<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 22:14:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-267177</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267177</link>
      <description>EUVD-2026-267177</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267177</guid>
    </item>
    <item>
      <title>fkie_cve-2025-65017</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-65017</link>
      <description>&lt;p&gt;Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data exports can lead to data leaks in case the UUID generation, causing collisions for the generated UUIDs. This issue has been patched in versions 0.30.4 and 0.31.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data exports can lead to data leaks in case the UUID generation, causing collisions for the generated UUIDs. This issue has been patched in versions 0.30.4 and 0.31.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-65017</guid>
    </item>
    <item>
      <title>GHSA-3cx6-j9j4-54mp — Decidim's private data exports can lead to data leaks</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3cx6-j9j4-54mp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: decidim-core, RubyGems: decidim&lt;/p&gt;
&lt;p&gt;### Impact
Private data exports can lead to data leaks in cases where the UUID generation causes collisions for the generated UUIDs.&lt;/p&gt;
&lt;p&gt;The bug was introduced by #13571 and affects Decidim versions 0.30.0 or newer (currently 2025-09-23).&lt;/p&gt;
&lt;p&gt;This issue  was discovered by running the following spec several times in a row, as it can randomly fail due to this bug:&lt;/p&gt;
&lt;p&gt;```bash
$ cd decidim-core
$ for i in {1..10}; do bundle exec rspec spec/jobs/decidim/download_your_data_export_job_spec.rb -e &amp;#34;deletes the&amp;#34; || break ; done
```&lt;/p&gt;
&lt;p&gt;Run the spec as many times as needed to hit a UUID that converts to `0` through `.to_i`.&lt;/p&gt;
&lt;p&gt;The UUID to zero conversion does not cause a security issue but the security issue is demonstrated with the following example.&lt;/p&gt;
&lt;p&gt;The following code regenerates the issue by assigning a predefined UUID that will generate a collision (example assumes there are already two existing users in the system):&lt;/p&gt;
&lt;p&gt;```ruby
# Create the ZIP buffers to be stored
buffer1 = Zip::OutputStream.write_buffer do |out|
  out.put_next_entry(&amp;#34;admin.txt&amp;#34;)
  out.write &amp;#34;Hello, admin!&amp;#34;
end
buffer1.rewind
buffer2 = Zip::OutputStream.write_buffer do |out|
  out.put_next_entry(&amp;#34;user.txt&amp;#34;)
  out.write &amp;#34;Hello, user!&amp;#34;
end
buffer2.rewind&lt;/p&gt;
&lt;p&gt;# Create the private exports with a predefined IDs
user1 = Decidim::User.find(1)
export = user1.private_exports.build
export.id = &amp;#34;0210ae70-482b-4671-b758-35e13e0097a9&amp;#34;
export.export_type = &amp;#34;download_your_data&amp;#34;
export.file.attach(io: buffer1, filename: &amp;#34;foobar.zip&amp;#34;, content_type…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: decidim-core, RubyGems: decidim&lt;/p&gt;
&lt;p&gt;### Impact
Private data exports can lead to data leaks in cases where the UUID generation causes collisions for the generated UUIDs.&lt;/p&gt;
&lt;p&gt;The bug was introduced by #13571 and affects Decidim versions 0.30.0 or newer (currently 2025-09-23).&lt;/p&gt;
&lt;p&gt;This issue  was discovered by running the following spec several times in a row, as it can randomly fail due to this bug:&lt;/p&gt;
&lt;p&gt;```bash
$ cd decidim-core
$ for i in {1..10}; do bundle exec rspec spec/jobs/decidim/download_your_data_export_job_spec.rb -e &amp;#34;deletes the&amp;#34; || break ; done
```&lt;/p&gt;
&lt;p&gt;Run the spec as many times as needed to hit a UUID that converts to `0` through `.to_i`.&lt;/p&gt;
&lt;p&gt;The UUID to zero conversion does not cause a security issue but the security issue is demonstrated with the following example.&lt;/p&gt;
&lt;p&gt;The following code regenerates the issue by assigning a predefined UUID that will generate a collision (example assumes there are already two existing users in the system):&lt;/p&gt;
&lt;p&gt;```ruby
# Create the ZIP buffers to be stored
buffer1 = Zip::OutputStream.write_buffer do |out|
  out.put_next_entry(&amp;#34;admin.txt&amp;#34;)
  out.write &amp;#34;Hello, admin!&amp;#34;
end
buffer1.rewind
buffer2 = Zip::OutputStream.write_buffer do |out|
  out.put_next_entry(&amp;#34;user.txt&amp;#34;)
  out.write &amp;#34;Hello, user!&amp;#34;
end
buffer2.rewind&lt;/p&gt;
&lt;p&gt;# Create the private exports with a predefined IDs
user1 = Decidim::User.find(1)
export = user1.private_exports.build
export.id = &amp;#34;0210ae70-482b-4671-b758-35e13e0097a9&amp;#34;
export.export_type = &amp;#34;download_your_data&amp;#34;
export.file.attach(io: buffer1, filename: &amp;#34;foobar.zip&amp;#34;, content_type…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3cx6-j9j4-54mp</guid>
    </item>
  </channel>
</rss>
