<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 16:22:07 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-291020</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291020</link>
      <description>EUVD-2026-291020</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291020</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40069</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40069</link>
      <description>&lt;p&gt;BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC&amp;#39;s failure detection only recognises REJECTED and DOUBLE_SPEND_ATTEMPTED. ARC responses with txStatus values of INVALID, MALFORMED, MINED_IN_STALE_BLOCK, or any ORPHAN-containing extraInfo / txStatus are silently treated as successful broadcasts. Applications that gate actions on broadcaster success are tricked into trusting transactions that were never accepted by the network. This vulnerability is fixed in 0.8.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC&amp;#39;s failure detection only recognises REJECTED and DOUBLE_SPEND_ATTEMPTED. ARC responses with txStatus values of INVALID, MALFORMED, MINED_IN_STALE_BLOCK, or any ORPHAN-containing extraInfo / txStatus are silently treated as successful broadcasts. Applications that gate actions on broadcaster success are tricked into trusting transactions that were never accepted by the network. This vulnerability is fixed in 0.8.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40069</guid>
    </item>
    <item>
      <title>GHSA-9hfr-gw99-8rhx — bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9hfr-gw99-8rhx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: bsv-sdk&lt;/p&gt;
&lt;p&gt;# ARC broadcaster treats failure statuses as successful broadcasts&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`BSV::Network::ARC`&amp;#39;s failure detection only recognises `REJECTED` and `DOUBLE_SPEND_ATTEMPTED`. ARC responses with `txStatus` values of `INVALID`, `MALFORMED`, `MINED_IN_STALE_BLOCK`, or any `ORPHAN`-containing `extraInfo` / `txStatus` are silently treated as successful broadcasts. Applications that gate actions on broadcaster success are tricked into trusting transactions that were never accepted by the network.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`lib/bsv/network/arc.rb` (lines ~74-100 in the affected code) uses a narrow failure predicate compared to the TypeScript reference SDK. The TS broadcaster additionally recognises:&lt;/p&gt;
&lt;p&gt;- `INVALID`
- `MALFORMED`
- `MINED_IN_STALE_BLOCK`
- Any response containing `ORPHAN` in `extraInfo` or `txStatus`&lt;/p&gt;
&lt;p&gt;The Ruby implementation omits all of these, so ARC responses carrying any of these statuses are returned to the caller as successful broadcasts.&lt;/p&gt;
&lt;p&gt;Additional divergences in the same module compound the risk:&lt;/p&gt;
&lt;p&gt;- `Content-Type` is sent as `application/octet-stream`; the TS reference sends `application/json` with a `{ rawTx: &amp;lt;hex&amp;gt; }` body (EF form where source transactions are available).
- The headers `XDeployment-ID`, `X-CallbackUrl`, and `X-CallbackToken` are not sent.&lt;/p&gt;
&lt;p&gt;The immediate security-relevant defect is the missing failure statuses; the other divergences are fixed in the same patch for protocol compliance.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Integrity: callers receive a success response for broadcas…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: bsv-sdk&lt;/p&gt;
&lt;p&gt;# ARC broadcaster treats failure statuses as successful broadcasts&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`BSV::Network::ARC`&amp;#39;s failure detection only recognises `REJECTED` and `DOUBLE_SPEND_ATTEMPTED`. ARC responses with `txStatus` values of `INVALID`, `MALFORMED`, `MINED_IN_STALE_BLOCK`, or any `ORPHAN`-containing `extraInfo` / `txStatus` are silently treated as successful broadcasts. Applications that gate actions on broadcaster success are tricked into trusting transactions that were never accepted by the network.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`lib/bsv/network/arc.rb` (lines ~74-100 in the affected code) uses a narrow failure predicate compared to the TypeScript reference SDK. The TS broadcaster additionally recognises:&lt;/p&gt;
&lt;p&gt;- `INVALID`
- `MALFORMED`
- `MINED_IN_STALE_BLOCK`
- Any response containing `ORPHAN` in `extraInfo` or `txStatus`&lt;/p&gt;
&lt;p&gt;The Ruby implementation omits all of these, so ARC responses carrying any of these statuses are returned to the caller as successful broadcasts.&lt;/p&gt;
&lt;p&gt;Additional divergences in the same module compound the risk:&lt;/p&gt;
&lt;p&gt;- `Content-Type` is sent as `application/octet-stream`; the TS reference sends `application/json` with a `{ rawTx: &amp;lt;hex&amp;gt; }` body (EF form where source transactions are available).
- The headers `XDeployment-ID`, `X-CallbackUrl`, and `X-CallbackToken` are not sent.&lt;/p&gt;
&lt;p&gt;The immediate security-relevant defect is the missing failure statuses; the other divergences are fixed in the same patch for protocol compliance.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Integrity: callers receive a success response for broadcas…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9hfr-gw99-8rhx</guid>
    </item>
  </channel>
</rss>
