<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:39:17 +0000</lastBuildDate>
    <item>
      <title>BREW-aider-CVE-2026-48818 — Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-48818</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When serving static files on Windows, `StaticFiles` resolves the requested path with [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath). If a UNC path (such as `\\attacker.com\share`) reaches the resolver, `realpath` causes the process to open a connection to the remote host over SMB (port 445). This is a server-side request forgery (SSRF) that leaks the service account&amp;#39;s NTLMv2 credentials to the attacker-controlled host, which can then be cracked offline or relayed to other hosts.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`StaticFiles.lookup_path()` joins the requested path onto the served directory and calls [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath) on the result before checking containment with [`os.path.commonpath`](https://docs.python.org/3/library/os.path.html#os.path.commonpath). On Windows, a UNC path is absolute, so [`os.path.join`](https://docs.python.org/3/library/os.path.html#os.path.join) discards the served directory and `realpath` resolves the bare UNC path, triggering the outbound SMB connection and NTLM authentication before the containment check rejects the path. The HTTP response is a benign 404, but the credential disclosure has already happened. POSIX systems are not affected.&lt;/p&gt;
&lt;p&gt;This only affects the default configuration (`follow_symlink=False`), which uses [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath). The `follow_symlink=True` branch uses [`os.path.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When serving static files on Windows, `StaticFiles` resolves the requested path with [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath). If a UNC path (such as `\\attacker.com\share`) reaches the resolver, `realpath` causes the process to open a connection to the remote host over SMB (port 445). This is a server-side request forgery (SSRF) that leaks the service account&amp;#39;s NTLMv2 credentials to the attacker-controlled host, which can then be cracked offline or relayed to other hosts.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`StaticFiles.lookup_path()` joins the requested path onto the served directory and calls [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath) on the result before checking containment with [`os.path.commonpath`](https://docs.python.org/3/library/os.path.html#os.path.commonpath). On Windows, a UNC path is absolute, so [`os.path.join`](https://docs.python.org/3/library/os.path.html#os.path.join) discards the served directory and `realpath` resolves the bare UNC path, triggering the outbound SMB connection and NTLM authentication before the containment check rejects the path. The HTTP response is a benign 404, but the credential disclosure has already happened. POSIX systems are not affected.&lt;/p&gt;
&lt;p&gt;This only affects the default configuration (`follow_symlink=False`), which uses [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath). The `follow_symlink=True` branch uses [`os.path.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-48818</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1206 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1206</link>
      <description>certfr-2026-avi-1206</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1206</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AL63130 — Security fixes in litellm-database 1.96.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-al63130</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: litellm-database&lt;/p&gt;
&lt;p&gt;Package litellm-database version 1.96.0-r0 fixes 5 vulnerabilities: CVE-2026-54282, CVE-2025-62727, CVE-2026-48818, CVE-2026-54283, CVE-2025-54121&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: litellm-database&lt;/p&gt;
&lt;p&gt;Package litellm-database version 1.96.0-r0 fixes 5 vulnerabilities: CVE-2026-54282, CVE-2025-62727, CVE-2026-48818, CVE-2026-54283, CVE-2025-54121&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-al63130</guid>
    </item>
    <item>
      <title>EUVD-2026-344202</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344202</link>
      <description>EUVD-2026-344202</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344202</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48818</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48818</link>
      <description>&lt;p&gt;Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as FastAPI; POSIX systems and follow_symlink=True are unaffected. The issue is fixed in 1.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as FastAPI; POSIX systems and follow_symlink=True are unaffected. The issue is fixed in 1.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48818</guid>
    </item>
    <item>
      <title>GHSA-wqp7-x3pw-xc5r — Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wqp7-x3pw-xc5r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: starlette&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When serving static files on Windows, `StaticFiles` resolves the requested path with [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath). If a UNC path (such as `\\attacker.com\share`) reaches the resolver, `realpath` causes the process to open a connection to the remote host over SMB (port 445). This is a server-side request forgery (SSRF) that leaks the service account&amp;#39;s NTLMv2 credentials to the attacker-controlled host, which can then be cracked offline or relayed to other hosts.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`StaticFiles.lookup_path()` joins the requested path onto the served directory and calls [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath) on the result before checking containment with [`os.path.commonpath`](https://docs.python.org/3/library/os.path.html#os.path.commonpath). On Windows, a UNC path is absolute, so [`os.path.join`](https://docs.python.org/3/library/os.path.html#os.path.join) discards the served directory and `realpath` resolves the bare UNC path, triggering the outbound SMB connection and NTLM authentication before the containment check rejects the path. The HTTP response is a benign 404, but the credential disclosure has already happened. POSIX systems are not affected.&lt;/p&gt;
&lt;p&gt;This only affects the default configuration (`follow_symlink=False`), which uses [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath). The `follow_symlink=True` branch uses [`os.path.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: starlette&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When serving static files on Windows, `StaticFiles` resolves the requested path with [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath). If a UNC path (such as `\\attacker.com\share`) reaches the resolver, `realpath` causes the process to open a connection to the remote host over SMB (port 445). This is a server-side request forgery (SSRF) that leaks the service account&amp;#39;s NTLMv2 credentials to the attacker-controlled host, which can then be cracked offline or relayed to other hosts.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`StaticFiles.lookup_path()` joins the requested path onto the served directory and calls [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath) on the result before checking containment with [`os.path.commonpath`](https://docs.python.org/3/library/os.path.html#os.path.commonpath). On Windows, a UNC path is absolute, so [`os.path.join`](https://docs.python.org/3/library/os.path.html#os.path.join) discards the served directory and `realpath` resolves the bare UNC path, triggering the outbound SMB connection and NTLM authentication before the containment check rejects the path. The HTTP response is a benign 404, but the credential disclosure has already happened. POSIX systems are not affected.&lt;/p&gt;
&lt;p&gt;This only affects the default configuration (`follow_symlink=False`), which uses [`os.path.realpath`](https://docs.python.org/3/library/os.path.html#os.path.realpath). The `follow_symlink=True` branch uses [`os.path.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wqp7-x3pw-xc5r</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11572-1 — python313-graphifyy-0.9.48-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11572-1</link>
      <description>&lt;p&gt;python313-graphifyy-0.9.48-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-graphifyy-0.9.48-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11572-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2281</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2281</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: starlette&lt;/p&gt;
&lt;p&gt;Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as FastAPI; POSIX systems and follow_symlink=True are unaffected. The issue is fixed in 1.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: starlette&lt;/p&gt;
&lt;p&gt;Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as FastAPI; POSIX systems and follow_symlink=True are unaffected. The issue is fixed in 1.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2281</guid>
    </item>
    <item>
      <title>RHSA-2026:30087 — Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (Spyre)</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:30087</link>
      <description>&lt;p&gt;vllm: VLLM deserialization vulnerability leading to DoS and potential RCE vllm: vLLM: Remote Code Execution via malicious model configuration libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication vllm: vLLM: Denial of Service via specially crafted image in multimodal model serving vLLM: vLLM: Remote code execution via invalid image processing in the multimodal endpoint. vLLM: vLLM: Arbitrary code execution via untrusted model loading vLLM: vLLM: Server-Side Request Forgery allows internal network access OpenEXR: OpenEXR: Arbitrary code execution and information disclosure via crafted EXR file vim: arbitrary command execution via modeline sandbox bypass OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode libsndfile: integer overflow in ima_reader_init() jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers jq: jq: Denial of Service via crafted JSON object causing hash collisions urllib3: urllib3: Information discl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vllm: VLLM deserialization vulnerability leading to DoS and potential RCE vllm: vLLM: Remote Code Execution via malicious model configuration libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication vllm: vLLM: Denial of Service via specially crafted image in multimodal model serving vLLM: vLLM: Remote code execution via invalid image processing in the multimodal endpoint. vLLM: vLLM: Arbitrary code execution via untrusted model loading vLLM: vLLM: Server-Side Request Forgery allows internal network access OpenEXR: OpenEXR: Arbitrary code execution and information disclosure via crafted EXR file vim: arbitrary command execution via modeline sandbox bypass OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode libsndfile: integer overflow in ima_reader_init() jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers jq: jq: Denial of Service via crafted JSON object causing hash collisions urllib3: urllib3: Information discl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:30087</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48818</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48818</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: starlette, Ubuntu:24.04:LTS: starlette, Ubuntu:25.10: starlette, Ubuntu:26.04:LTS: starlette&lt;/p&gt;
&lt;p&gt;Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as FastAPI; POSIX systems and follow_symlink=True are unaffected. The issue is fixed in 1.1.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: starlette, Ubuntu:24.04:LTS: starlette, Ubuntu:25.10: starlette, Ubuntu:26.04:LTS: starlette&lt;/p&gt;
&lt;p&gt;Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as FastAPI; POSIX systems and follow_symlink=True are unaffected. The issue is fixed in 1.1.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48818</guid>
    </item>
  </channel>
</rss>
