<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:42:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-328962</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328962</link>
      <description>EUVD-2026-328962</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328962</guid>
    </item>
    <item>
      <title>fkie_cve-2026-11748</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-11748</link>
      <description>&lt;p&gt;A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-11748</guid>
    </item>
    <item>
      <title>GHSA-98q5-5qh2-7w75 — Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-98q5-5qh2-7w75</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.linecorp.centraldogma:centraldogma-server-auth-shiro&lt;/p&gt;
&lt;p&gt;# Vulnerability&lt;/p&gt;
&lt;p&gt;`SearchFirstActiveDirectoryRealm.findUserDn()` substitutes the user-supplied username from the login form into an LDAP search filter template (default `cn={0}`) **without escaping RFC 4515 filter metacharacters** (`*`, `(`, `)`, `\`, NUL). Combined with `SearchControls.setCountLimit(1)` on the same call site, this allows three distinct attack primitives:&lt;/p&gt;
&lt;p&gt;1. **Authentication confusion** — typing username `*` causes the realm to construct filter `cn=*`, return the first directory entry (typically a privileged account in AD ordering), and attempt bind against that DN with the attacker&amp;#39;s password.
2. **Audit log evasion** — payload `bob)(uid=alice` is recorded verbatim in audit logs while the realm searches with the malformed filter, breaking accountability/compliance (SOX, PCI-DSS, ISO 27001).
3. **Directory enumeration** — wildcards and timing differences allow reconnaissance of OU structure and admin group membership.&lt;/p&gt;
&lt;p&gt;A repo-wide search for any LDAP escape helper (`escapeLdap`, `encodeFilter`, `escapeFilter`, `ldapEscape`) returns **zero hits** — the defense is not just missing, it was never added.&lt;/p&gt;
&lt;p&gt;&amp;gt; **Applicability note:** This realm is opt-in. The shipped default LDAP example (`dist/src/conf/shiro.example.ldap.ini`) uses Shiro&amp;#39;s `DefaultLdapRealm` with `userDnTemplate` and is **NOT** affected. However, the realm exists precisely to support Active Directory environments where users log in via `sAMAccountName` and the realm must search for the DN first — t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.linecorp.centraldogma:centraldogma-server-auth-shiro&lt;/p&gt;
&lt;p&gt;# Vulnerability&lt;/p&gt;
&lt;p&gt;`SearchFirstActiveDirectoryRealm.findUserDn()` substitutes the user-supplied username from the login form into an LDAP search filter template (default `cn={0}`) **without escaping RFC 4515 filter metacharacters** (`*`, `(`, `)`, `\`, NUL). Combined with `SearchControls.setCountLimit(1)` on the same call site, this allows three distinct attack primitives:&lt;/p&gt;
&lt;p&gt;1. **Authentication confusion** — typing username `*` causes the realm to construct filter `cn=*`, return the first directory entry (typically a privileged account in AD ordering), and attempt bind against that DN with the attacker&amp;#39;s password.
2. **Audit log evasion** — payload `bob)(uid=alice` is recorded verbatim in audit logs while the realm searches with the malformed filter, breaking accountability/compliance (SOX, PCI-DSS, ISO 27001).
3. **Directory enumeration** — wildcards and timing differences allow reconnaissance of OU structure and admin group membership.&lt;/p&gt;
&lt;p&gt;A repo-wide search for any LDAP escape helper (`escapeLdap`, `encodeFilter`, `escapeFilter`, `ldapEscape`) returns **zero hits** — the defense is not just missing, it was never added.&lt;/p&gt;
&lt;p&gt;&amp;gt; **Applicability note:** This realm is opt-in. The shipped default LDAP example (`dist/src/conf/shiro.example.ldap.ini`) uses Shiro&amp;#39;s `DefaultLdapRealm` with `userDnTemplate` and is **NOT** affected. However, the realm exists precisely to support Active Directory environments where users log in via `sAMAccountName` and the realm must search for the DN first — t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-98q5-5qh2-7w75</guid>
    </item>
  </channel>
</rss>
