<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 03:56:50 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-341798</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341798</link>
      <description>EUVD-2026-341798</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341798</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56115</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56115</link>
      <description>&lt;p&gt;Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function in internal/auth/auth.go, which validates JWT tokens and account status but fails to inspect the is_admin flag. Attackers can send requests to any endpoint under the /api/users path to create new administrator accounts or reset administrator passwords, thereby gaining full control of the server and the ability to modify boot menus and installation scripts served to PXE clients.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function in internal/auth/auth.go, which validates JWT tokens and account status but fails to inspect the is_admin flag. Attackers can send requests to any endpoint under the /api/users path to create new administrator accounts or reset administrator passwords, thereby gaining full control of the server and the ability to modify boot menus and installation scripts served to PXE clients.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56115</guid>
    </item>
    <item>
      <title>GHSA-vhmp-9f3g-3f36</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vhmp-9f3g-3f36</link>
      <description>&lt;p&gt;dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer by serializing an oversized RFC6603 OPTION_PD_EXCLUDE option body. Attackers can send a crafted DHCPv6 ADVERTISE message containing an IA_PD IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix length of /121 through /128 to trigger the out-of-bounds write and potentially corrupt adjacent stack memory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer by serializing an oversized RFC6603 OPTION_PD_EXCLUDE option body. Attackers can send a crafted DHCPv6 ADVERTISE message containing an IA_PD IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix length of /121 through /128 to trigger the out-of-bounds write and potentially corrupt adjacent stack memory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vhmp-9f3g-3f36</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-56115 — Bootimus 0.1.70 Broken Access Control via JWTMiddleware Authorization Bypass</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-56115</link>
      <description>msrc_CVE-2026-56115</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-56115</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11473-1 — dhcpcd-10.5.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11473-1</link>
      <description>&lt;p&gt;dhcpcd-10.5.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dhcpcd-10.5.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11473-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23400-1 — Security update for dhcpcd</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23400-1</link>
      <description>&lt;p&gt;Security update for dhcpcd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for dhcpcd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23400-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-56115</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56115</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: dhcpcd&lt;/p&gt;
&lt;p&gt;Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function in internal/auth/auth.go, which validates JWT tokens and account status but fails to inspect the is_admin flag. Attackers can send requests to any endpoint under the /api/users path to create new administrator accounts or reset administrator passwords, thereby gaining full control of the server and the ability to modify boot menus and installation scripts served to PXE clients.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: dhcpcd&lt;/p&gt;
&lt;p&gt;Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function in internal/auth/auth.go, which validates JWT tokens and account status but fails to inspect the is_admin flag. Attackers can send requests to any endpoint under the /api/users path to create new administrator accounts or reset administrator passwords, thereby gaining full control of the server and the ability to modify boot menus and installation scripts served to PXE clients.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56115</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2046 — dhcpcd: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2046</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in dhcpcd ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in dhcpcd ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2046</guid>
    </item>
  </channel>
</rss>
