<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:54:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292776</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292776</link>
      <description>EUVD-2026-292776</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292776</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40471</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40471</link>
      <description>&lt;p&gt;hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40471</guid>
    </item>
    <item>
      <title>GHSA-mf84-vmqg-86fm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mf84-vmqg-86fm</link>
      <description>&lt;p&gt;hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mf84-vmqg-86fm</guid>
    </item>
    <item>
      <title>HSEC-2026-0002 — Hackage CSRF vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2026-0002</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: hackage-server&lt;/p&gt;
&lt;p&gt;# Hackage CSRF vulnerability&lt;/p&gt;
&lt;p&gt;* Vulnerable File: `src/Distribution/Server/Features/Votes.hs` (example)
* Impact: can forge requests through XSS&lt;/p&gt;
&lt;p&gt;hackage-server lacked Cross-Site Request Forgery (CSRF) protection
across its endpoints.  Scripts on foreign sites could trigger
requests to hackage server, possibly abusing latent credentials to
upload packages or perform other administrative actions.  Some
unauthenticated actions could also be abused (e.g. creating new user
accounts).&lt;/p&gt;
&lt;p&gt;To fix the issue, a new CSRF middleware checks all requests.
Requests using HTTP methods other than `GET`, `HEAD` and `OPTIONS`
are subject to a check of the [`Sec-Fetch-Site`
header][sec-fetch-site], which is [widely supported by modern
browsers][caniuse-sec-fetch-site].  Cross-site requests are `403
Forbidden`.  Certain approved and expected non-browser user agents
(e.g. `cabal-install/*`) are exempted from the check, as are
requests using token authentication (`Authorization: X-ApiKey ...`).&lt;/p&gt;
&lt;p&gt;The fix has been [committed][commit] and deployed on
`hackage.haskell.org`.&lt;/p&gt;
&lt;p&gt;## Acknowledgements&lt;/p&gt;
&lt;p&gt;- **Joshua Rogers** (https://joshua.hu/) of AISLE
  (https://aisle.com/) reported the issue to the Haskell Security
  Response Team.
- **Spenser Janssen** implemented the fix, and **Fraser Tweedale**
  reviewed it.
- **Gershom Bazerman** merged the fix and deployed it to
  `hackage.haskell.org`.&lt;/p&gt;
&lt;p&gt;[sec-fetch-site]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Sec-Fetch-Site
[caniuse-sec-fet…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: hackage-server&lt;/p&gt;
&lt;p&gt;# Hackage CSRF vulnerability&lt;/p&gt;
&lt;p&gt;* Vulnerable File: `src/Distribution/Server/Features/Votes.hs` (example)
* Impact: can forge requests through XSS&lt;/p&gt;
&lt;p&gt;hackage-server lacked Cross-Site Request Forgery (CSRF) protection
across its endpoints.  Scripts on foreign sites could trigger
requests to hackage server, possibly abusing latent credentials to
upload packages or perform other administrative actions.  Some
unauthenticated actions could also be abused (e.g. creating new user
accounts).&lt;/p&gt;
&lt;p&gt;To fix the issue, a new CSRF middleware checks all requests.
Requests using HTTP methods other than `GET`, `HEAD` and `OPTIONS`
are subject to a check of the [`Sec-Fetch-Site`
header][sec-fetch-site], which is [widely supported by modern
browsers][caniuse-sec-fetch-site].  Cross-site requests are `403
Forbidden`.  Certain approved and expected non-browser user agents
(e.g. `cabal-install/*`) are exempted from the check, as are
requests using token authentication (`Authorization: X-ApiKey ...`).&lt;/p&gt;
&lt;p&gt;The fix has been [committed][commit] and deployed on
`hackage.haskell.org`.&lt;/p&gt;
&lt;p&gt;## Acknowledgements&lt;/p&gt;
&lt;p&gt;- **Joshua Rogers** (https://joshua.hu/) of AISLE
  (https://aisle.com/) reported the issue to the Haskell Security
  Response Team.
- **Spenser Janssen** implemented the fix, and **Fraser Tweedale**
  reviewed it.
- **Gershom Bazerman** merged the fix and deployed it to
  `hackage.haskell.org`.&lt;/p&gt;
&lt;p&gt;[sec-fetch-site]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Sec-Fetch-Site
[caniuse-sec-fet…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2026-0002</guid>
    </item>
  </channel>
</rss>
