<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:29:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15328</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15328</link>
      <description>bdu:2026-15328</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15328</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0783 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783</link>
      <description>certfr-2026-avi-0783</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0783</guid>
    </item>
    <item>
      <title>EUVD-2026-340594</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-340594</link>
      <description>EUVD-2026-340594</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-340594</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48858</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48858</link>
      <description>&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address.&lt;/p&gt;
&lt;p&gt;The ftp_internal:handle_ctrl_result/2 PASV handler (mode=passive, ipfamily=inet, ftp_extension=false) extracts the IP address from the server&amp;#39;s 227 response and passes it directly to gen_tcp:connect/4 without validating it against the control connection peer address. The adjacent EPSV handlers correctly call peername(CSock) to derive the IP from the control connection, but the PASV handler does not. A malicious or compromised FTP server can redirect the client&amp;#39;s data connection to an arbitrary internal host and port. On read operations (ftp:ls/1,2, ftp:nlist/1,2, ftp:recv/2,3), data from the redirected target is returned to the caller. On write operations (ftp:send/2,3, ftp:append/2,3), file content is sent to the redirected target. This enables SSRF against internal hosts, cloud metadata endpoints, and FTP bounce attacks against third-party hosts.&lt;/p&gt;
&lt;p&gt;The vulnerable path is the default configuration (mode=passive, ipfamily=inet, ftp_extension=false). RFC 2577 section 3 explicitly recommends validating the PASV response IP against the control connection peer.&lt;/p&gt;
&lt;p&gt;The ftp application is deprecated and scheduled for removal in OTP-30.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/inets/src/ftp/ftp_internal.erl (inets 5.10.4 through 6.5, OTP 17.4 through 20.3) and lib/ftp/src/ftp_internal.erl (ftp 1.0 and…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address.&lt;/p&gt;
&lt;p&gt;The ftp_internal:handle_ctrl_result/2 PASV handler (mode=passive, ipfamily=inet, ftp_extension=false) extracts the IP address from the server&amp;#39;s 227 response and passes it directly to gen_tcp:connect/4 without validating it against the control connection peer address. The adjacent EPSV handlers correctly call peername(CSock) to derive the IP from the control connection, but the PASV handler does not. A malicious or compromised FTP server can redirect the client&amp;#39;s data connection to an arbitrary internal host and port. On read operations (ftp:ls/1,2, ftp:nlist/1,2, ftp:recv/2,3), data from the redirected target is returned to the caller. On write operations (ftp:send/2,3, ftp:append/2,3), file content is sent to the redirected target. This enables SSRF against internal hosts, cloud metadata endpoints, and FTP bounce attacks against third-party hosts.&lt;/p&gt;
&lt;p&gt;The vulnerable path is the default configuration (mode=passive, ipfamily=inet, ftp_extension=false). RFC 2577 section 3 explicitly recommends validating the PASV response IP against the control connection peer.&lt;/p&gt;
&lt;p&gt;The ftp application is deprecated and scheduled for removal in OTP-30.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/inets/src/ftp/ftp_internal.erl (inets 5.10.4 through 6.5, OTP 17.4 through 20.3) and lib/ftp/src/ftp_internal.erl (ftp 1.0 and…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48858</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-48858 — ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-48858</link>
      <description>msrc_CVE-2026-48858</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-48858</guid>
    </item>
    <item>
      <title>OESA-2026-3041 — erlang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3041</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: erlang&lt;/p&gt;
&lt;p&gt;Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.&lt;/p&gt;
&lt;p&gt;The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.&lt;/p&gt;
&lt;p&gt;The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 17.0 before 29.0.2, 28.5.0.2 and 27.3.4.13 corresponding to ssh from 3.0.1 before 6.0.1, 5.5.2.1 and 5.2.11.8.(CVE-2026-48855)&lt;/p&gt;
&lt;p&gt;Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data.&lt;/p&gt;
&lt;p&gt;The httpc client forwards the Authorization and P…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: erlang&lt;/p&gt;
&lt;p&gt;Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.&lt;/p&gt;
&lt;p&gt;The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.&lt;/p&gt;
&lt;p&gt;The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 17.0 before 29.0.2, 28.5.0.2 and 27.3.4.13 corresponding to ssh from 3.0.1 before 6.0.1, 5.5.2.1 and 5.2.11.8.(CVE-2026-48855)&lt;/p&gt;
&lt;p&gt;Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data.&lt;/p&gt;
&lt;p&gt;The httpc client forwards the Authorization and P…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3041</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11559-1 — erlang-28.5.0.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11559-1</link>
      <description>&lt;p&gt;erlang-28.5.0.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;erlang-28.5.0.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11559-1</guid>
    </item>
    <item>
      <title>RHSA-2026:63160 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:63160</link>
      <description>&lt;p&gt;erlang: Erlang OTP public_key: Certificate chain forgery via improper trust chain validation erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing erlang: Erlang OTP: Authentication bypass due to improper OCSP certificate validation erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP erlang: erlang-inets: erlang-ftp: Erlang/OTP ftp: Server-Side Request Forgery (SSRF) via unvalidated PASV response IP address erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk erlang: Erlang OTP ssh: Denial of Service via infinite loop in SFTP channel erlang: Erlang SSL: Unauthenticated data injection during TLS handshake erlang: Erlang/OTP: Denial of Service in TLS 1.3 session ticket handling erlang: Erlang/OTP: Remote denial of service via signed length overflow in TCP driver&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;erlang: Erlang OTP public_key: Certificate chain forgery via improper trust chain validation erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing erlang: Erlang OTP: Authentication bypass due to improper OCSP certificate validation erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP erlang: erlang-inets: erlang-ftp: Erlang/OTP ftp: Server-Side Request Forgery (SSRF) via unvalidated PASV response IP address erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk erlang: Erlang OTP ssh: Denial of Service via infinite loop in SFTP channel erlang: Erlang SSL: Unauthenticated data injection during TLS handshake erlang: Erlang/OTP: Denial of Service in TLS 1.3 session ticket handling erlang: Erlang/OTP: Remote denial of service via signed length overflow in TCP driver&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:63160</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48858</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48858</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: erlang, Ubuntu:Pro:16.04:LTS: erlang, Ubuntu:Pro:18.04:LTS: erlang, Ubuntu:Pro:20.04:LTS: erlang, Ubuntu:22.04:LTS: erlang, Ubuntu:24.04:LTS: erlang, Ubuntu:25.10: erlang, Ubuntu:26.04:LTS: erlang&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_result/2 PASV handler (mode=passive, ipfamily=inet, ftp_extension=false) extracts the IP address from the server&amp;#39;s 227 response and passes it directly to gen_tcp:connect/4 without validating it against the control connection peer address. The adjacent EPSV handlers correctly call peername(CSock) to derive the IP from the control connection, but the PASV handler does not. A malicious or compromised FTP server can redirect the client&amp;#39;s data connection to an arbitrary internal host and port. On read operations (ftp:ls/1,2, ftp:nlist/1,2, ftp:recv/2,3), data from the redirected target is returned to the caller. On write operations (ftp:send/2,3, ftp:append/2,3), file content is sent to the redirected target. This enables SSRF against internal hosts, cloud metadata endpoints, and FTP bounce attacks against third-party hosts. The vulnerable path is the default configuration (mode=passive, ipfamily=inet, ftp_extension=false). RFC 2577 section 3 explicitly recommends validating the PASV response IP against the control connection peer. The ftp application is deprecated and scheduled for removal in OTP-30. This vulnerability is associated with program files lib/inets/src/ftp/ftp_internal.erl (inets 5.10.4 through 6.5, OTP 17.4 through 20.3) and lib/ftp/src/ftp_internal.erl (ftp 1.0 and late…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: erlang, Ubuntu:Pro:16.04:LTS: erlang, Ubuntu:Pro:18.04:LTS: erlang, Ubuntu:Pro:20.04:LTS: erlang, Ubuntu:22.04:LTS: erlang, Ubuntu:24.04:LTS: erlang, Ubuntu:25.10: erlang, Ubuntu:26.04:LTS: erlang&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_result/2 PASV handler (mode=passive, ipfamily=inet, ftp_extension=false) extracts the IP address from the server&amp;#39;s 227 response and passes it directly to gen_tcp:connect/4 without validating it against the control connection peer address. The adjacent EPSV handlers correctly call peername(CSock) to derive the IP from the control connection, but the PASV handler does not. A malicious or compromised FTP server can redirect the client&amp;#39;s data connection to an arbitrary internal host and port. On read operations (ftp:ls/1,2, ftp:nlist/1,2, ftp:recv/2,3), data from the redirected target is returned to the caller. On write operations (ftp:send/2,3, ftp:append/2,3), file content is sent to the redirected target. This enables SSRF against internal hosts, cloud metadata endpoints, and FTP bounce attacks against third-party hosts. The vulnerable path is the default configuration (mode=passive, ipfamily=inet, ftp_extension=false). RFC 2577 section 3 explicitly recommends validating the PASV response IP against the control connection peer. The ftp application is deprecated and scheduled for removal in OTP-30. This vulnerability is associated with program files lib/inets/src/ftp/ftp_internal.erl (inets 5.10.4 through 6.5, OTP 17.4 through 20.3) and lib/ftp/src/ftp_internal.erl (ftp 1.0 and late…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48858</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1887 — Erlang/OTP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1887</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Erlang/OTP ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Erlang/OTP ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1887</guid>
    </item>
  </channel>
</rss>
