<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 15:57:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277257</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277257</link>
      <description>EUVD-2026-277257</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277257</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33690</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33690</link>
      <description>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers to determine the client&amp;#39;s IP address. An attacker can spoof their IP address by sending forged headers, bypassing any IP-based access controls or audit logging. Commit 1a1df6a9377e5cc67d1d0ac8ef571f7abbffbc6c contains a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers to determine the client&amp;#39;s IP address. An attacker can spoof their IP address by sending forged headers, bypassing any IP-based access controls or audit logging. Commit 1a1df6a9377e5cc67d1d0ac8ef571f7abbffbc6c contains a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33690</guid>
    </item>
    <item>
      <title>GHSA-8p2x-5cpm-qrqw — AVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr()</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8p2x-5cpm-qrqw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers to determine the client&amp;#39;s IP address. 
An attacker can spoof their IP address by sending forged headers, bypassing any IP-based access controls or audit logging.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;File: `objects/functions.php`
```php
$headers = [
    &amp;#39;HTTP_X_REAL_IP&amp;#39;,      
    &amp;#39;HTTP_CLIENT_IP&amp;#39;,    
    &amp;#39;HTTP_X_FORWARDED_FOR&amp;#39;,
    &amp;#39;REMOTE_ADDR&amp;#39;
];&lt;/p&gt;
&lt;p&gt;foreach ($headers as $header) {
    if (!empty($_SERVER[$header])) {
        $ips = explode(&amp;#39;,&amp;#39;, $_SERVER[$header]);
        foreach ($ips as $ipCandidate) {
            $ipCandidate = trim($ipCandidate);
            if (filter_var($ipCandidate, FILTER_VALIDATE_IP, 
                           FILTER_FLAG_IPV4)) {
                return $ipCandidate; 
            }
        }
    }
}
```&lt;/p&gt;
&lt;p&gt;## Attack Scenario&lt;/p&gt;
&lt;p&gt;1. Attacker sends request with forged header:
```
X-Client-IP: 127.0.0.1
```
or
```
X-Real-IP: 192.168.1.1
```&lt;/p&gt;
&lt;p&gt;2. `getRealIpAddr()` returns the forged IP
3. Any IP-based rate limiting, access control, or audit 
   log that relies on this function is bypassed&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```bash
curl -H &amp;#34;X-Client-IP: 127.0.0.1&amp;#34; \
     https://target.com/any_endpoint.php
```&lt;/p&gt;
&lt;p&gt;The server now believes the request came from localhost.&lt;/p&gt;
&lt;p&gt;## Impact
- Bypass IP-based rate limiting
- Bypass IP-based access controls
- Forge audit log entries
- Potential privilege escalation if localhost is trusted&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wwbn/avideo&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers to determine the client&amp;#39;s IP address. 
An attacker can spoof their IP address by sending forged headers, bypassing any IP-based access controls or audit logging.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;File: `objects/functions.php`
```php
$headers = [
    &amp;#39;HTTP_X_REAL_IP&amp;#39;,      
    &amp;#39;HTTP_CLIENT_IP&amp;#39;,    
    &amp;#39;HTTP_X_FORWARDED_FOR&amp;#39;,
    &amp;#39;REMOTE_ADDR&amp;#39;
];&lt;/p&gt;
&lt;p&gt;foreach ($headers as $header) {
    if (!empty($_SERVER[$header])) {
        $ips = explode(&amp;#39;,&amp;#39;, $_SERVER[$header]);
        foreach ($ips as $ipCandidate) {
            $ipCandidate = trim($ipCandidate);
            if (filter_var($ipCandidate, FILTER_VALIDATE_IP, 
                           FILTER_FLAG_IPV4)) {
                return $ipCandidate; 
            }
        }
    }
}
```&lt;/p&gt;
&lt;p&gt;## Attack Scenario&lt;/p&gt;
&lt;p&gt;1. Attacker sends request with forged header:
```
X-Client-IP: 127.0.0.1
```
or
```
X-Real-IP: 192.168.1.1
```&lt;/p&gt;
&lt;p&gt;2. `getRealIpAddr()` returns the forged IP
3. Any IP-based rate limiting, access control, or audit 
   log that relies on this function is bypassed&lt;/p&gt;
&lt;p&gt;## Proof of Concept
```bash
curl -H &amp;#34;X-Client-IP: 127.0.0.1&amp;#34; \
     https://target.com/any_endpoint.php
```&lt;/p&gt;
&lt;p&gt;The server now believes the request came from localhost.&lt;/p&gt;
&lt;p&gt;## Impact
- Bypass IP-based rate limiting
- Bypass IP-based access controls
- Forge audit log entries
- Potential privilege escalation if localhost is trusted&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8p2x-5cpm-qrqw</guid>
    </item>
  </channel>
</rss>
