capability&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerable Code Analysis&lt;/p&gt;
&lt;p&gt;### Server-Side Authentication (rustfs/src/server/http.rs:679-686)&lt;/p&gt;
&lt;p&gt;```rust
#[allow(clippy::result_large_err)]
fn check_auth(req: Request&amp;lt;()&amp;gt;) -&amp;gt; std::result::Result&amp;lt;Request&amp;lt;()&amp;gt;, Status&amp;gt; {
    let token: MetadataValue&amp;lt;_&amp;gt; = &amp;#34;rustfs rpc&amp;#34;.parse().unwrap();…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: rustfs&lt;/p&gt;
&lt;p&gt;## Vulnerability Overview&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;RustFS implements gRPC authentication using a hardcoded static token `&amp;#34;rustfs rpc&amp;#34;` that is:
1. **Publicly exposed** in the source code repository
2. **Hardcoded** on both client and server sides
3. **Non-configurable** with no mechanism for token rotation
4. **Universally valid** across all RustFS deployments&lt;/p&gt;
&lt;p&gt;Any attacker with network access to the gRPC port can authenticate using this publicly known token and execute privileged operations including data destruction, policy manipulation, and cluster configuration changes.&lt;/p&gt;
&lt;p&gt;### CVSS 3.1 Score&lt;/p&gt;
&lt;p&gt;**Score**: 9.8 (Critical)
**Vector**: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`&lt;/p&gt;
&lt;p&gt;- **Attack Vector (AV)**: Network - Exploitable remotely
- **Attack Complexity (AC)**: Low - No special conditions required
- **Privileges Required (PR)**: None - No authentication needed (bypassed)
- **User Interaction (UI)**: None - Fully automated exploitation
- **Scope (S)**: Unchanged - Impact contained to vulnerable component
- **Confidentiality (C)**: High - Complete data disclosure
- **Integrity (I)**: High - Complete data modification capability
- **Availability (A)**: High - Complete service disruption capability&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerable Code Analysis&lt;/p&gt;
&lt;p&gt;### Server-Side Authentication (rustfs/src/server/http.rs:679-686)&lt;/p&gt;
&lt;p&gt;```rust
#[allow(clippy::result_large_err)]
fn check_auth(req: Request&amp;lt;()&amp;gt;) -&amp;gt; std::result::Result&amp;lt;Request&amp;lt;()&amp;gt;, Status&amp;gt; {
    let token: MetadataValue&amp;lt;_&amp;gt; = &amp;#34;rustfs rpc&amp;#34;.parse().unwrap();…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h956-rh7x-ppgj</guid>
    </item>
  </channel>
</rss>
