<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 19:12:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277542</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277542</link>
      <description>EUVD-2026-277542</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277542</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33182</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33182</link>
      <description>&lt;p&gt;Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon combined the connector&amp;#39;s base URL with the request endpoint. If the endpoint was a valid absolute URL, the code used that URL as-is and ignored the base URL. The request—and any authentication headers, cookies, or tokens attached by the connector—was then sent to the attacker-controlled host. If the endpoint could be influenced by user input or configuration (e.g. redirect_uri, callback URL), this allowed server-side request forgery (SSRF) and/or credential leakage to a third-party host. The fix in version 4.0.0 is to reject absolute URLs in the endpoint: URLHelper::join() throws InvalidArgumentException when the endpoint is a valid absolute URL, unless explicitly allowed, requiring callers to opt-in to the functionality on a per-connector or per-request basis.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon combined the connector&amp;#39;s base URL with the request endpoint. If the endpoint was a valid absolute URL, the code used that URL as-is and ignored the base URL. The request—and any authentication headers, cookies, or tokens attached by the connector—was then sent to the attacker-controlled host. If the endpoint could be influenced by user input or configuration (e.g. redirect_uri, callback URL), this allowed server-side request forgery (SSRF) and/or credential leakage to a third-party host. The fix in version 4.0.0 is to reject absolute URLs in the endpoint: URLHelper::join() throws InvalidArgumentException when the endpoint is a valid absolute URL, unless explicitly allowed, requiring callers to opt-in to the functionality on a per-connector or per-request basis.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33182</guid>
    </item>
    <item>
      <title>GHSA-c83f-3xp6-hfcp — Saloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URL</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c83f-3xp6-hfcp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: saloonphp/saloon&lt;/p&gt;
&lt;p&gt;### Impact
Users providing user generated input into the `resolveEndpoint` method on requests.&lt;/p&gt;
&lt;p&gt;### Patches
Upgrade to Saloon v4+&lt;/p&gt;
&lt;p&gt;Upgrade guide: https://docs.saloon.dev/upgrade/upgrading-from-v3-to-v4&lt;/p&gt;
&lt;p&gt;### Description
When building the request URL, Saloon combined the connector&amp;#39;s base URL with the request endpoint. If the endpoint was a valid absolute URL (e.g. https://attacker.example.com/callback), the code used that URL as-is and ignored the base URL. The request—and any authentication headers, cookies, or tokens attached by the connector—was then sent to the attacker-controlled host. If the endpoint could be influenced by user input or configuration (e.g. redirect_uri, callback URL), this allowed server-side request forgery (SSRF) and/or credential leakage to a third-party host. The fix (in the next major version) is to reject absolute URLs in the endpoint: URLHelper::join() throws InvalidArgumentException when the endpoint is a valid absolute URL, unless explicitly allowed, requiring callers to opt-in to the functionality on a per-connector or per-request basis.&lt;/p&gt;
&lt;p&gt;### Credits
Saloon thanks @HuajiHD for finding the issue and recommending solutions and @JonPurvis for applying the fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: saloonphp/saloon&lt;/p&gt;
&lt;p&gt;### Impact
Users providing user generated input into the `resolveEndpoint` method on requests.&lt;/p&gt;
&lt;p&gt;### Patches
Upgrade to Saloon v4+&lt;/p&gt;
&lt;p&gt;Upgrade guide: https://docs.saloon.dev/upgrade/upgrading-from-v3-to-v4&lt;/p&gt;
&lt;p&gt;### Description
When building the request URL, Saloon combined the connector&amp;#39;s base URL with the request endpoint. If the endpoint was a valid absolute URL (e.g. https://attacker.example.com/callback), the code used that URL as-is and ignored the base URL. The request—and any authentication headers, cookies, or tokens attached by the connector—was then sent to the attacker-controlled host. If the endpoint could be influenced by user input or configuration (e.g. redirect_uri, callback URL), this allowed server-side request forgery (SSRF) and/or credential leakage to a third-party host. The fix (in the next major version) is to reject absolute URLs in the endpoint: URLHelper::join() throws InvalidArgumentException when the endpoint is a valid absolute URL, unless explicitly allowed, requiring callers to opt-in to the functionality on a per-connector or per-request basis.&lt;/p&gt;
&lt;p&gt;### Credits
Saloon thanks @HuajiHD for finding the issue and recommending solutions and @JonPurvis for applying the fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c83f-3xp6-hfcp</guid>
    </item>
  </channel>
</rss>
