<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 21:53:44 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-325120</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-325120</link>
      <description>EUVD-2026-325120</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-325120</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45327</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45327</link>
      <description>&lt;p&gt;TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection. Version 2.5.0 fixes the issue by requiring either HTTP Basic auth or a `?password=` query parameter, comparing the supplied password against the per-mount source password (or the `default_source_password` fallback) using bcrypt, hooking into the existing brute-force IP rate-limiter (5 failed attempts per IP within 15 minutes triggers a lockout), and rejecting requests for mounts in `disabled_mounts`. The same release also tightens an adjacent endpoint, `POST /admin/golive/chunk`, which previously required session authentication but did not verify the session user&amp;#39;s per-mount access nor check the CSRF token.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection. Version 2.5.0 fixes the issue by requiring either HTTP Basic auth or a `?password=` query parameter, comparing the supplied password against the per-mount source password (or the `default_source_password` fallback) using bcrypt, hooking into the existing brute-force IP rate-limiter (5 failed attempts per IP within 15 minutes triggers a lockout), and rejecting requests for mounts in `disabled_mounts`. The same release also tightens an adjacent endpoint, `POST /admin/golive/chunk`, which previously required session authentication but did not verify the session user&amp;#39;s per-mount access nor check the CSRF token.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45327</guid>
    </item>
    <item>
      <title>GHSA-p7c4-8x34-8j8f — TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p7c4-8x34-8j8f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/DatanoiseTV/tinyice&lt;/p&gt;
&lt;p&gt;## Title&lt;/p&gt;
&lt;p&gt;Missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection in TinyIce&lt;/p&gt;
&lt;p&gt;## Ecosystem / Package&lt;/p&gt;
&lt;p&gt;- **Ecosystem:** `Go` (or &amp;#34;Other&amp;#34; — TinyIce is shipped as a Go binary, not a Go module published to a registry)
- **Package name:** `github.com/DatanoiseTV/tinyice`&lt;/p&gt;
&lt;p&gt;## Affected versions&lt;/p&gt;
&lt;p&gt;```
&amp;gt;= 0.8.95, &amp;lt;= 2.4.1
```&lt;/p&gt;
&lt;p&gt;(Introduced 2026-02-21 in commit `e2b60d6` — &amp;#34;debug: add Go Live connection tracing and backend data flow logging&amp;#34; — when `handleWebRTCSourceOffer` was registered at `/webrtc/source-offer` without an authentication check. Every tagged release from `v0.8.95` through `v2.4.1` ships the vulnerable handler.)&lt;/p&gt;
&lt;p&gt;## Patched versions&lt;/p&gt;
&lt;p&gt;```
&amp;gt;= 2.5.0
```&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;- **CVSS 3.1 base score:** 7.4 (High)
- **CVSS vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L`
- **CWE:** [CWE-306: Missing Authentication for Critical Function](https://cwe.mitre.org/data/definitions/306.html)&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;TinyIce&amp;#39;s WebRTC source-ingest HTTP endpoint, `POST /webrtc/source-offer?mount=&amp;lt;mount&amp;gt;`, accepted any inbound WebRTC SDP offer with no authentication check. The handler routed the offer to `WebRTCManager.HandleSourceOffer`, which then accepted whatever audio/video tracks the peer published and broadcast them on the named mount as if they were the legitimate source.&lt;/p&gt;
&lt;p&gt;The other ingest paths (`POST /&amp;lt;mount&amp;gt;` over HTTP/1 with the icecast `SOURCE` / `PUT` verb, RTMP, SRT) all require the per-mount source password, falling back to `default_source_pass…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/DatanoiseTV/tinyice&lt;/p&gt;
&lt;p&gt;## Title&lt;/p&gt;
&lt;p&gt;Missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection in TinyIce&lt;/p&gt;
&lt;p&gt;## Ecosystem / Package&lt;/p&gt;
&lt;p&gt;- **Ecosystem:** `Go` (or &amp;#34;Other&amp;#34; — TinyIce is shipped as a Go binary, not a Go module published to a registry)
- **Package name:** `github.com/DatanoiseTV/tinyice`&lt;/p&gt;
&lt;p&gt;## Affected versions&lt;/p&gt;
&lt;p&gt;```
&amp;gt;= 0.8.95, &amp;lt;= 2.4.1
```&lt;/p&gt;
&lt;p&gt;(Introduced 2026-02-21 in commit `e2b60d6` — &amp;#34;debug: add Go Live connection tracing and backend data flow logging&amp;#34; — when `handleWebRTCSourceOffer` was registered at `/webrtc/source-offer` without an authentication check. Every tagged release from `v0.8.95` through `v2.4.1` ships the vulnerable handler.)&lt;/p&gt;
&lt;p&gt;## Patched versions&lt;/p&gt;
&lt;p&gt;```
&amp;gt;= 2.5.0
```&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;- **CVSS 3.1 base score:** 7.4 (High)
- **CVSS vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L`
- **CWE:** [CWE-306: Missing Authentication for Critical Function](https://cwe.mitre.org/data/definitions/306.html)&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;TinyIce&amp;#39;s WebRTC source-ingest HTTP endpoint, `POST /webrtc/source-offer?mount=&amp;lt;mount&amp;gt;`, accepted any inbound WebRTC SDP offer with no authentication check. The handler routed the offer to `WebRTCManager.HandleSourceOffer`, which then accepted whatever audio/video tracks the peer published and broadcast them on the named mount as if they were the legitimate source.&lt;/p&gt;
&lt;p&gt;The other ingest paths (`POST /&amp;lt;mount&amp;gt;` over HTTP/1 with the icecast `SOURCE` / `PUT` verb, RTMP, SRT) all require the per-mount source password, falling back to `default_source_pass…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p7c4-8x34-8j8f</guid>
    </item>
  </channel>
</rss>
