<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 06:32:10 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-227290</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-227290</link>
      <description>EUVD-2026-227290</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-227290</guid>
    </item>
    <item>
      <title>fkie_cve-2025-32013</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-32013</link>
      <description>&lt;p&gt;LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits&amp;#39; LNURL authentication handling functionality. When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn&amp;#39;t properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits&amp;#39; LNURL authentication handling functionality. When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn&amp;#39;t properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-32013</guid>
    </item>
    <item>
      <title>GHSA-qp8j-p87f-c8cc — LNbits Lightning Network Payment System Vulnerable to Server-Side Request Forgery via LNURL Authentication Callback</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qp8j-p87f-c8cc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lnbits&lt;/p&gt;
&lt;p&gt;# Server-Side Request Forgery via LNURL Authentication Callback in LNbits Lightning Network Payment System&lt;/p&gt;
&lt;p&gt;## Disclaimer&lt;/p&gt;
&lt;p&gt;This vulnerability was detected using **[XBOW](https://xbow.com/)**, a system that autonomously finds and exploits potential security vulnerabilities. The finding has been thoroughly reviewed and validated by a security researcher before submission. While XBOW is intended to work autonomously, during its development human experts ensure the accuracy and relevance of its reports.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits&amp;#39; LNURL authentication handling functionality. The vulnerability exists in the LNURL authentication callback process where the application makes HTTP requests to user-provided callback URLs and follows redirects without proper validation.&lt;/p&gt;
&lt;p&gt;When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn&amp;#39;t properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.&lt;/p&gt;
&lt;p&gt;This vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal network locations, potentially exposing sensitive information or accessing internal services that should not be accessible from the internet.&lt;/p&gt;
&lt;p&gt;## Steps to Reproduce&lt;/p&gt;
&lt;p&gt;1. Create a new wallet account to get an admin k…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lnbits&lt;/p&gt;
&lt;p&gt;# Server-Side Request Forgery via LNURL Authentication Callback in LNbits Lightning Network Payment System&lt;/p&gt;
&lt;p&gt;## Disclaimer&lt;/p&gt;
&lt;p&gt;This vulnerability was detected using **[XBOW](https://xbow.com/)**, a system that autonomously finds and exploits potential security vulnerabilities. The finding has been thoroughly reviewed and validated by a security researcher before submission. While XBOW is intended to work autonomously, during its development human experts ensure the accuracy and relevance of its reports.&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits&amp;#39; LNURL authentication handling functionality. The vulnerability exists in the LNURL authentication callback process where the application makes HTTP requests to user-provided callback URLs and follows redirects without proper validation.&lt;/p&gt;
&lt;p&gt;When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn&amp;#39;t properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.&lt;/p&gt;
&lt;p&gt;This vulnerability allows an attacker to make the application send HTTP requests to arbitrary internal network locations, potentially exposing sensitive information or accessing internal services that should not be accessible from the internet.&lt;/p&gt;
&lt;p&gt;## Steps to Reproduce&lt;/p&gt;
&lt;p&gt;1. Create a new wallet account to get an admin k…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qp8j-p87f-c8cc</guid>
    </item>
    <item>
      <title>PYSEC-2025-16</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2025-16</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lnbits&lt;/p&gt;
&lt;p&gt;LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits&amp;#39; LNURL authentication handling functionality. When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn&amp;#39;t properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: lnbits&lt;/p&gt;
&lt;p&gt;LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits&amp;#39; LNURL authentication handling functionality. When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn&amp;#39;t properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2025-16</guid>
    </item>
  </channel>
</rss>
