<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:29:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-365461</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-365461</link>
      <description>EUVD-2026-365461</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-365461</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40293</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40293</link>
      <description>&lt;p&gt;OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint. The /playground endpoint is enabled by default and does not require authentication. It is intended for local development and debugging and is not designed to be exposed to production environments. Only those who run OpenFGA with `--authn-method` preshared, with the playground enabled, and with the playground endpoint accessible beyond localhost or trusted networks are vulnerable. To remediate the issue, users should upgrade to OpenFGA v1.14.0, or disable the playground by running `./openfga run --playground-enabled=false.`&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint. The /playground endpoint is enabled by default and does not require authentication. It is intended for local development and debugging and is not designed to be exposed to production environments. Only those who run OpenFGA with `--authn-method` preshared, with the playground enabled, and with the playground endpoint accessible beyond localhost or trusted networks are vulnerable. To remediate the issue, users should upgrade to OpenFGA v1.14.0, or disable the playground by running `./openfga run --playground-enabled=false.`&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40293</guid>
    </item>
    <item>
      <title>GHSA-68m9-983m-f3v5 — OpenFGA: Unauthenticated playground endpoint discloses preshared API key in HTML response</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-68m9-983m-f3v5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openfga/openfga&lt;/p&gt;
&lt;p&gt;### Description
When OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint. The /playground endpoint is enabled by default and does not require authentication. It is intended for local development and debugging and is not designed to be exposed to production environments.&lt;/p&gt;
&lt;p&gt;### Am I Affected?
You are affected if you meet each of the following preconditions:
* You are running OpenFGA with --authn-method preshared, and
* The playground is enabled, and
* The playground endpoint is accessible beyond localhost or trusted networks.&lt;/p&gt;
&lt;p&gt;### Fix
Upgrade to OpenFGA v1.14.0, or disable the playground by running `./openfga run --playground-enabled=false.`&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openfga/openfga&lt;/p&gt;
&lt;p&gt;### Description
When OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint. The /playground endpoint is enabled by default and does not require authentication. It is intended for local development and debugging and is not designed to be exposed to production environments.&lt;/p&gt;
&lt;p&gt;### Am I Affected?
You are affected if you meet each of the following preconditions:
* You are running OpenFGA with --authn-method preshared, and
* The playground is enabled, and
* The playground endpoint is accessible beyond localhost or trusted networks.&lt;/p&gt;
&lt;p&gt;### Fix
Upgrade to OpenFGA v1.14.0, or disable the playground by running `./openfga run --playground-enabled=false.`&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-68m9-983m-f3v5</guid>
    </item>
    <item>
      <title>RHSA-2026:24503 — Red Hat Security Advisory: Multicluster Global Hub 1.7.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:24503</link>
      <description>&lt;p&gt;pyroscope: sensitive COS SecretKey exposed in plaintext via configuration API due to missing type protection grafana/tempo: Tempo: Denial of Service via large queries crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root golang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsing github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability Moby: Moby: Authorization bypass vulnerability OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input github.com/apache/thrift: Apache Thrift: Integer Overflow in TFramedTransport Go implementation Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pyroscope: sensitive COS SecretKey exposed in plaintext via configuration API due to missing type protection grafana/tempo: Tempo: Denial of Service via large queries crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root golang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsing github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability Moby: Moby: Authorization bypass vulnerability OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input github.com/apache/thrift: Apache Thrift: Integer Overflow in TFramedTransport Go implementation Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:24503</guid>
    </item>
  </channel>
</rss>
