<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:27:36 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-268885</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-268885</link>
      <description>EUVD-2026-268885</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-268885</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25739</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25739</link>
      <description>&lt;p&gt;Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to cross-site scripting when uploading certain file types as materials. Users should upgrade to version 3.3.10 to receive a patch. To apply the fix itself updating is sufficient, but to benefit from the strict Content Security Policy (CSP) Indico now applies by default for file downloads, update the webserver config in case one uses nginx with Indico&amp;#39;s `STATIC_FILE_METHOD` set to `xaccelredirect`. For further directions, consult the GitHub Security advisory or Indico setup documentation. Some workarounds are available. Use the webserver config to apply a strict CSP for material download endpoints, and/or only let trustworthy users create content (including material uploads, which speakers can typically do as well) on Indico.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to cross-site scripting when uploading certain file types as materials. Users should upgrade to version 3.3.10 to receive a patch. To apply the fix itself updating is sufficient, but to benefit from the strict Content Security Policy (CSP) Indico now applies by default for file downloads, update the webserver config in case one uses nginx with Indico&amp;#39;s `STATIC_FILE_METHOD` set to `xaccelredirect`. For further directions, consult the GitHub Security advisory or Indico setup documentation. Some workarounds are available. Use the webserver config to apply a strict CSP for material download endpoints, and/or only let trustworthy users create content (including material uploads, which speakers can typically do as well) on Indico.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25739</guid>
    </item>
    <item>
      <title>GHSA-jxc4-54g3-j7vp — Indico Affected by Cross-Site-Scripting via material uploads</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jxc4-54g3-j7vp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: indico&lt;/p&gt;
&lt;p&gt;### Impact
There is a Cross-Site-Scripting vulnerability when uploading certain file types as materials.&lt;/p&gt;
&lt;p&gt;### Patches
You should to update to [Indico 3.3.10](https://github.com/indico/indico/releases/tag/v3.3.10) as soon as possible.
See [the docs](https://docs.getindico.io/en/stable/installation/upgrade/) for instructions on how to update.&lt;/p&gt;
&lt;p&gt;Please be aware that to apply the fix itself updating is sufficient, but to benefit from the strict Content-Security-Policy we now apply by default for file downloads, you need to update your webserver config in case you use nginx with Indico&amp;#39;s `STATIC_FILE_METHOD` set to `xaccelredirect` and add the following line to the `.xsf/indico/` location block (you can consult the Indico setup documentation for the full configuration snippet):&lt;/p&gt;
&lt;p&gt;```nginx
add_header Content-Security-Policy $upstream_http_content_security_policy;
```&lt;/p&gt;
&lt;p&gt;### Workarounds
- Use your webserver config to apply a strict CSP for material download endpoints.
- Only let trustworthy users create content (including material uploads, which speakers can typically do as well) on Indico.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;- Open a thread in [our forum](https://talk.getindico.io/)
- Email us privately at [indico-team@cern.ch](mailto:indico-team@cern.ch)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: indico&lt;/p&gt;
&lt;p&gt;### Impact
There is a Cross-Site-Scripting vulnerability when uploading certain file types as materials.&lt;/p&gt;
&lt;p&gt;### Patches
You should to update to [Indico 3.3.10](https://github.com/indico/indico/releases/tag/v3.3.10) as soon as possible.
See [the docs](https://docs.getindico.io/en/stable/installation/upgrade/) for instructions on how to update.&lt;/p&gt;
&lt;p&gt;Please be aware that to apply the fix itself updating is sufficient, but to benefit from the strict Content-Security-Policy we now apply by default for file downloads, you need to update your webserver config in case you use nginx with Indico&amp;#39;s `STATIC_FILE_METHOD` set to `xaccelredirect` and add the following line to the `.xsf/indico/` location block (you can consult the Indico setup documentation for the full configuration snippet):&lt;/p&gt;
&lt;p&gt;```nginx
add_header Content-Security-Policy $upstream_http_content_security_policy;
```&lt;/p&gt;
&lt;p&gt;### Workarounds
- Use your webserver config to apply a strict CSP for material download endpoints.
- Only let trustworthy users create content (including material uploads, which speakers can typically do as well) on Indico.&lt;/p&gt;
&lt;p&gt;### For more information
If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;- Open a thread in [our forum](https://talk.getindico.io/)
- Email us privately at [indico-team@cern.ch](mailto:indico-team@cern.ch)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jxc4-54g3-j7vp</guid>
    </item>
    <item>
      <title>PYSEC-2026-2182</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2182</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: indico&lt;/p&gt;
&lt;p&gt;Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to cross-site scripting when uploading certain file types as materials. Users should upgrade to version 3.3.10 to receive a patch. To apply the fix itself updating is sufficient, but to benefit from the strict Content Security Policy (CSP) Indico now applies by default for file downloads, update the webserver config in case one uses nginx with Indico&amp;#39;s `STATIC_FILE_METHOD` set to `xaccelredirect`. For further directions, consult the GitHub Security advisory or Indico setup documentation. Some workarounds are available. Use the webserver config to apply a strict CSP for material download endpoints, and/or only let trustworthy users create content (including material uploads, which speakers can typically do as well) on Indico.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: indico&lt;/p&gt;
&lt;p&gt;Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to cross-site scripting when uploading certain file types as materials. Users should upgrade to version 3.3.10 to receive a patch. To apply the fix itself updating is sufficient, but to benefit from the strict Content Security Policy (CSP) Indico now applies by default for file downloads, update the webserver config in case one uses nginx with Indico&amp;#39;s `STATIC_FILE_METHOD` set to `xaccelredirect`. For further directions, consult the GitHub Security advisory or Indico setup documentation. Some workarounds are available. Use the webserver config to apply a strict CSP for material download endpoints, and/or only let trustworthy users create content (including material uploads, which speakers can typically do as well) on Indico.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2182</guid>
    </item>
  </channel>
</rss>
