<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:44:49 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-UF69839 — Security fix for CVE-2026-27795 applied in: n8n 2.28.0-r2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-uf69839</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: n8n&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the n8n package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: n8n&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the n8n package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-uf69839</guid>
    </item>
    <item>
      <title>EUVD-2026-270695</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-270695</link>
      <description>EUVD-2026-270695</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-270695</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27795</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27795</link>
      <description>&lt;p&gt;LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates the initial URL but allows the underlying fetch to follow redirects automatically, which permits a transition from a safe public URL to an internal or metadata endpoint without revalidation. This is a bypass of the SSRF protections introduced in 1.1.14 (CVE-2026-26019). Users should upgrade to `@langchain/community` 1.1.18, which validates every redirect hop by disabling automatic redirects and re-validating `Location` targets before following them. In this version, automatic redirects are disabled (`redirect: &amp;#34;manual&amp;#34;`), each 3xx `Location` is resolved and validated with `validateSafeUrl()` before the next request, and a maximum redirect limit prevents infinite loops.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates the initial URL but allows the underlying fetch to follow redirects automatically, which permits a transition from a safe public URL to an internal or metadata endpoint without revalidation. This is a bypass of the SSRF protections introduced in 1.1.14 (CVE-2026-26019). Users should upgrade to `@langchain/community` 1.1.18, which validates every redirect hop by disabling automatic redirects and re-validating `Location` targets before following them. In this version, automatic redirects are disabled (`redirect: &amp;#34;manual&amp;#34;`), each 3xx `Location` is resolved and validated with `validateSafeUrl()` before the next request, and a maximum redirect limit prevents infinite loops.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27795</guid>
    </item>
    <item>
      <title>GHSA-mphv-75cg-56wg — LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mphv-75cg-56wg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @langchain/community&lt;/p&gt;
&lt;p&gt;## Summary
A redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates the initial URL but allows the underlying fetch to follow redirects automatically, which permits a transition from a safe public URL to an internal or metadata endpoint without revalidation. This is a bypass of the SSRF protections introduced in 1.1.14 (CVE-2026-26019).&lt;/p&gt;
&lt;p&gt;## Affected Component
- Package: `@langchain/community`
- Component: `RecursiveUrlLoader`
- Configuration: `preventOutside` (default: `true`) is insufficient to prevent this bypass when redirects are followed automatically.&lt;/p&gt;
&lt;p&gt;## Description
`RecursiveUrlLoader` is a web crawler that recursively follows links from a starting URL. The existing SSRF mitigation validates the initial URL before fetching, but it does not re-validate when the request follows redirects. Because fetch follows redirects by default, an attacker can supply a public URL that passes validation and then redirects to a private network address, localhost, or cloud metadata endpoint.&lt;/p&gt;
&lt;p&gt;This constitutes a “check‑then‑act” gap in the request lifecycle: the safety check occurs before the redirect chain is resolved, and the final destination is never validated.&lt;/p&gt;
&lt;p&gt;## Impact
If an attacker can influence content on a page being crawled (e.g., user‑generated content, untrusted external pages), they can cause the crawler to:
- Fetch cloud instance metadata (AWS, GCP, Azure), potentially exposing credentials…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @langchain/community&lt;/p&gt;
&lt;p&gt;## Summary
A redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates the initial URL but allows the underlying fetch to follow redirects automatically, which permits a transition from a safe public URL to an internal or metadata endpoint without revalidation. This is a bypass of the SSRF protections introduced in 1.1.14 (CVE-2026-26019).&lt;/p&gt;
&lt;p&gt;## Affected Component
- Package: `@langchain/community`
- Component: `RecursiveUrlLoader`
- Configuration: `preventOutside` (default: `true`) is insufficient to prevent this bypass when redirects are followed automatically.&lt;/p&gt;
&lt;p&gt;## Description
`RecursiveUrlLoader` is a web crawler that recursively follows links from a starting URL. The existing SSRF mitigation validates the initial URL before fetching, but it does not re-validate when the request follows redirects. Because fetch follows redirects by default, an attacker can supply a public URL that passes validation and then redirects to a private network address, localhost, or cloud metadata endpoint.&lt;/p&gt;
&lt;p&gt;This constitutes a “check‑then‑act” gap in the request lifecycle: the safety check occurs before the redirect chain is resolved, and the final destination is never validated.&lt;/p&gt;
&lt;p&gt;## Impact
If an attacker can influence content on a page being crawled (e.g., user‑generated content, untrusted external pages), they can cause the crawler to:
- Fetch cloud instance metadata (AWS, GCP, Azure), potentially exposing credentials…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mphv-75cg-56wg</guid>
    </item>
  </channel>
</rss>
