<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 16:40:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277696</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277696</link>
      <description>EUVD-2026-277696</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277696</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33668</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33668</link>
      <description>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disabled or locked, the status check is only enforced on the local login and JWT token refresh paths. Three other authentication paths — API tokens, CalDAV basic auth, and OpenID Connect — do not verify user status, allowing disabled or locked users to continue accessing the API and syncing data. Version 2.2.1 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disabled or locked, the status check is only enforced on the local login and JWT token refresh paths. Three other authentication paths — API tokens, CalDAV basic auth, and OpenID Connect — do not verify user status, allowing disabled or locked users to continue accessing the API and syncing data. Version 2.2.1 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33668</guid>
    </item>
    <item>
      <title>GHSA-94xm-jj8x-3cr4 — Vikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-94xm-jj8x-3cr4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When a user account is disabled or locked, the status check is only enforced on the local login and JWT token refresh paths. Three other authentication paths — API tokens, CalDAV basic auth, and OpenID Connect — do not verify user status, allowing disabled or locked users to continue accessing the API and syncing data.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;User status (`StatusDisabled`, `StatusAccountLocked`) is checked in only two places:&lt;/p&gt;
&lt;p&gt;1. **Local/LDAP login** (`pkg/routes/api/v1/login.go:74`) — prevents issuing new JWTs
2. **JWT token refresh** (`pkg/routes/api/v1/login.go:247`) — prevents refreshing expired JWTs&lt;/p&gt;
&lt;p&gt;Three other authentication paths fetch the user from the database via `GetUserByID` but never inspect the returned user&amp;#39;s status:&lt;/p&gt;
&lt;p&gt;### 1. API Token Authentication (`pkg/routes/api_tokens.go:76-103`)&lt;/p&gt;
&lt;p&gt;API tokens are long-lived (up to years) and have no refresh cycle. A disabled user&amp;#39;s API tokens remain fully functional until they expire naturally.&lt;/p&gt;
&lt;p&gt;### 2. CalDAV Basic Auth (`pkg/routes/caldav/auth.go`)&lt;/p&gt;
&lt;p&gt;The CalDAV basic auth handler validates credentials but does not check user status before granting access. A disabled user with valid credentials or a CalDAV token can continue syncing calendars and tasks.&lt;/p&gt;
&lt;p&gt;### 3. OpenID Connect Callback (`pkg/modules/auth/openid/openid.go`)&lt;/p&gt;
&lt;p&gt;The OIDC callback issues a fresh JWT token after validating the identity provider&amp;#39;s response but does not check whether the Vikunja user account is disabled. If the user&amp;#39;s identity provider session is s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When a user account is disabled or locked, the status check is only enforced on the local login and JWT token refresh paths. Three other authentication paths — API tokens, CalDAV basic auth, and OpenID Connect — do not verify user status, allowing disabled or locked users to continue accessing the API and syncing data.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;User status (`StatusDisabled`, `StatusAccountLocked`) is checked in only two places:&lt;/p&gt;
&lt;p&gt;1. **Local/LDAP login** (`pkg/routes/api/v1/login.go:74`) — prevents issuing new JWTs
2. **JWT token refresh** (`pkg/routes/api/v1/login.go:247`) — prevents refreshing expired JWTs&lt;/p&gt;
&lt;p&gt;Three other authentication paths fetch the user from the database via `GetUserByID` but never inspect the returned user&amp;#39;s status:&lt;/p&gt;
&lt;p&gt;### 1. API Token Authentication (`pkg/routes/api_tokens.go:76-103`)&lt;/p&gt;
&lt;p&gt;API tokens are long-lived (up to years) and have no refresh cycle. A disabled user&amp;#39;s API tokens remain fully functional until they expire naturally.&lt;/p&gt;
&lt;p&gt;### 2. CalDAV Basic Auth (`pkg/routes/caldav/auth.go`)&lt;/p&gt;
&lt;p&gt;The CalDAV basic auth handler validates credentials but does not check user status before granting access. A disabled user with valid credentials or a CalDAV token can continue syncing calendars and tasks.&lt;/p&gt;
&lt;p&gt;### 3. OpenID Connect Callback (`pkg/modules/auth/openid/openid.go`)&lt;/p&gt;
&lt;p&gt;The OIDC callback issues a fresh JWT token after validating the identity provider&amp;#39;s response but does not check whether the Vikunja user account is disabled. If the user&amp;#39;s identity provider session is s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-94xm-jj8x-3cr4</guid>
    </item>
  </channel>
</rss>
