<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 09:37:23 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277221</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277221</link>
      <description>EUVD-2026-277221</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277221</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33679</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33679</link>
      <description>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client{}` with no SSRF protection when downloading user avatar images from the OpenID Connect `picture` claim URL. An attacker who controls their OIDC profile picture URL can force the Vikunja server to make HTTP GET requests to arbitrary internal or cloud metadata endpoints. This bypasses the SSRF protections that are correctly applied to the webhook system. Version 2.2.1 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client{}` with no SSRF protection when downloading user avatar images from the OpenID Connect `picture` claim URL. An attacker who controls their OIDC profile picture URL can force the Vikunja server to make HTTP GET requests to arbitrary internal or cloud metadata endpoints. This bypasses the SSRF protections that are correctly applied to the webhook system. Version 2.2.1 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33679</guid>
    </item>
    <item>
      <title>GHSA-g9xj-752q-xh63 — Vikjuna Bypasses Webhook SSRF Protections During OpenID Connect Avatar Download</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g9xj-752q-xh63</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client{}` with no SSRF protection when downloading user avatar images from the OpenID Connect `picture` claim URL. An attacker who controls their OIDC profile picture URL can force the Vikunja server to make HTTP GET requests to arbitrary internal or cloud metadata endpoints. This bypasses the SSRF protections that are correctly applied to the webhook system.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;When a user authenticates via OpenID Connect, Vikunja extracts the `picture` claim from the ID token or UserInfo endpoint and passes it to `syncUserAvatarFromOpenID`, which calls `utils.DownloadImage` with the attacker-controlled URL:&lt;/p&gt;
&lt;p&gt;**Claim extraction** (`pkg/modules/auth/openid/openid.go:70-78`):
```go
type claims struct {
	Email              string                   `json:&amp;#34;email&amp;#34;`
	Name               string                   `json:&amp;#34;name&amp;#34;`
	PreferredUsername   string                   `json:&amp;#34;preferred_username&amp;#34;`
	Nickname           string                   `json:&amp;#34;nickname&amp;#34;`
	VikunjaGroups      []map[string]interface{} `json:&amp;#34;vikunja_groups&amp;#34;`
	Picture            string                   `json:&amp;#34;picture&amp;#34;`
	// ...
}
```&lt;/p&gt;
&lt;p&gt;**Avatar sync trigger** (`pkg/modules/auth/openid/openid.go:348-352`):
```go
// Try sync avatar if available
err = syncUserAvatarFromOpenID(s, u, cl.Picture)
if err != nil {
	log.Errorf(&amp;#34;Error syncing avatar for user %s: %v&amp;#34;, u.Username, err)
}
```&lt;/p&gt;
&lt;p&gt;**Vulnerable download** (`pkg/utils/avatar.go:94-115`):
```…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `DownloadImage` function in `pkg/utils/avatar.go` uses a bare `http.Client{}` with no SSRF protection when downloading user avatar images from the OpenID Connect `picture` claim URL. An attacker who controls their OIDC profile picture URL can force the Vikunja server to make HTTP GET requests to arbitrary internal or cloud metadata endpoints. This bypasses the SSRF protections that are correctly applied to the webhook system.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;When a user authenticates via OpenID Connect, Vikunja extracts the `picture` claim from the ID token or UserInfo endpoint and passes it to `syncUserAvatarFromOpenID`, which calls `utils.DownloadImage` with the attacker-controlled URL:&lt;/p&gt;
&lt;p&gt;**Claim extraction** (`pkg/modules/auth/openid/openid.go:70-78`):
```go
type claims struct {
	Email              string                   `json:&amp;#34;email&amp;#34;`
	Name               string                   `json:&amp;#34;name&amp;#34;`
	PreferredUsername   string                   `json:&amp;#34;preferred_username&amp;#34;`
	Nickname           string                   `json:&amp;#34;nickname&amp;#34;`
	VikunjaGroups      []map[string]interface{} `json:&amp;#34;vikunja_groups&amp;#34;`
	Picture            string                   `json:&amp;#34;picture&amp;#34;`
	// ...
}
```&lt;/p&gt;
&lt;p&gt;**Avatar sync trigger** (`pkg/modules/auth/openid/openid.go:348-352`):
```go
// Try sync avatar if available
err = syncUserAvatarFromOpenID(s, u, cl.Picture)
if err != nil {
	log.Errorf(&amp;#34;Error syncing avatar for user %s: %v&amp;#34;, u.Username, err)
}
```&lt;/p&gt;
&lt;p&gt;**Vulnerable download** (`pkg/utils/avatar.go:94-115`):
```…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g9xj-752q-xh63</guid>
    </item>
  </channel>
</rss>
