<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:27:28 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15326</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15326</link>
      <description>bdu:2026-15326</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15326</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0783 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783</link>
      <description>certfr-2026-avi-0783</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783</guid>
    </item>
    <item>
      <title>EUVD-2026-375439</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-375439</link>
      <description>EUVD-2026-375439</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-375439</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48855</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48855</link>
      <description>&lt;p&gt;Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.&lt;/p&gt;
&lt;p&gt;The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.&lt;/p&gt;
&lt;p&gt;The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssh from 3.0.1 before 5.2.11.8, 5.5.2.1, and 6.0.1. Whether OTP before OTP 17.0, corresponding to ssh before 3.0.1, is affected is unknown.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.&lt;/p&gt;
&lt;p&gt;The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.&lt;/p&gt;
&lt;p&gt;The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssh from 3.0.1 before 5.2.11.8, 5.5.2.1, and 6.0.1. Whether OTP before OTP 17.0, corresponding to ssh before 3.0.1, is affected is unknown.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48855</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-48855 — SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-48855</link>
      <description>msrc_CVE-2026-48855</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-48855</guid>
    </item>
    <item>
      <title>OESA-2026-3041 — erlang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3041</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: erlang&lt;/p&gt;
&lt;p&gt;Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.&lt;/p&gt;
&lt;p&gt;The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.&lt;/p&gt;
&lt;p&gt;The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 17.0 before 29.0.2, 28.5.0.2 and 27.3.4.13 corresponding to ssh from 3.0.1 before 6.0.1, 5.5.2.1 and 5.2.11.8.(CVE-2026-48855)&lt;/p&gt;
&lt;p&gt;Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data.&lt;/p&gt;
&lt;p&gt;The httpc client forwards the Authorization and P…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: erlang&lt;/p&gt;
&lt;p&gt;Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.&lt;/p&gt;
&lt;p&gt;The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.&lt;/p&gt;
&lt;p&gt;The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 17.0 before 29.0.2, 28.5.0.2 and 27.3.4.13 corresponding to ssh from 3.0.1 before 6.0.1, 5.5.2.1 and 5.2.11.8.(CVE-2026-48855)&lt;/p&gt;
&lt;p&gt;Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data.&lt;/p&gt;
&lt;p&gt;The httpc client forwards the Authorization and P…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3041</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11559-1 — erlang-28.5.0.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11559-1</link>
      <description>&lt;p&gt;erlang-28.5.0.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;erlang-28.5.0.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11559-1</guid>
    </item>
    <item>
      <title>RHSA-2026:63160 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:63160</link>
      <description>&lt;p&gt;erlang: Erlang OTP public_key: Certificate chain forgery via improper trust chain validation erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing erlang: Erlang OTP: Authentication bypass due to improper OCSP certificate validation erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP erlang: erlang-inets: erlang-ftp: Erlang/OTP ftp: Server-Side Request Forgery (SSRF) via unvalidated PASV response IP address erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk erlang: Erlang OTP ssh: Denial of Service via infinite loop in SFTP channel erlang: Erlang SSL: Unauthenticated data injection during TLS handshake erlang: Erlang/OTP: Denial of Service in TLS 1.3 session ticket handling erlang: Erlang/OTP: Remote denial of service via signed length overflow in TCP driver&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;erlang: Erlang OTP public_key: Certificate chain forgery via improper trust chain validation erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing erlang: Erlang OTP: Authentication bypass due to improper OCSP certificate validation erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP erlang: erlang-inets: erlang-ftp: Erlang/OTP ftp: Server-Side Request Forgery (SSRF) via unvalidated PASV response IP address erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk erlang: Erlang OTP ssh: Denial of Service via infinite loop in SFTP channel erlang: Erlang SSL: Unauthenticated data injection during TLS handshake erlang: Erlang/OTP: Denial of Service in TLS 1.3 session ticket handling erlang: Erlang/OTP: Remote denial of service via signed length overflow in TCP driver&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:63160</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48855</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48855</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: erlang, Ubuntu:Pro:16.04:LTS: erlang, Ubuntu:Pro:18.04:LTS: erlang, Ubuntu:Pro:20.04:LTS: erlang, Ubuntu:22.04:LTS: erlang, Ubuntu:24.04:LTS: erlang, Ubuntu:25.10: erlang, Ubuntu:26.04:LTS: erlang&lt;/p&gt;
&lt;p&gt;Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /. The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssh from 3.0.1 before 5.2.11.8, 5.5.2.1, and 6.0.1. Whether OTP before OTP 17.0, corresponding to ssh before 3.0.1, is affected is unknown.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: erlang, Ubuntu:Pro:16.04:LTS: erlang, Ubuntu:Pro:18.04:LTS: erlang, Ubuntu:Pro:20.04:LTS: erlang, Ubuntu:22.04:LTS: erlang, Ubuntu:24.04:LTS: erlang, Ubuntu:25.10: erlang, Ubuntu:26.04:LTS: erlang&lt;/p&gt;
&lt;p&gt;Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /. The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to ssh from 3.0.1 before 5.2.11.8, 5.5.2.1, and 6.0.1. Whether OTP before OTP 17.0, corresponding to ssh before 3.0.1, is affected is unknown.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48855</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1887 — Erlang/OTP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1887</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Erlang/OTP ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Erlang/OTP ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1887</guid>
    </item>
  </channel>
</rss>
