<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:04:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-333908</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333908</link>
      <description>EUVD-2026-333908</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333908</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59153</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59153</link>
      <description>&lt;p&gt;Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59153</guid>
    </item>
    <item>
      <title>GHSA-869j-r97x-hx2g — Anki's local HTTP server does not sufficiently validate requests</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-869j-r97x-hx2g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aqt&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Anki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests.&lt;/p&gt;
&lt;p&gt;## Browser impact&lt;/p&gt;
&lt;p&gt;The severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses:&lt;/p&gt;
&lt;p&gt;Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt.
Safari: Hasn&amp;#39;t implemented PNA yet, though macOS has some OS-level protections.
Firefox: Most vulnerable — hasn&amp;#39;t implemented PNA yet, though it&amp;#39;s reportedly planned for Firefox 151.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The issue was fixed as of Anki 25.09.3&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://x.com/taviso/status/2051310678800253318&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aqt&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Anki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests.&lt;/p&gt;
&lt;p&gt;## Browser impact&lt;/p&gt;
&lt;p&gt;The severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses:&lt;/p&gt;
&lt;p&gt;Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt.
Safari: Hasn&amp;#39;t implemented PNA yet, though macOS has some OS-level protections.
Firefox: Most vulnerable — hasn&amp;#39;t implemented PNA yet, though it&amp;#39;s reportedly planned for Firefox 151.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The issue was fixed as of Anki 25.09.3&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://x.com/taviso/status/2051310678800253318&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-869j-r97x-hx2g</guid>
    </item>
    <item>
      <title>PYSEC-2026-3459 — Anki's local HTTP server does not sufficiently validate requests</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3459</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aqt&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Anki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests.&lt;/p&gt;
&lt;p&gt;## Browser impact&lt;/p&gt;
&lt;p&gt;The severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses:&lt;/p&gt;
&lt;p&gt;Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt.
Safari: Hasn&amp;#39;t implemented PNA yet, though macOS has some OS-level protections.
Firefox: Most vulnerable — hasn&amp;#39;t implemented PNA yet, though it&amp;#39;s reportedly planned for Firefox 151.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The issue was fixed as of Anki 25.09.3&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://x.com/taviso/status/2051310678800253318&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: aqt&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Anki launches a local HTTP server to serve media files and web pages for parts of its interface. While the server has a CORS setup, requests from other origins were not blocked, allowing malicious websites to potentially trigger side-effecting requests.&lt;/p&gt;
&lt;p&gt;## Browser impact&lt;/p&gt;
&lt;p&gt;The severity varies by browser because of Private Network Access (PNA), a newer spec that restricts web pages from making requests to localhost/local network addresses:&lt;/p&gt;
&lt;p&gt;Chrome/Chromium (including Edge, Brave): Largely protected, as Chrome has implemented PNA restrictions for several years and now puts local network access behind a permission prompt.
Safari: Hasn&amp;#39;t implemented PNA yet, though macOS has some OS-level protections.
Firefox: Most vulnerable — hasn&amp;#39;t implemented PNA yet, though it&amp;#39;s reportedly planned for Firefox 151.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The issue was fixed as of Anki 25.09.3&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;https://x.com/taviso/status/2051310678800253318&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3459</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59153</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59153</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: anki, Ubuntu:18.04:LTS: anki, Ubuntu:20.04:LTS: anki, Ubuntu:22.04:LTS: anki, Ubuntu:24.04:LTS: anki&lt;/p&gt;
&lt;p&gt;Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: anki, Ubuntu:18.04:LTS: anki, Ubuntu:20.04:LTS: anki, Ubuntu:22.04:LTS: anki, Ubuntu:24.04:LTS: anki&lt;/p&gt;
&lt;p&gt;Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media files and web pages for parts of its interface, but requests from other origins were not sufficiently blocked. A malicious website could potentially trigger side-effecting requests to the local server, with severity varying by browser depending on Private Network Access protections. This issue is fixed in version 25.09.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59153</guid>
    </item>
  </channel>
</rss>
