<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 21:28:43 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15209</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15209</link>
      <description>bdu:2026-15209</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15209</guid>
    </item>
    <item>
      <title>BIT-elk-2026-33458 — Server-Side Request Forgery (SSRF) in Kibana One Workflow Leading to Information Disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/bit-elk-2026-33458</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: elk&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: elk&lt;/p&gt;
&lt;p&gt;Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-elk-2026-33458</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0413 — De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0413</link>
      <description>certfr-2026-avi-0413</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0413</guid>
    </item>
    <item>
      <title>EUVD-2026-290116</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290116</link>
      <description>EUVD-2026-290116</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290116</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33458</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33458</link>
      <description>&lt;p&gt;Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33458</guid>
    </item>
    <item>
      <title>GHSA-grxp-xwh4-267v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-grxp-xwh4-267v</link>
      <description>&lt;p&gt;Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host allowlist restrictions in the Workflows Execution Engine, potentially exposing sensitive internal endpoints and data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-grxp-xwh4-267v</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1029 — Kibana: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1029</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kibana ausnutzen, um Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1029</guid>
    </item>
  </channel>
</rss>
