<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 04:59:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-291186</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291186</link>
      <description>EUVD-2026-291186</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291186</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35598</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35598</link>
      <description>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesByList methods fetch tasks by UID from the database without verifying that the authenticated user has access to the task&amp;#39;s project. Any authenticated CalDAV user who knows (or guesses) a task UID can read the full task data from any project on the instance. This vulnerability is fixed in 2.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesByList methods fetch tasks by UID from the database without verifying that the authenticated user has access to the task&amp;#39;s project. Any authenticated CalDAV user who knows (or guesses) a task UID can read the full task data from any project on the instance. This vulnerability is fixed in 2.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35598</guid>
    </item>
    <item>
      <title>GHSA-48ch-p4gq-x46x — Vikunja Missing Authorization on CalDAV Task Read</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-48ch-p4gq-x46x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The CalDAV `GetResource` and `GetResourcesByList` methods fetch tasks by UID from the database without verifying that the authenticated user has access to the task&amp;#39;s project. Any authenticated CalDAV user who knows (or guesses) a task UID can read the full task data from any project on the instance.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`GetTasksByUIDs` at `pkg/models/tasks.go:376-393` performs a global database query with no authorization check:&lt;/p&gt;
&lt;p&gt;```go
func GetTasksByUIDs(s *xorm.Session, uids []string, a web.Auth) (tasks []*Task, err error) {
    tasks = []*Task{}
    err = s.In(&amp;#34;uid&amp;#34;, uids).Find(&amp;amp;tasks)
    // ...
}
```&lt;/p&gt;
&lt;p&gt;The `web.Auth` parameter is accepted but never used for permission filtering. This function is called by:
- `GetResource` at `pkg/routes/caldav/listStorageProvider.go:266` (CalDAV GET)
- `GetResourcesByList` at `pkg/routes/caldav/listStorageProvider.go:199` (CalDAV REPORT multiget)&lt;/p&gt;
&lt;p&gt;All other CalDAV operations enforce authorization: `CreateResource` checks `CanCreate()`, `UpdateResource` checks `CanUpdate()`, `DeleteResource` checks `CanDelete()`. Only the read operations skip authorization.&lt;/p&gt;
&lt;p&gt;The project ID in the CalDAV URL is ignored. A request to `/dav/projects/{attacker_project}/{victim_task_uid}.ics` returns the victim&amp;#39;s task regardless of which project ID is in the path.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;Tested on Vikunja v2.2.2.&lt;/p&gt;
&lt;p&gt;```python
import requests
from requests.auth import HTTPBasicAuth&lt;/p&gt;
&lt;p&gt;TARGET = &amp;#34;http://localhost:3456&amp;#34;
API = f&amp;#34;{TARGET}/api/v1&amp;#34;&lt;/p&gt;
&lt;p&gt;def login(u, p):…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The CalDAV `GetResource` and `GetResourcesByList` methods fetch tasks by UID from the database without verifying that the authenticated user has access to the task&amp;#39;s project. Any authenticated CalDAV user who knows (or guesses) a task UID can read the full task data from any project on the instance.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`GetTasksByUIDs` at `pkg/models/tasks.go:376-393` performs a global database query with no authorization check:&lt;/p&gt;
&lt;p&gt;```go
func GetTasksByUIDs(s *xorm.Session, uids []string, a web.Auth) (tasks []*Task, err error) {
    tasks = []*Task{}
    err = s.In(&amp;#34;uid&amp;#34;, uids).Find(&amp;amp;tasks)
    // ...
}
```&lt;/p&gt;
&lt;p&gt;The `web.Auth` parameter is accepted but never used for permission filtering. This function is called by:
- `GetResource` at `pkg/routes/caldav/listStorageProvider.go:266` (CalDAV GET)
- `GetResourcesByList` at `pkg/routes/caldav/listStorageProvider.go:199` (CalDAV REPORT multiget)&lt;/p&gt;
&lt;p&gt;All other CalDAV operations enforce authorization: `CreateResource` checks `CanCreate()`, `UpdateResource` checks `CanUpdate()`, `DeleteResource` checks `CanDelete()`. Only the read operations skip authorization.&lt;/p&gt;
&lt;p&gt;The project ID in the CalDAV URL is ignored. A request to `/dav/projects/{attacker_project}/{victim_task_uid}.ics` returns the victim&amp;#39;s task regardless of which project ID is in the path.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;Tested on Vikunja v2.2.2.&lt;/p&gt;
&lt;p&gt;```python
import requests
from requests.auth import HTTPBasicAuth&lt;/p&gt;
&lt;p&gt;TARGET = &amp;#34;http://localhost:3456&amp;#34;
API = f&amp;#34;{TARGET}/api/v1&amp;#34;&lt;/p&gt;
&lt;p&gt;def login(u, p):…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-48ch-p4gq-x46x</guid>
    </item>
  </channel>
</rss>
