<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:21:31 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-FA26777 — Security fix for CVE-2026-48096 applied in: grafana 12.2.10-r1, grafana 12.3.10-r1, pmm 3.5.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fa26777</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: grafana, CleanStart: pmm&lt;/p&gt;
&lt;p&gt;CVE-2026-48096 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: grafana, CleanStart: pmm&lt;/p&gt;
&lt;p&gt;CVE-2026-48096 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fa26777</guid>
    </item>
    <item>
      <title>EUVD-2026-326539</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326539</link>
      <description>EUVD-2026-326539</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326539</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48096</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48096</link>
      <description>&lt;p&gt;OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48096</guid>
    </item>
    <item>
      <title>GHSA-8396-jffm-qx4w — OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorizat…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8396-jffm-qx4w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openfga/openfga&lt;/p&gt;
&lt;p&gt;### Description
In OpenFGA, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request.&lt;/p&gt;
&lt;p&gt;### Preconditions
This applies if the following preconditions are present:&lt;/p&gt;
&lt;p&gt;- FGA runs with SharedIteratorCache enabled,
- FGA runs with ListObjectsIteratorCache enabled.&lt;/p&gt;
&lt;p&gt;### Fix
Upgrade to version 1.16.0 or greater.&lt;/p&gt;
&lt;p&gt;### Acknowledgements
OpenFGA would like to thank @j4xT for the discovery and the detailed report.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/openfga/openfga&lt;/p&gt;
&lt;p&gt;### Description
In OpenFGA, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request.&lt;/p&gt;
&lt;p&gt;### Preconditions
This applies if the following preconditions are present:&lt;/p&gt;
&lt;p&gt;- FGA runs with SharedIteratorCache enabled,
- FGA runs with ListObjectsIteratorCache enabled.&lt;/p&gt;
&lt;p&gt;### Fix
Upgrade to version 1.16.0 or greater.&lt;/p&gt;
&lt;p&gt;### Acknowledgements
OpenFGA would like to thank @j4xT for the discovery and the detailed report.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8396-jffm-qx4w</guid>
    </item>
  </channel>
</rss>
