<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:16:00 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-357245</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357245</link>
      <description>EUVD-2026-357245</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357245</guid>
    </item>
    <item>
      <title>fkie_cve-2026-67448</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67448</link>
      <description>&lt;p&gt;Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit&amp;#39;s server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go&amp;#39;s ServeMux routes using the percent-decoded URL path, and server/websockets/client.go configures websocket.Upgrader.CheckOrigin to return true. A malicious website can request /%61pi/events, skip corsOriginAccessControl(), reach the /api/events WebSocket handler, and receive live message IDs, Message-Id values, sender and recipient fields, subjects, tags, and body snippets from an unauthenticated default Mailpit instance after the user visits the site. This is a regression of the earlier WebSocket origin protection and does not affect deployments protected by --ui-auth-file. This issue is fixed in version 1.30.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit&amp;#39;s server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go&amp;#39;s ServeMux routes using the percent-decoded URL path, and server/websockets/client.go configures websocket.Upgrader.CheckOrigin to return true. A malicious website can request /%61pi/events, skip corsOriginAccessControl(), reach the /api/events WebSocket handler, and receive live message IDs, Message-Id values, sender and recipient fields, subjects, tags, and body snippets from an unauthenticated default Mailpit instance after the user visits the site. This is a regression of the earlier WebSocket origin protection and does not affect deployments protected by --ui-auth-file. This issue is fixed in version 1.30.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-67448</guid>
    </item>
    <item>
      <title>GHSA-8r62-w5wh-fc5m — Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8r62-w5wh-fc5m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/axllent/mailpit&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The cross-site WebSocket hijacking fix was reimplemented as an origin check gated on a raw-URI prefix test, but Go&amp;#39;s ServeMux routes on the percent-decoded path, so requesting /%61pi/events reaches the WebSocket handler while skipping the only origin control, and the upgrader itself accepts every origin. Confirmed at HEAD 408b30d. Affects 1.29.0 through 1.30.5.&lt;/p&gt;
&lt;p&gt;## The defect&lt;/p&gt;
&lt;p&gt;Two halves that were each correct in isolation. server/websockets/client.go accepts any origin and delegates the check elsewhere:&lt;/p&gt;
&lt;p&gt;```go
var upgrader = websocket.Upgrader{                       // line 33
    ...
    CheckOrigin: func(_ *http.Request) bool {            // line 37
        // origin is checked via server.go&amp;#39;s CORS settings
        return true                                      // line 39
    },
}
```&lt;/p&gt;
&lt;p&gt;server/server.go performs that check but keys it on the RAW request target:&lt;/p&gt;
&lt;p&gt;```go
if strings.HasPrefix(r.RequestURI, config.Webroot+&amp;#34;api/&amp;#34;) || htmlPreviewRouteRe.MatchString(r.RequestURI) {   // line 320
    if allowed := corsOriginAccessControl(r); !allowed {
        http.Error(w, &amp;#34;Blocked due to CORS violation&amp;#34;, http.StatusForbidden)
        return
    }
```&lt;/p&gt;
&lt;p&gt;r.RequestURI is the untouched wire target; Go&amp;#39;s ServeMux routes on the percent-DECODED path. So for /%61pi/events: `strings.HasPrefix(&amp;#34;/%61pi/events&amp;#34;, &amp;#34;/api/&amp;#34;)` is FALSE (origin check skipped), ServeMux decodes %61 to &amp;#34;a&amp;#34; and routes to /api/events, and the upgrader&amp;#39;s CheckOrigin returns true.&lt;/p&gt;
&lt;p&gt;Measured, default config,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/axllent/mailpit&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The cross-site WebSocket hijacking fix was reimplemented as an origin check gated on a raw-URI prefix test, but Go&amp;#39;s ServeMux routes on the percent-decoded path, so requesting /%61pi/events reaches the WebSocket handler while skipping the only origin control, and the upgrader itself accepts every origin. Confirmed at HEAD 408b30d. Affects 1.29.0 through 1.30.5.&lt;/p&gt;
&lt;p&gt;## The defect&lt;/p&gt;
&lt;p&gt;Two halves that were each correct in isolation. server/websockets/client.go accepts any origin and delegates the check elsewhere:&lt;/p&gt;
&lt;p&gt;```go
var upgrader = websocket.Upgrader{                       // line 33
    ...
    CheckOrigin: func(_ *http.Request) bool {            // line 37
        // origin is checked via server.go&amp;#39;s CORS settings
        return true                                      // line 39
    },
}
```&lt;/p&gt;
&lt;p&gt;server/server.go performs that check but keys it on the RAW request target:&lt;/p&gt;
&lt;p&gt;```go
if strings.HasPrefix(r.RequestURI, config.Webroot+&amp;#34;api/&amp;#34;) || htmlPreviewRouteRe.MatchString(r.RequestURI) {   // line 320
    if allowed := corsOriginAccessControl(r); !allowed {
        http.Error(w, &amp;#34;Blocked due to CORS violation&amp;#34;, http.StatusForbidden)
        return
    }
```&lt;/p&gt;
&lt;p&gt;r.RequestURI is the untouched wire target; Go&amp;#39;s ServeMux routes on the percent-DECODED path. So for /%61pi/events: `strings.HasPrefix(&amp;#34;/%61pi/events&amp;#34;, &amp;#34;/api/&amp;#34;)` is FALSE (origin check skipped), ServeMux decodes %61 to &amp;#34;a&amp;#34; and routes to /api/events, and the upgrader&amp;#39;s CheckOrigin returns true.&lt;/p&gt;
&lt;p&gt;Measured, default config,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8r62-w5wh-fc5m</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2556 — MailPit: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2556</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in MailPit ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in MailPit ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2556</guid>
    </item>
  </channel>
</rss>
