<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:12:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-354513</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-354513</link>
      <description>EUVD-2026-354513</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-354513</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45725</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45725</link>
      <description>&lt;p&gt;compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library&amp;#39;s remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location outside the intended cache directory, enabling arbitrary file write with attacker-controlled content to the filesystem. Versions 3.12.3 and 4.0.3 patch the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library&amp;#39;s remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location outside the intended cache directory, enabling arbitrary file write with attacker-controlled content to the filesystem. Versions 3.12.3 and 4.0.3 patch the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45725</guid>
    </item>
    <item>
      <title>GHSA-g3vg-vx23-3858 — compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g3vg-vx23-3858</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: compliance-trestle&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The compliance-trestle library&amp;#39;s remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location **outside the intended cache directory**, enabling **arbitrary file write with attacker-controlled content** to the filesystem.&lt;/p&gt;
&lt;p&gt;**Attack chain:** Malicious OSCAL profile → HTTPS fetch → cache path traversal → arbitrary file write → RCE (via cron, SSH keys, etc.)&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;**Repository:** https://github.com/IBM/compliance-trestle
**File:** `trestle/core/remote/cache.py` (lines 259-266 for HTTPSFetcher, lines 328-333 for SFTPFetcher)
**Version:** v4.0.2 (latest as of 2026-04-30)
## Vulnerable Code&lt;/p&gt;
&lt;p&gt;### cache.py:259-266 — HTTPSFetcher cache path construction&lt;/p&gt;
&lt;p&gt;```python
class HTTPSFetcher(FetcherBase):
    def __init__(self, trestle_root: pathlib.Path, uri: str) -&amp;gt; None:
        # ...
        u = parse.urlparse(self._uri)
        # ...
        if u.hostname is None:
            raise TrestleError(f&amp;#39;Cache request for {self._uri} requires hostname&amp;#39;)
        https_cached_dir = self._trestle_cache_path / u.hostname
        # ❌ path_parent preserves ../ sequences from URL
        path_parent = pathlib.Path(u.path[re.search(&amp;#39;[^/\\\\]&amp;#39;, u.path).span()[0] :]).parent
        https_cached_dir = https_cached_dir / path_parent…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: compliance-trestle&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The compliance-trestle library&amp;#39;s remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location **outside the intended cache directory**, enabling **arbitrary file write with attacker-controlled content** to the filesystem.&lt;/p&gt;
&lt;p&gt;**Attack chain:** Malicious OSCAL profile → HTTPS fetch → cache path traversal → arbitrary file write → RCE (via cron, SSH keys, etc.)&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;**Repository:** https://github.com/IBM/compliance-trestle
**File:** `trestle/core/remote/cache.py` (lines 259-266 for HTTPSFetcher, lines 328-333 for SFTPFetcher)
**Version:** v4.0.2 (latest as of 2026-04-30)
## Vulnerable Code&lt;/p&gt;
&lt;p&gt;### cache.py:259-266 — HTTPSFetcher cache path construction&lt;/p&gt;
&lt;p&gt;```python
class HTTPSFetcher(FetcherBase):
    def __init__(self, trestle_root: pathlib.Path, uri: str) -&amp;gt; None:
        # ...
        u = parse.urlparse(self._uri)
        # ...
        if u.hostname is None:
            raise TrestleError(f&amp;#39;Cache request for {self._uri} requires hostname&amp;#39;)
        https_cached_dir = self._trestle_cache_path / u.hostname
        # ❌ path_parent preserves ../ sequences from URL
        path_parent = pathlib.Path(u.path[re.search(&amp;#39;[^/\\\\]&amp;#39;, u.path).span()[0] :]).parent
        https_cached_dir = https_cached_dir / path_parent…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g3vg-vx23-3858</guid>
    </item>
    <item>
      <title>PYSEC-2026-2424 — compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2424</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: compliance-trestle&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The compliance-trestle library&amp;#39;s remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location **outside the intended cache directory**, enabling **arbitrary file write with attacker-controlled content** to the filesystem.&lt;/p&gt;
&lt;p&gt;**Attack chain:** Malicious OSCAL profile → HTTPS fetch → cache path traversal → arbitrary file write → RCE (via cron, SSH keys, etc.)&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;**Repository:** https://github.com/IBM/compliance-trestle
**File:** `trestle/core/remote/cache.py` (lines 259-266 for HTTPSFetcher, lines 328-333 for SFTPFetcher)
**Version:** v4.0.2 (latest as of 2026-04-30)
## Vulnerable Code&lt;/p&gt;
&lt;p&gt;### cache.py:259-266 — HTTPSFetcher cache path construction&lt;/p&gt;
&lt;p&gt;```python
class HTTPSFetcher(FetcherBase):
    def __init__(self, trestle_root: pathlib.Path, uri: str) -&amp;gt; None:
        # ...
        u = parse.urlparse(self._uri)
        # ...
        if u.hostname is None:
            raise TrestleError(f&amp;#39;Cache request for {self._uri} requires hostname&amp;#39;)
        https_cached_dir = self._trestle_cache_path / u.hostname
        # ❌ path_parent preserves ../ sequences from URL
        path_parent = pathlib.Path(u.path[re.search(&amp;#39;[^/\\\\]&amp;#39;, u.path).span()[0] :]).parent
        https_cached_dir = https_cached_dir / path_parent…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: compliance-trestle&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The compliance-trestle library&amp;#39;s remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location **outside the intended cache directory**, enabling **arbitrary file write with attacker-controlled content** to the filesystem.&lt;/p&gt;
&lt;p&gt;**Attack chain:** Malicious OSCAL profile → HTTPS fetch → cache path traversal → arbitrary file write → RCE (via cron, SSH keys, etc.)&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;**Repository:** https://github.com/IBM/compliance-trestle
**File:** `trestle/core/remote/cache.py` (lines 259-266 for HTTPSFetcher, lines 328-333 for SFTPFetcher)
**Version:** v4.0.2 (latest as of 2026-04-30)
## Vulnerable Code&lt;/p&gt;
&lt;p&gt;### cache.py:259-266 — HTTPSFetcher cache path construction&lt;/p&gt;
&lt;p&gt;```python
class HTTPSFetcher(FetcherBase):
    def __init__(self, trestle_root: pathlib.Path, uri: str) -&amp;gt; None:
        # ...
        u = parse.urlparse(self._uri)
        # ...
        if u.hostname is None:
            raise TrestleError(f&amp;#39;Cache request for {self._uri} requires hostname&amp;#39;)
        https_cached_dir = self._trestle_cache_path / u.hostname
        # ❌ path_parent preserves ../ sequences from URL
        path_parent = pathlib.Path(u.path[re.search(&amp;#39;[^/\\\\]&amp;#39;, u.path).span()[0] :]).parent
        https_cached_dir = https_cached_dir / path_parent…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2424</guid>
    </item>
  </channel>
</rss>
