<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:04:58 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-FX79373 — Security fix for CVE-2026-48816 applied in: pulumi 3.248.0-r0, renovate 44.31.0-r2, renovate 44.32.4-r1, renovate 44.32…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fx79373</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: pulumi, CleanStart: renovate&lt;/p&gt;
&lt;p&gt;CVE-2026-48816 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: pulumi, CleanStart: renovate&lt;/p&gt;
&lt;p&gt;CVE-2026-48816 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fx79373</guid>
    </item>
    <item>
      <title>EUVD-2026-337995</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337995</link>
      <description>EUVD-2026-337995</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337995</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48816</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48816</link>
      <description>&lt;p&gt;sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind integratedTime, allowing an attacker who can supply an untrusted bundle to influence certificate validity and timestampThreshold verification decisions. This issue is fixed in version 3.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind integratedTime, allowing an attacker who can supply an untrusted bundle to influence certificate validity and timestampThreshold verification decisions. This issue is fixed in version 3.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48816</guid>
    </item>
    <item>
      <title>GHSA-xgjw-pm74-86q4 — sigstore-js has Insufficient Verification of Data Authenticity</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xgjw-pm74-86q4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @sigstore/verify&lt;/p&gt;
&lt;p&gt;sigstore-js derives a transparency-log timestamp from `tlogEntries[].integratedTime` and uses it to validate certificate validity windows and satisfy `timestampThreshold`. For bundle v0.2, a tlog entry can be inclusionProof-only (no signed inclusionPromise/set), and the inclusion proof path does not cryptographically bind `integratedTime`. As a result, an attacker who can supply an untrusted bundle can influence time-based verification decisions by choosing `integratedTime`.&lt;/p&gt;
&lt;p&gt;## impact
If a consumer accepts attacker-provided bundle v0.2 inputs and relies on tlog-derived timestamps for certificate validity checks, verification can be influenced by an unauthenticated timestamp value. This is a trust gap: `integratedTime` is treated as a trusted observer timestamp under inclusionProof-only mode even though only the signed inclusionPromise/set path binds it.&lt;/p&gt;
&lt;p&gt;## affected code
- `packages/verify/src/bundle/index.ts` (adds a transparency-log timestamp whenever `integratedTime != 0`)
- `packages/verify/src/timestamp/index.ts` (converts `integratedTime` to a `Date`)
- `packages/verify/src/verifier.ts` (verifies timestamps before verifying tlog inclusion)
- `packages/verify/src/tlog/index.ts` + `packages/verify/src/tlog/set.ts` (only the inclusionPromise/set path binds `integratedTime`)&lt;/p&gt;
&lt;p&gt;## proof of concept
The attached `poc.zip` contains a self-contained harness that reproduces the behavior on the pinned commit and includes both a canonical test and a negative control.&lt;/p&gt;
&lt;p&gt;repro:
1) ex…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @sigstore/verify&lt;/p&gt;
&lt;p&gt;sigstore-js derives a transparency-log timestamp from `tlogEntries[].integratedTime` and uses it to validate certificate validity windows and satisfy `timestampThreshold`. For bundle v0.2, a tlog entry can be inclusionProof-only (no signed inclusionPromise/set), and the inclusion proof path does not cryptographically bind `integratedTime`. As a result, an attacker who can supply an untrusted bundle can influence time-based verification decisions by choosing `integratedTime`.&lt;/p&gt;
&lt;p&gt;## impact
If a consumer accepts attacker-provided bundle v0.2 inputs and relies on tlog-derived timestamps for certificate validity checks, verification can be influenced by an unauthenticated timestamp value. This is a trust gap: `integratedTime` is treated as a trusted observer timestamp under inclusionProof-only mode even though only the signed inclusionPromise/set path binds it.&lt;/p&gt;
&lt;p&gt;## affected code
- `packages/verify/src/bundle/index.ts` (adds a transparency-log timestamp whenever `integratedTime != 0`)
- `packages/verify/src/timestamp/index.ts` (converts `integratedTime` to a `Date`)
- `packages/verify/src/verifier.ts` (verifies timestamps before verifying tlog inclusion)
- `packages/verify/src/tlog/index.ts` + `packages/verify/src/tlog/set.ts` (only the inclusionPromise/set path binds `integratedTime`)&lt;/p&gt;
&lt;p&gt;## proof of concept
The attached `poc.zip` contains a self-contained harness that reproduces the behavior on the pinned commit and includes both a canonical test and a negative control.&lt;/p&gt;
&lt;p&gt;repro:
1) ex…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xgjw-pm74-86q4</guid>
    </item>
  </channel>
</rss>
