<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 19:27:50 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1934 — Moderate: mod_auth_mellon security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1934</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: mod_auth_mellon, AlmaLinux:8: mod_auth_mellon-diagnostics&lt;/p&gt;
&lt;p&gt;The mod_auth_mellon module for the Apache HTTP Server is an authentication service that implements the SAML 2.0 federation protocol. The module grants access based on the attributes received in assertions generated by an IdP server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mod_auth_mellon: Open Redirect vulnerability in logout URLs (CVE-2021-3639)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: mod_auth_mellon, AlmaLinux:8: mod_auth_mellon-diagnostics&lt;/p&gt;
&lt;p&gt;The mod_auth_mellon module for the Apache HTTP Server is an authentication service that implements the SAML 2.0 federation protocol. The module grants access based on the attributes received in assertions generated by an IdP server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mod_auth_mellon: Open Redirect vulnerability in logout URLs (CVE-2021-3639)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1934</guid>
    </item>
    <item>
      <title>EUVD-2026-20963</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-20963</link>
      <description>EUVD-2026-20963</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-20963</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3639</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3639</link>
      <description>&lt;p&gt;A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3639</guid>
    </item>
    <item>
      <title>GHSA-mhcv-7w89-jjj5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mhcv-7w89-jjj5</link>
      <description>&lt;p&gt;A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mhcv-7w89-jjj5</guid>
    </item>
    <item>
      <title>gsd-2021-3639</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3639</link>
      <description>gsd-2021-3639</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3639</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-3639 — A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an att…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3639</link>
      <description>msrc_CVE-2021-3639</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-3639</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13848-1 — apache2-mod_auth_mellon-0.19.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13848-1</link>
      <description>&lt;p&gt;apache2-mod_auth_mellon-0.19.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache2-mod_auth_mellon-0.19.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13848-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:2912-1 — Security update for apache2-mod_auth_mellon</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:2912-1</link>
      <description>&lt;p&gt;Security update for apache2-mod_auth_mellon&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apache2-mod_auth_mellon&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:2912-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3639</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3639</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libapache2-mod-auth-mellon, Ubuntu:18.04:LTS: libapache2-mod-auth-mellon, Ubuntu:20.04:LTS: libapache2-mod-auth-mellon, Ubuntu:22.04:LTS: libapache2-mod-auth-mellon&lt;/p&gt;
&lt;p&gt;A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libapache2-mod-auth-mellon, Ubuntu:18.04:LTS: libapache2-mod-auth-mellon, Ubuntu:20.04:LTS: libapache2-mod-auth-mellon, Ubuntu:22.04:LTS: libapache2-mod-auth-mellon&lt;/p&gt;
&lt;p&gt;A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. The highest threat from this liability is to confidentiality and integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3639</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1389 — Red Hat Enterprise Linux (mod_auth_mellon): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1389</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1389</guid>
    </item>
  </channel>
</rss>
