<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:22:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-351921</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351921</link>
      <description>EUVD-2026-351921</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351921</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73501</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73501</link>
      <description>&lt;p&gt;kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73501</guid>
    </item>
    <item>
      <title>GHSA-r277-6w6q-xmqw — kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r277-6w6q-xmqw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/getkin/kin-openapi&lt;/p&gt;
&lt;p&gt;### Summary
`ValidationHandler.Load()` in `getkin/kin-openapi` silently replaces a nil `AuthenticationFunc` with `NoopAuthenticationFunc`, which always returns `nil` without performing any credential check. Because this substitution happens unconditionally when the caller omits the field, every OpenAPI `security` requirement declared in the spec is silently satisfied for unauthenticated requests. An unauthenticated remote attacker can reach handlers for routes whose OpenAPI operation requires an API key, OAuth token, or any other security scheme if the application relies on `ValidationHandler` as its enforcement middleware.&lt;/p&gt;
&lt;p&gt;### Details
`ValidationHandler` is an HTTP middleware exported by `openapi3filter` that validates incoming requests and responses against a loaded OpenAPI specification. Its `Load()` method initialises default fields before the handler begins serving:&lt;/p&gt;
&lt;p&gt;```go
// openapi3filter/validation_handler.go:47-49
if h.AuthenticationFunc == nil {
    h.AuthenticationFunc = NoopAuthenticationFunc
}
```&lt;/p&gt;
&lt;p&gt;`NoopAuthenticationFunc` is defined as:&lt;/p&gt;
&lt;p&gt;```go
// openapi3filter/validation_handler.go:17-18
func NoopAuthenticationFunc(context.Context, *AuthenticationInput) error { return nil }
```&lt;/p&gt;
&lt;p&gt;It always returns `nil`, meaning every security scheme check it handles is automatically approved.&lt;/p&gt;
&lt;p&gt;When a request arrives, `ServeHTTP` → `before` → `validateRequest` assembles a `RequestValidationInput` with the current `AuthenticationFunc` (now the no-op) injected into `Options`:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/getkin/kin-openapi&lt;/p&gt;
&lt;p&gt;### Summary
`ValidationHandler.Load()` in `getkin/kin-openapi` silently replaces a nil `AuthenticationFunc` with `NoopAuthenticationFunc`, which always returns `nil` without performing any credential check. Because this substitution happens unconditionally when the caller omits the field, every OpenAPI `security` requirement declared in the spec is silently satisfied for unauthenticated requests. An unauthenticated remote attacker can reach handlers for routes whose OpenAPI operation requires an API key, OAuth token, or any other security scheme if the application relies on `ValidationHandler` as its enforcement middleware.&lt;/p&gt;
&lt;p&gt;### Details
`ValidationHandler` is an HTTP middleware exported by `openapi3filter` that validates incoming requests and responses against a loaded OpenAPI specification. Its `Load()` method initialises default fields before the handler begins serving:&lt;/p&gt;
&lt;p&gt;```go
// openapi3filter/validation_handler.go:47-49
if h.AuthenticationFunc == nil {
    h.AuthenticationFunc = NoopAuthenticationFunc
}
```&lt;/p&gt;
&lt;p&gt;`NoopAuthenticationFunc` is defined as:&lt;/p&gt;
&lt;p&gt;```go
// openapi3filter/validation_handler.go:17-18
func NoopAuthenticationFunc(context.Context, *AuthenticationInput) error { return nil }
```&lt;/p&gt;
&lt;p&gt;It always returns `nil`, meaning every security scheme check it handles is automatically approved.&lt;/p&gt;
&lt;p&gt;When a request arrives, `ServeHTTP` → `before` → `validateRequest` assembles a `RequestValidationInput` with the current `AuthenticationFunc` (now the no-op) injected into `Options`:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r277-6w6q-xmqw</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11684-1 — grafana-12.4.10-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11684-1</link>
      <description>&lt;p&gt;grafana-12.4.10-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grafana-12.4.10-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11684-1</guid>
    </item>
    <item>
      <title>RHSA-2026:54549 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:54549</link>
      <description>&lt;p&gt;golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input github.com/getkin/kin-openapi: kin-openapi: kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input github.com/getkin/kin-openapi: kin-openapi: kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:54549</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-73501</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73501</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-getkin-kin-openapi, Ubuntu:24.04:LTS: golang-github-getkin-kin-openapi, Ubuntu:26.04:LTS: golang-github-getkin-kin-openapi&lt;/p&gt;
&lt;p&gt;kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-getkin-kin-openapi, Ubuntu:24.04:LTS: golang-github-getkin-kin-openapi, Ubuntu:26.04:LTS: golang-github-getkin-kin-openapi&lt;/p&gt;
&lt;p&gt;kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73501</guid>
    </item>
  </channel>
</rss>
