<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:06:45 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-10805</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10805</link>
      <description>bdu:2026-10805</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10805</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2026-44307 — CVE-2026-44307 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-44307</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-44307</guid>
    </item>
    <item>
      <title>BREW-ansible-cmdb-CVE-2026-44307 — Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cmdb-cve-2026-44307</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible-cmdb&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a mismatch between `posixpath` (used for URI normalization in `get_template()`) and `os.path` (used for file access via `os.path.isfile()` and validation via `os.path.normpath()` in `Template.__init__`). On Windows, `os.path` is `ntpath`, which treats `\` as a path separator, while `posixpath` treats it as a literal character.&lt;/p&gt;
&lt;p&gt;The vulnerability chain:&lt;/p&gt;
&lt;p&gt;1. `get_template()` strips only leading `/` via `re.sub(r&amp;#34;^\/+&amp;#34;, &amp;#34;&amp;#34;, uri)` and normalizes with `posixpath` — backslash `\` is treated as a literal character, so `\..\ secret.txt` passes through with `..` undetected.
2. `Template.__init__()` validation uses `os.path.normpath()` — on Windows this resolves `\..\ secret.txt` to `\secret.txt`, which does not start with `..`, so the `startswith(&amp;#34;..&amp;#34;)` check passes.
3. `os.path.isfile()` on Windows interprets `\` as a path separator, resolving the `..` traversal and finding files outside the template directory.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `mako/lookup.py`: `TemplateLookup.get_template()` uses `posixpath.normpath`/`posixpath.join` for path construction but `os.path.isfile()` for existence check
- `mako/template.py`: `Template.__init__()` URI validation uses `os.path.normpath…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible-cmdb&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a mismatch between `posixpath` (used for URI normalization in `get_template()`) and `os.path` (used for file access via `os.path.isfile()` and validation via `os.path.normpath()` in `Template.__init__`). On Windows, `os.path` is `ntpath`, which treats `\` as a path separator, while `posixpath` treats it as a literal character.&lt;/p&gt;
&lt;p&gt;The vulnerability chain:&lt;/p&gt;
&lt;p&gt;1. `get_template()` strips only leading `/` via `re.sub(r&amp;#34;^\/+&amp;#34;, &amp;#34;&amp;#34;, uri)` and normalizes with `posixpath` — backslash `\` is treated as a literal character, so `\..\ secret.txt` passes through with `..` undetected.
2. `Template.__init__()` validation uses `os.path.normpath()` — on Windows this resolves `\..\ secret.txt` to `\secret.txt`, which does not start with `..`, so the `startswith(&amp;#34;..&amp;#34;)` check passes.
3. `os.path.isfile()` on Windows interprets `\` as a path separator, resolving the `..` traversal and finding files outside the template directory.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `mako/lookup.py`: `TemplateLookup.get_template()` uses `posixpath.normpath`/`posixpath.join` for path construction but `os.path.isfile()` for existence check
- `mako/template.py`: `Template.__init__()` URI validation uses `os.path.normpath…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cmdb-cve-2026-44307</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AF67526 — Security fixes for CVE-2026-42304, CVE-2026-44307, CVE-2026-48522, CVE-2026-48523, CVE-2026-48524, CVE-2026-48525, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-af67526</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jupyterhub-k8s-hub&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the jupyterhub-k8s-hub package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jupyterhub-k8s-hub&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the jupyterhub-k8s-hub package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-af67526</guid>
    </item>
    <item>
      <title>EUVD-2026-318054</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318054</link>
      <description>EUVD-2026-318054</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318054</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44307</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44307</link>
      <description>&lt;p&gt;Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44307</guid>
    </item>
    <item>
      <title>GHSA-2h4p-vjrc-8xpq — Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2h4p-vjrc-8xpq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Mako&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a mismatch between `posixpath` (used for URI normalization in `get_template()`) and `os.path` (used for file access via `os.path.isfile()` and validation via `os.path.normpath()` in `Template.__init__`). On Windows, `os.path` is `ntpath`, which treats `\` as a path separator, while `posixpath` treats it as a literal character.&lt;/p&gt;
&lt;p&gt;The vulnerability chain:&lt;/p&gt;
&lt;p&gt;1. `get_template()` strips only leading `/` via `re.sub(r&amp;#34;^\/+&amp;#34;, &amp;#34;&amp;#34;, uri)` and normalizes with `posixpath` — backslash `\` is treated as a literal character, so `\..\ secret.txt` passes through with `..` undetected.
2. `Template.__init__()` validation uses `os.path.normpath()` — on Windows this resolves `\..\ secret.txt` to `\secret.txt`, which does not start with `..`, so the `startswith(&amp;#34;..&amp;#34;)` check passes.
3. `os.path.isfile()` on Windows interprets `\` as a path separator, resolving the `..` traversal and finding files outside the template directory.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `mako/lookup.py`: `TemplateLookup.get_template()` uses `posixpath.normpath`/`posixpath.join` for path construction but `os.path.isfile()` for existence check
- `mako/template.py`: `Template.__init__()` URI validation uses `os.path.normpath…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Mako&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a mismatch between `posixpath` (used for URI normalization in `get_template()`) and `os.path` (used for file access via `os.path.isfile()` and validation via `os.path.normpath()` in `Template.__init__`). On Windows, `os.path` is `ntpath`, which treats `\` as a path separator, while `posixpath` treats it as a literal character.&lt;/p&gt;
&lt;p&gt;The vulnerability chain:&lt;/p&gt;
&lt;p&gt;1. `get_template()` strips only leading `/` via `re.sub(r&amp;#34;^\/+&amp;#34;, &amp;#34;&amp;#34;, uri)` and normalizes with `posixpath` — backslash `\` is treated as a literal character, so `\..\ secret.txt` passes through with `..` undetected.
2. `Template.__init__()` validation uses `os.path.normpath()` — on Windows this resolves `\..\ secret.txt` to `\secret.txt`, which does not start with `..`, so the `startswith(&amp;#34;..&amp;#34;)` check passes.
3. `os.path.isfile()` on Windows interprets `\` as a path separator, resolving the `..` traversal and finding files outside the template directory.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `mako/lookup.py`: `TemplateLookup.get_template()` uses `posixpath.normpath`/`posixpath.join` for path construction but `os.path.isfile()` for existence check
- `mako/template.py`: `Template.__init__()` URI validation uses `os.path.normpath…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2h4p-vjrc-8xpq</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-44307 — Mako: Path traversal via backslash URI on Windows in TemplateLookup</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-44307</link>
      <description>msrc_CVE-2026-44307</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-44307</guid>
    </item>
    <item>
      <title>PYSEC-2026-2617 — Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2617</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mako&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a mismatch between `posixpath` (used for URI normalization in `get_template()`) and `os.path` (used for file access via `os.path.isfile()` and validation via `os.path.normpath()` in `Template.__init__`). On Windows, `os.path` is `ntpath`, which treats `\` as a path separator, while `posixpath` treats it as a literal character.&lt;/p&gt;
&lt;p&gt;The vulnerability chain:&lt;/p&gt;
&lt;p&gt;1. `get_template()` strips only leading `/` via `re.sub(r&amp;#34;^\/+&amp;#34;, &amp;#34;&amp;#34;, uri)` and normalizes with `posixpath` — backslash `\` is treated as a literal character, so `\..\ secret.txt` passes through with `..` undetected.
2. `Template.__init__()` validation uses `os.path.normpath()` — on Windows this resolves `\..\ secret.txt` to `\secret.txt`, which does not start with `..`, so the `startswith(&amp;#34;..&amp;#34;)` check passes.
3. `os.path.isfile()` on Windows interprets `\` as a path separator, resolving the `..` traversal and finding files outside the template directory.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `mako/lookup.py`: `TemplateLookup.get_template()` uses `posixpath.normpath`/`posixpath.join` for path construction but `os.path.isfile()` for existence check
- `mako/template.py`: `Template.__init__()` URI validation uses `os.path.normpath…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: mako&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a mismatch between `posixpath` (used for URI normalization in `get_template()`) and `os.path` (used for file access via `os.path.isfile()` and validation via `os.path.normpath()` in `Template.__init__`). On Windows, `os.path` is `ntpath`, which treats `\` as a path separator, while `posixpath` treats it as a literal character.&lt;/p&gt;
&lt;p&gt;The vulnerability chain:&lt;/p&gt;
&lt;p&gt;1. `get_template()` strips only leading `/` via `re.sub(r&amp;#34;^\/+&amp;#34;, &amp;#34;&amp;#34;, uri)` and normalizes with `posixpath` — backslash `\` is treated as a literal character, so `\..\ secret.txt` passes through with `..` undetected.
2. `Template.__init__()` validation uses `os.path.normpath()` — on Windows this resolves `\..\ secret.txt` to `\secret.txt`, which does not start with `..`, so the `startswith(&amp;#34;..&amp;#34;)` check passes.
3. `os.path.isfile()` on Windows interprets `\` as a path separator, resolving the `..` traversal and finding files outside the template directory.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `mako/lookup.py`: `TemplateLookup.get_template()` uses `posixpath.normpath`/`posixpath.join` for path construction but `os.path.isfile()` for existence check
- `mako/template.py`: `Template.__init__()` URI validation uses `os.path.normpath…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2617</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2026-44307</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44307</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: mako, Ubuntu:Pro:18.04:LTS: mako, Ubuntu:Pro:20.04:LTS: mako, Ubuntu:22.04:LTS: mako, Ubuntu:24.04:LTS: mako, Ubuntu:25.10: mako, Ubuntu:26.04:LTS: mako&lt;/p&gt;
&lt;p&gt;Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: mako, Ubuntu:Pro:18.04:LTS: mako, Ubuntu:Pro:20.04:LTS: mako, Ubuntu:22.04:LTS: mako, Ubuntu:24.04:LTS: mako, Ubuntu:25.10: mako, Ubuntu:26.04:LTS: mako&lt;/p&gt;
&lt;p&gt;Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44307</guid>
    </item>
  </channel>
</rss>
