<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 19:50:57 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00674</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00674</link>
      <description>bdu:2026-00674</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00674</guid>
    </item>
    <item>
      <title>EUVD-2026-265858</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265858</link>
      <description>EUVD-2026-265858</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265858</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23511</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23511</link>
      <description>&lt;p&gt;ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel&amp;#39;s login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel&amp;#39;s login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23511</guid>
    </item>
    <item>
      <title>GHSA-pvm5-9frx-264r — Zitadel has a user enumeration vulnerability in Login UIs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pvm5-9frx-264r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/zitadel/zitadel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A user enumeration vulnerability has been discovered in Zitadel&amp;#39;s login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The login UIs (in version 1 and 2) provide the possibility to request a password reset, where an email will be sent to the user with a link to a verification endpoint.
By submitting arbitrary userIDs to these endpoints, an attacker can differentiate between valid and invalid accounts based on the system&amp;#39;s response.&lt;/p&gt;
&lt;p&gt;For an effective exploit the attacker needs to iterate through the potential set of userIDs. The impact can be limited by implementing [rate limiting](https://zitadel.com/docs/self-hosting/manage/production#limits-and-quotas) or similar measures to limit enumeration of userIDs.&lt;/p&gt;
&lt;p&gt;Additionally, Zitadel includes a security feature &amp;#34;Ignoring unknown usernames&amp;#34;, designed to prevent username enumeration attacks by presenting a generic response for both valid and invalid usernames on the login page. The login UI V2 did not handle the setting correctly and would allow attackers to enumerate through usernames to check their existence.&lt;/p&gt;
&lt;p&gt;### Affected Versions&lt;/p&gt;
&lt;p&gt;All versions within the following ranges, including release candidates (RCs), are affected:
- **v4.x**: `4.0.0` through `4.9.0`
- **3.x**: `3.0.0` through `3.4.5`
- **2.x**: `2.0.0` through `2.71.19`&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The vulnerability has been addressed in the latest releas…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/zitadel/zitadel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A user enumeration vulnerability has been discovered in Zitadel&amp;#39;s login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The login UIs (in version 1 and 2) provide the possibility to request a password reset, where an email will be sent to the user with a link to a verification endpoint.
By submitting arbitrary userIDs to these endpoints, an attacker can differentiate between valid and invalid accounts based on the system&amp;#39;s response.&lt;/p&gt;
&lt;p&gt;For an effective exploit the attacker needs to iterate through the potential set of userIDs. The impact can be limited by implementing [rate limiting](https://zitadel.com/docs/self-hosting/manage/production#limits-and-quotas) or similar measures to limit enumeration of userIDs.&lt;/p&gt;
&lt;p&gt;Additionally, Zitadel includes a security feature &amp;#34;Ignoring unknown usernames&amp;#34;, designed to prevent username enumeration attacks by presenting a generic response for both valid and invalid usernames on the login page. The login UI V2 did not handle the setting correctly and would allow attackers to enumerate through usernames to check their existence.&lt;/p&gt;
&lt;p&gt;### Affected Versions&lt;/p&gt;
&lt;p&gt;All versions within the following ranges, including release candidates (RCs), are affected:
- **v4.x**: `4.0.0` through `4.9.0`
- **3.x**: `3.0.0` through `3.4.5`
- **2.x**: `2.0.0` through `2.71.19`&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The vulnerability has been addressed in the latest releas…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pvm5-9frx-264r</guid>
    </item>
  </channel>
</rss>
