<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 13:51:30 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-274129</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274129</link>
      <description>EUVD-2026-274129</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274129</guid>
    </item>
    <item>
      <title>fkie_cve-2026-28268</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28268</link>
      <description>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upon use and a critical logic bug in the token cleanup cron job, reset tokens remain valid forever. This allows an attacker who intercepts a single reset token (via logs, browser history, or phishing) to perform a complete, persistent account takeover at any point in the future, bypassing standard authentication controls. Version 2.1.0 contains a patch for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upon use and a critical logic bug in the token cleanup cron job, reset tokens remain valid forever. This allows an attacker who intercepts a single reset token (via logs, browser history, or phishing) to perform a complete, persistent account takeover at any point in the future, bypassing standard authentication controls. Version 2.1.0 contains a patch for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-28268</guid>
    </item>
    <item>
      <title>GHSA-rfjg-6m84-crj2 — Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rfjg-6m84-crj2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;**Summary**
A critical business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upon use and a critical logic bug in the token cleanup cron job, reset tokens remain valid forever.&lt;/p&gt;
&lt;p&gt;This allows an attacker who intercepts a single reset token (via logs, browser history, or phishing) to perform a complete, persistent account takeover at any point in the future, bypassing standard authentication controls.&lt;/p&gt;
&lt;p&gt;**Technical Analysis**
The vulnerability stems from two distinct logic errors in the pkg/user/ package that confirm the tokens are never removed.&lt;/p&gt;
&lt;p&gt;1. Logic Error in Password Reset (No Invalidation)
In pkg/user/user_password_reset.go, the ResetPassword function successfully updates the user&amp;#39;s password but fails to delete the reset token used to authorize the request. Instead, it attempts to delete a TokenEmailConfirm token, leaving the TokenPasswordReset active.&lt;/p&gt;
&lt;p&gt;Vulnerable Code: pkg/user/user_password_reset.go (Lines 36-94)
```
func ResetPassword(s *xorm.Session, reset *PasswordReset) (userID int64, err error) {
    // ... [Validation and User Lookup] ...&lt;/p&gt;
&lt;p&gt;// Hash the password
    user.Password, err = HashPassword(reset.NewPassword)
    if err != nil {
        return
    }&lt;/p&gt;
&lt;p&gt;// FLAW: Deletes &amp;#39;TokenEmailConfirm&amp;#39; instead of the current &amp;#39;TokenPasswordReset&amp;#39;
    err = removeTokens(s, user, TokenEmailConfirm)
    if err != nil {
        return
    }…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;**Summary**
A critical business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upon use and a critical logic bug in the token cleanup cron job, reset tokens remain valid forever.&lt;/p&gt;
&lt;p&gt;This allows an attacker who intercepts a single reset token (via logs, browser history, or phishing) to perform a complete, persistent account takeover at any point in the future, bypassing standard authentication controls.&lt;/p&gt;
&lt;p&gt;**Technical Analysis**
The vulnerability stems from two distinct logic errors in the pkg/user/ package that confirm the tokens are never removed.&lt;/p&gt;
&lt;p&gt;1. Logic Error in Password Reset (No Invalidation)
In pkg/user/user_password_reset.go, the ResetPassword function successfully updates the user&amp;#39;s password but fails to delete the reset token used to authorize the request. Instead, it attempts to delete a TokenEmailConfirm token, leaving the TokenPasswordReset active.&lt;/p&gt;
&lt;p&gt;Vulnerable Code: pkg/user/user_password_reset.go (Lines 36-94)
```
func ResetPassword(s *xorm.Session, reset *PasswordReset) (userID int64, err error) {
    // ... [Validation and User Lookup] ...&lt;/p&gt;
&lt;p&gt;// Hash the password
    user.Password, err = HashPassword(reset.NewPassword)
    if err != nil {
        return
    }&lt;/p&gt;
&lt;p&gt;// FLAW: Deletes &amp;#39;TokenEmailConfirm&amp;#39; instead of the current &amp;#39;TokenPasswordReset&amp;#39;
    err = removeTokens(s, user, TokenEmailConfirm)
    if err != nil {
        return
    }…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rfjg-6m84-crj2</guid>
    </item>
  </channel>
</rss>
