<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:43:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-349351</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349351</link>
      <description>EUVD-2026-349351</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349351</guid>
    </item>
    <item>
      <title>fkie_cve-2026-62996</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-62996</link>
      <description>&lt;p&gt;Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty&amp;#39;s stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped resource name to be used to read the contents of arbitrary local files accessible to the PHP process. An attacker able to author or influence a template&amp;#39;s resource reference could exploit this to disclose sensitive file contents outside the intended template/config scope. This issue is fixed in version 5.8.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty&amp;#39;s stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped resource name to be used to read the contents of arbitrary local files accessible to the PHP process. An attacker able to author or influence a template&amp;#39;s resource reference could exploit this to disclose sensitive file contents outside the intended template/config scope. This issue is fixed in version 5.8.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-62996</guid>
    </item>
    <item>
      <title>GHSA-rjhh-76wf-8xmw — Smarty Security stream restriction bypass through stream: resource</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rjhh-76wf-8xmw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: smarty/smarty&lt;/p&gt;
&lt;p&gt;`smarty/smarty` version `5.8.0` can read local files through PHP stream wrappers even when Smarty Security is enabled and all streams are disabled with `Security::$streams = null`.&lt;/p&gt;
&lt;p&gt;The bypass uses Smarty&amp;#39;s built-in `stream:` resource type. A template such as:&lt;/p&gt;
&lt;p&gt;```smarty
{include file=&amp;#34;stream:php://filter/read=convert.base64-encode/resource=/tmp/secret.tpl&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;is handled as Smarty resource type `stream`, so the security check that would normally reject the underlying `php` wrapper is not applied. `StreamPlugin` then opens the nested `php://filter/...` URI directly.&lt;/p&gt;
&lt;p&gt;For comparison, the direct resource:&lt;/p&gt;
&lt;p&gt;```smarty
{include file=&amp;#34;php://filter/read=convert.base64-encode/resource=/tmp/secret.tpl&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;is blocked with `stream &amp;#39;php&amp;#39; not allowed by security setting`.&lt;/p&gt;
&lt;p&gt;Affected package:&lt;/p&gt;
&lt;p&gt;- Ecosystem: Packagist / Composer
- Package: `smarty/smarty`
- Confirmed affected version: `5.8.0`
- Confirmed source reference from Composer lock: `78d259d3b971c59a0cd719c270cc5cbb740c36a7`
- Current stable version on Packagist at review time: `v5.8.0`
- Packagist usage at review time: 41,113,855 total downloads and 840,604 monthly downloads&lt;/p&gt;
&lt;p&gt;Relevant code paths:&lt;/p&gt;
&lt;p&gt;- `Smarty\Resource\BasePlugin::load(...)`
- `Smarty\Resource\StreamPlugin::getContent(...)`
- `Smarty\Security::isTrustedStream(...)`&lt;/p&gt;
&lt;p&gt;`BasePlugin::load()` maps the built-in resource name `stream` directly to `StreamPlugin` before the code path that checks PHP stream wrappers with `stream_get_wrappers()` and `Security::isTrustedStream…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: smarty/smarty&lt;/p&gt;
&lt;p&gt;`smarty/smarty` version `5.8.0` can read local files through PHP stream wrappers even when Smarty Security is enabled and all streams are disabled with `Security::$streams = null`.&lt;/p&gt;
&lt;p&gt;The bypass uses Smarty&amp;#39;s built-in `stream:` resource type. A template such as:&lt;/p&gt;
&lt;p&gt;```smarty
{include file=&amp;#34;stream:php://filter/read=convert.base64-encode/resource=/tmp/secret.tpl&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;is handled as Smarty resource type `stream`, so the security check that would normally reject the underlying `php` wrapper is not applied. `StreamPlugin` then opens the nested `php://filter/...` URI directly.&lt;/p&gt;
&lt;p&gt;For comparison, the direct resource:&lt;/p&gt;
&lt;p&gt;```smarty
{include file=&amp;#34;php://filter/read=convert.base64-encode/resource=/tmp/secret.tpl&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;is blocked with `stream &amp;#39;php&amp;#39; not allowed by security setting`.&lt;/p&gt;
&lt;p&gt;Affected package:&lt;/p&gt;
&lt;p&gt;- Ecosystem: Packagist / Composer
- Package: `smarty/smarty`
- Confirmed affected version: `5.8.0`
- Confirmed source reference from Composer lock: `78d259d3b971c59a0cd719c270cc5cbb740c36a7`
- Current stable version on Packagist at review time: `v5.8.0`
- Packagist usage at review time: 41,113,855 total downloads and 840,604 monthly downloads&lt;/p&gt;
&lt;p&gt;Relevant code paths:&lt;/p&gt;
&lt;p&gt;- `Smarty\Resource\BasePlugin::load(...)`
- `Smarty\Resource\StreamPlugin::getContent(...)`
- `Smarty\Security::isTrustedStream(...)`&lt;/p&gt;
&lt;p&gt;`BasePlugin::load()` maps the built-in resource name `stream` directly to `StreamPlugin` before the code path that checks PHP stream wrappers with `stream_get_wrappers()` and `Security::isTrustedStream…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rjhh-76wf-8xmw</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-62996</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-62996</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: smarty3, Ubuntu:Pro:18.04:LTS: smarty3, Ubuntu:Pro:20.04:LTS: smarty3, Ubuntu:22.04:LTS: smarty3, Ubuntu:24.04:LTS: smarty3, Ubuntu:24.04:LTS: smarty4, Ubuntu:26.04:LTS: smarty3, Ubuntu:26.04:LTS: smarty4&lt;/p&gt;
&lt;p&gt;Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty&amp;#39;s stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped resource name to be used to read the contents of arbitrary local files accessible to the PHP process. An attacker able to author or influence a template&amp;#39;s resource reference could exploit this to disclose sensitive file contents outside the intended template/config scope. This issue is fixed in version 5.8.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: smarty3, Ubuntu:Pro:18.04:LTS: smarty3, Ubuntu:Pro:20.04:LTS: smarty3, Ubuntu:22.04:LTS: smarty3, Ubuntu:24.04:LTS: smarty3, Ubuntu:24.04:LTS: smarty4, Ubuntu:26.04:LTS: smarty3, Ubuntu:26.04:LTS: smarty4&lt;/p&gt;
&lt;p&gt;Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty&amp;#39;s stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped resource name to be used to read the contents of arbitrary local files accessible to the PHP process. An attacker able to author or influence a template&amp;#39;s resource reference could exploit this to disclose sensitive file contents outside the intended template/config scope. This issue is fixed in version 5.8.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-62996</guid>
    </item>
  </channel>
</rss>
