<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 13:05:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-261762</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261762</link>
      <description>EUVD-2026-261762</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261762</guid>
    </item>
    <item>
      <title>fkie_cve-2025-65109</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-65109</link>
      <description>&lt;p&gt;Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access to. This issue has been patched in Minder Helm version 0.20250203.3849+ref.fdc94f0 and Minder Go version 0.0.84.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access to. This issue has been patched in Minder Helm version 0.20250203.3849+ref.fdc94f0 and Minder Go version 0.0.84.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-65109</guid>
    </item>
    <item>
      <title>GHSA-6xvf-4vh9-mw47 — Minder does not sandbox http.send in Rego programs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6xvf-4vh9-mw47</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/mindersec/minder&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access to (for example, if the Minder server is behind a firewall or other network partition).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;https://github.com/mindersec/minder/commit/f770400923984649a287d7215410ef108e845af8&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users should avoid deploying Minder with access to sensitive resources.  Unfortunately, this could include access to systems like OpenFGA or Keycloak, depending on the deployment configuration.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;Sample ruletype:&lt;/p&gt;
&lt;p&gt;```yaml
version: v1
type: rule-type
name: test-http-send
display_name: Test that we can call http.send
short_failure_message: Failed http.send
severity:
  value: medium
context:
  provider: github
description: |
  ...
guidance: |
  ....
def:
  in_entity: repository
  rule_schema:
    type: object
    properties: {}
  ingest:
    type: git
    git: {}
  eval:
    type: rego
    violation_format: text
    rego:
      type: constraints
      def: |
        package minder&lt;/p&gt;
&lt;p&gt;import rego.v1&lt;/p&gt;
&lt;p&gt;violations contains {&amp;#34;msg&amp;#34;: &amp;#34;Check-execution&amp;#34;}&lt;/p&gt;
&lt;p&gt;resp := http.send({
          &amp;#34;method&amp;#34;: &amp;#34;GET&amp;#34;,
          &amp;#34;url&amp;#34;: &amp;#34;http://openfga:8080/&amp;#34;,
          &amp;#34;raise_error&amp;#34;: false,
        })&lt;/p&gt;
&lt;p&gt;violations contains {&amp;#34;msg&amp;#34;: sprintf(&amp;#34;Response: %s&amp;#34;, [resp.status])}&lt;/p&gt;
&lt;p&gt;details := sprintf(&amp;#34;High score: %s&amp;#34;, [resp.body.summary])&lt;/p&gt;
&lt;p&gt;violations contains {&amp;#34;msg&amp;#34;: sprintf(&amp;#34;Response body: %s&amp;#34;, [resp.body]) }…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/mindersec/minder&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access to (for example, if the Minder server is behind a firewall or other network partition).&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;https://github.com/mindersec/minder/commit/f770400923984649a287d7215410ef108e845af8&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users should avoid deploying Minder with access to sensitive resources.  Unfortunately, this could include access to systems like OpenFGA or Keycloak, depending on the deployment configuration.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;Sample ruletype:&lt;/p&gt;
&lt;p&gt;```yaml
version: v1
type: rule-type
name: test-http-send
display_name: Test that we can call http.send
short_failure_message: Failed http.send
severity:
  value: medium
context:
  provider: github
description: |
  ...
guidance: |
  ....
def:
  in_entity: repository
  rule_schema:
    type: object
    properties: {}
  ingest:
    type: git
    git: {}
  eval:
    type: rego
    violation_format: text
    rego:
      type: constraints
      def: |
        package minder&lt;/p&gt;
&lt;p&gt;import rego.v1&lt;/p&gt;
&lt;p&gt;violations contains {&amp;#34;msg&amp;#34;: &amp;#34;Check-execution&amp;#34;}&lt;/p&gt;
&lt;p&gt;resp := http.send({
          &amp;#34;method&amp;#34;: &amp;#34;GET&amp;#34;,
          &amp;#34;url&amp;#34;: &amp;#34;http://openfga:8080/&amp;#34;,
          &amp;#34;raise_error&amp;#34;: false,
        })&lt;/p&gt;
&lt;p&gt;violations contains {&amp;#34;msg&amp;#34;: sprintf(&amp;#34;Response: %s&amp;#34;, [resp.status])}&lt;/p&gt;
&lt;p&gt;details := sprintf(&amp;#34;High score: %s&amp;#34;, [resp.body.summary])&lt;/p&gt;
&lt;p&gt;violations contains {&amp;#34;msg&amp;#34;: sprintf(&amp;#34;Response body: %s&amp;#34;, [resp.body]) }…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6xvf-4vh9-mw47</guid>
    </item>
  </channel>
</rss>
