<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 07:45:14 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-0532 — External Control of File Name or Path and Server-Side Request Forgery (SSRF) in Kibana Google Gemini Connector</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-0532</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Elastic Kibana, Red Hat Logging Subsystem for Red Hat OpenShift, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift distributed tracing 3, Red Hat OpenStack Platform 16.2&lt;/p&gt;
&lt;p&gt;External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts &amp;amp; Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Elastic Kibana, Red Hat Logging Subsystem for Red Hat OpenShift, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat OpenShift distributed tracing 3, Red Hat OpenStack Platform 16.2&lt;/p&gt;
&lt;p&gt;External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts &amp;amp; Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-0532</guid>
    </item>
  </channel>
</rss>
