<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:33:16 +0000</lastBuildDate>
    <item>
      <title>BREW-aider-CVE-2026-22701 — filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-22701</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;## Vulnerability Summary&lt;/p&gt;
&lt;p&gt;**Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock&lt;/p&gt;
&lt;p&gt;**Affected Component:** `filelock` package - `SoftFileLock` class
**File:** `src/filelock/_soft.py` lines 17-27
**CWE:** CWE-362, CWE-367, CWE-59&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly.&lt;/p&gt;
&lt;p&gt;The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service.&lt;/p&gt;
&lt;p&gt;### Attack Scenario&lt;/p&gt;
&lt;p&gt;```
1. Lock attempts to acquire on /tmp/app.lock
2. Permission validation passes
3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock
4. os.open() tries to create lock file
5. Lock operates on attacker-controlled target file or fails
```&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization.&lt;/p&gt;
&lt;p&gt;**Affected Users:**
- Applications using `filelock.SoftFil…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;## Vulnerability Summary&lt;/p&gt;
&lt;p&gt;**Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock&lt;/p&gt;
&lt;p&gt;**Affected Component:** `filelock` package - `SoftFileLock` class
**File:** `src/filelock/_soft.py` lines 17-27
**CWE:** CWE-362, CWE-367, CWE-59&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly.&lt;/p&gt;
&lt;p&gt;The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service.&lt;/p&gt;
&lt;p&gt;### Attack Scenario&lt;/p&gt;
&lt;p&gt;```
1. Lock attempts to acquire on /tmp/app.lock
2. Permission validation passes
3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock
4. os.open() tries to create lock file
5. Lock operates on attacker-controlled target file or fails
```&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization.&lt;/p&gt;
&lt;p&gt;**Affected Users:**
- Applications using `filelock.SoftFil…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-22701</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0224 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224</link>
      <description>certfr-2026-avi-0224</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0224</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-BI98027 — Security fix for CVE-2026-22701 applied in: kserve-storage-controller 0.19.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bi98027</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kserve-storage-controller&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the kserve-storage-controller package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kserve-storage-controller&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the kserve-storage-controller package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bi98027</guid>
    </item>
    <item>
      <title>EUVD-2026-265407</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265407</link>
      <description>EUVD-2026-265407</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265407</guid>
    </item>
    <item>
      <title>fkie_cve-2026-22701</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22701</link>
      <description>&lt;p&gt;filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission check) and os.open() (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. This issue has been patched in version 3.20.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission check) and os.open() (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. This issue has been patched in version 3.20.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-22701</guid>
    </item>
    <item>
      <title>GHSA-qmgc-5h2g-mvrw — filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qmgc-5h2g-mvrw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: filelock&lt;/p&gt;
&lt;p&gt;## Vulnerability Summary&lt;/p&gt;
&lt;p&gt;**Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock&lt;/p&gt;
&lt;p&gt;**Affected Component:** `filelock` package - `SoftFileLock` class
**File:** `src/filelock/_soft.py` lines 17-27
**CWE:** CWE-362, CWE-367, CWE-59&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly.&lt;/p&gt;
&lt;p&gt;The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service.&lt;/p&gt;
&lt;p&gt;### Attack Scenario&lt;/p&gt;
&lt;p&gt;```
1. Lock attempts to acquire on /tmp/app.lock
2. Permission validation passes
3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock
4. os.open() tries to create lock file
5. Lock operates on attacker-controlled target file or fails
```&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization.&lt;/p&gt;
&lt;p&gt;**Affected Users:**
- Applications using `filelock.SoftFil…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: filelock&lt;/p&gt;
&lt;p&gt;## Vulnerability Summary&lt;/p&gt;
&lt;p&gt;**Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock&lt;/p&gt;
&lt;p&gt;**Affected Component:** `filelock` package - `SoftFileLock` class
**File:** `src/filelock/_soft.py` lines 17-27
**CWE:** CWE-362, CWE-367, CWE-59&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly.&lt;/p&gt;
&lt;p&gt;The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service.&lt;/p&gt;
&lt;p&gt;### Attack Scenario&lt;/p&gt;
&lt;p&gt;```
1. Lock attempts to acquire on /tmp/app.lock
2. Permission validation passes
3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock
4. os.open() tries to create lock file
5. Lock operates on attacker-controlled target file or fails
```&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization.&lt;/p&gt;
&lt;p&gt;**Affected Users:**
- Applications using `filelock.SoftFil…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qmgc-5h2g-mvrw</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-22701 — filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-22701</link>
      <description>msrc_CVE-2026-22701</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-22701</guid>
    </item>
    <item>
      <title>OESA-2026-1237 — python-filelock security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1237</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: python-filelock&lt;/p&gt;
&lt;p&gt;This package contains a single module, which implements a platform independent file locking mechanism for Python.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission check) and os.open() (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. This issue has been patched in version 3.20.3.(CVE-2026-22701)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: python-filelock&lt;/p&gt;
&lt;p&gt;This package contains a single module, which implements a platform independent file locking mechanism for Python.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission check) and os.open() (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. This issue has been patched in version 3.20.3.(CVE-2026-22701)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1237</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10043-1 — python311-filelock-3.20.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10043-1</link>
      <description>&lt;p&gt;python311-filelock-3.20.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-filelock-3.20.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10043-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1374 — filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1374</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: filelock&lt;/p&gt;
&lt;p&gt;## Vulnerability Summary&lt;/p&gt;
&lt;p&gt;**Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock&lt;/p&gt;
&lt;p&gt;**Affected Component:** `filelock` package - `SoftFileLock` class
**File:** `src/filelock/_soft.py` lines 17-27
**CWE:** CWE-362, CWE-367, CWE-59&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly.&lt;/p&gt;
&lt;p&gt;The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service.&lt;/p&gt;
&lt;p&gt;### Attack Scenario&lt;/p&gt;
&lt;p&gt;```
1. Lock attempts to acquire on /tmp/app.lock
2. Permission validation passes
3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock
4. os.open() tries to create lock file
5. Lock operates on attacker-controlled target file or fails
```&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization.&lt;/p&gt;
&lt;p&gt;**Affected Users:**
- Applications using `filelock.SoftFil…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: filelock&lt;/p&gt;
&lt;p&gt;## Vulnerability Summary&lt;/p&gt;
&lt;p&gt;**Title:** Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock&lt;/p&gt;
&lt;p&gt;**Affected Component:** `filelock` package - `SoftFileLock` class
**File:** `src/filelock/_soft.py` lines 17-27
**CWE:** CWE-362, CWE-367, CWE-59&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A TOCTOU race condition vulnerability exists in the `SoftFileLock` implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly.&lt;/p&gt;
&lt;p&gt;The vulnerability occurs in the `_acquire()` method between `raise_on_not_writable_file()` (permission check) and `os.open()` (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service.&lt;/p&gt;
&lt;p&gt;### Attack Scenario&lt;/p&gt;
&lt;p&gt;```
1. Lock attempts to acquire on /tmp/app.lock
2. Permission validation passes
3. [RACE WINDOW] - Attacker creates: ln -s /tmp/important.txt /tmp/app.lock
4. os.open() tries to create lock file
5. Lock operates on attacker-controlled target file or fails
```&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;This is a **Time-of-Check-Time-of-Use (TOCTOU) race condition vulnerability** affecting any application using `SoftFileLock` for inter-process synchronization.&lt;/p&gt;
&lt;p&gt;**Affected Users:**
- Applications using `filelock.SoftFil…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1374</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:20216-1 — Security update for python-filelock</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:20216-1</link>
      <description>&lt;p&gt;Security update for python-filelock&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-filelock&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:20216-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-22701</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22701</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: python-filelock, Ubuntu:Pro:22.04:LTS: python-filelock, Ubuntu:Pro:24.04:LTS: python-filelock, Ubuntu:25.10: python-filelock, Ubuntu:26.04:LTS: python-filelock&lt;/p&gt;
&lt;p&gt;filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission check) and os.open() (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. This issue has been patched in version 3.20.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: python-filelock, Ubuntu:Pro:22.04:LTS: python-filelock, Ubuntu:Pro:24.04:LTS: python-filelock, Ubuntu:25.10: python-filelock, Ubuntu:26.04:LTS: python-filelock&lt;/p&gt;
&lt;p&gt;filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission validation and file creation to cause lock operations to fail or behave unexpectedly. The vulnerability occurs in the _acquire() method between raise_on_not_writable_file() (permission check) and os.open() (file creation). During this race window, an attacker can create a symlink at the lock file path, potentially causing the lock to operate on an unintended target file or leading to denial of service. This issue has been patched in version 3.20.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22701</guid>
    </item>
  </channel>
</rss>
