<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:34:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-267662</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267662</link>
      <description>EUVD-2026-267662</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267662</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25757</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25757</link>
      <description>&lt;p&gt;Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Order ID. This issue may lead to disclosure of PII of guest users (including names, addresses and phone numbers). This issue has been patched in versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Order ID. This issue may lead to disclosure of PII of guest users (including names, addresses and phone numbers). This issue has been patched in versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25757</guid>
    </item>
    <item>
      <title>GHSA-p6pv-q7rc-g4h9 — Unauthenticated Spree Commerce users can view completed guest orders by Order ID</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p6pv-q7rc-g4h9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: spree_storefront&lt;/p&gt;
&lt;p&gt;### Unauthenticated users can view completed guest orders by Order ID (`GHSL-2026-029`)&lt;/p&gt;
&lt;p&gt;The `OrdersController#show` action permits viewing completed guest orders by order number alone, without requiring the associated order token.&lt;/p&gt;
&lt;p&gt;Order lookup without enforcing token requirement in [`OrdersController#show`](https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/storefront/app/controllers/spree/orders_controller.rb#L14):&lt;/p&gt;
&lt;p&gt;```ruby
@order = complete_order_finder.new(number: params[:id], token: params[:token], store: current_store).execute.first
```&lt;/p&gt;
&lt;p&gt;Authorization bypass for guest orders in [`authorize_access`](https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/storefront/app/controllers/spree/orders_controller.rb#L51C1-L55C8):
```ruby
def authorize_access
  return true if @order.user_id.nil?&lt;/p&gt;
&lt;p&gt;@order.user == try_spree_current_user
end
```&lt;/p&gt;
&lt;p&gt;If the attacker is in possession of a leaked Order ID, they might look it up directly via this API.
Alternatively, brute forcing all or parts of the possible Order IDs might be feasible for an attacker. (The Order IDs themselves are [securely generated](https://github.com/spree/spree/blob/a878eb4a782ce0445d218ea86fb12075b0e3d7cc/core/lib/spree/core/number_generator.rb#L45), but with relatively low entropy: by default an order ID has a length of 9 and a base of 10, that would require an attacker to perform 1 billion requests to gather all guest orders. (At an assumed constant rate of 100 reque…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: spree_storefront&lt;/p&gt;
&lt;p&gt;### Unauthenticated users can view completed guest orders by Order ID (`GHSL-2026-029`)&lt;/p&gt;
&lt;p&gt;The `OrdersController#show` action permits viewing completed guest orders by order number alone, without requiring the associated order token.&lt;/p&gt;
&lt;p&gt;Order lookup without enforcing token requirement in [`OrdersController#show`](https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/storefront/app/controllers/spree/orders_controller.rb#L14):&lt;/p&gt;
&lt;p&gt;```ruby
@order = complete_order_finder.new(number: params[:id], token: params[:token], store: current_store).execute.first
```&lt;/p&gt;
&lt;p&gt;Authorization bypass for guest orders in [`authorize_access`](https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/storefront/app/controllers/spree/orders_controller.rb#L51C1-L55C8):
```ruby
def authorize_access
  return true if @order.user_id.nil?&lt;/p&gt;
&lt;p&gt;@order.user == try_spree_current_user
end
```&lt;/p&gt;
&lt;p&gt;If the attacker is in possession of a leaked Order ID, they might look it up directly via this API.
Alternatively, brute forcing all or parts of the possible Order IDs might be feasible for an attacker. (The Order IDs themselves are [securely generated](https://github.com/spree/spree/blob/a878eb4a782ce0445d218ea86fb12075b0e3d7cc/core/lib/spree/core/number_generator.rb#L45), but with relatively low entropy: by default an order ID has a length of 9 and a base of 10, that would require an attacker to perform 1 billion requests to gather all guest orders. (At an assumed constant rate of 100 reque…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p6pv-q7rc-g4h9</guid>
    </item>
  </channel>
</rss>
