<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 02:41:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277086</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277086</link>
      <description>EUVD-2026-277086</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277086</guid>
    </item>
    <item>
      <title>fkie_cve-2025-9572</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-9572</link>
      <description>&lt;p&gt;n authorization flaw in Foreman&amp;#39;s GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;n authorization flaw in Foreman&amp;#39;s GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-9572</guid>
    </item>
    <item>
      <title>GHSA-gvvp-xfg4-2fr6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gvvp-xfg4-2fr6</link>
      <description>&lt;p&gt;n authorization flaw in Foreman&amp;#39;s GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;n authorization flaw in Foreman&amp;#39;s GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gvvp-xfg4-2fr6</guid>
    </item>
    <item>
      <title>RHSA-2025:21886 — Red Hat Security Advisory: Satellite 6.18.1 Async Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:21886</link>
      <description>&lt;p&gt;foreman: Satellite: GraphQL API permission bypass leads to information disclosure&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;foreman: Satellite: GraphQL API permission bypass leads to information disclosure&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:21886</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-9572</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9572</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-foreman, Ubuntu:18.04:LTS: ruby-foreman, Ubuntu:20.04:LTS: ruby-foreman, Ubuntu:22.04:LTS: ruby-foreman, Ubuntu:24.04:LTS: ruby-foreman, Ubuntu:25.10: ruby-foreman, Ubuntu:26.04:LTS: ruby-foreman&lt;/p&gt;
&lt;p&gt;n authorization flaw in Foreman&amp;#39;s GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-foreman, Ubuntu:18.04:LTS: ruby-foreman, Ubuntu:20.04:LTS: ruby-foreman, Ubuntu:22.04:LTS: ruby-foreman, Ubuntu:24.04:LTS: ruby-foreman, Ubuntu:25.10: ruby-foreman, Ubuntu:26.04:LTS: ruby-foreman&lt;/p&gt;
&lt;p&gt;n authorization flaw in Foreman&amp;#39;s GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9572</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2652 — Red Hat Satellite: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2652</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Satellite für Red Hat Enterprise Linux ausnutzen, um Sicherheitsmaßnahmen zu umgehen und so vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Satellite für Red Hat Enterprise Linux ausnutzen, um Sicherheitsmaßnahmen zu umgehen und so vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2652</guid>
    </item>
  </channel>
</rss>
