<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 18:45:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-321461</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-321461</link>
      <description>EUVD-2026-321461</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-321461</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45728</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45728</link>
      <description>&lt;p&gt;Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled. debugMode activates the PrettyError renderer, which on any Lua or template error response dumps the absolute path of the file that errored, complete byte contents of that file, and exception or parser error text. This response is served with HTTP 200 OK to whoever sent the request that triggered the error. Any client able to reach the server and able to provoke a runtime error in the served script obtains the full server-side source of that script and of any sibling Lua data file consulted during the request. This vulnerability is fixed in 1.17.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled. debugMode activates the PrettyError renderer, which on any Lua or template error response dumps the absolute path of the file that errored, complete byte contents of that file, and exception or parser error text. This response is served with HTTP 200 OK to whoever sent the request that triggered the error. Any client able to reach the server and able to provoke a runtime error in the served script obtains the full server-side source of that script and of any sibling Lua data file consulted during the request. This vulnerability is fixed in 1.17.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45728</guid>
    </item>
    <item>
      <title>GHSA-fwqx-8365-9983 — Algernon: Single-file mode unconditionally enables debug mode</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fwqx-8365-9983</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/xyproto/algernon&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When Algernon is invoked with a single file path instead of a directory — the documented &amp;#34;quick demo&amp;#34; workflow (`algernon foo.lua`, `algernon page.po2`, `algernon index.html`, `algernon mywebsite.alg`) — `singleFileMode` is set to true and **`debugMode` is forcibly enabled** with no opt-out:&lt;/p&gt;
&lt;p&gt;```go
// engine/config.go:498-502
// Make a few changes to the defaults if we are serving a single file
if ac.singleFileMode {
    ac.debugMode = true
    ac.serveJustHTTP = true
}
```&lt;/p&gt;
&lt;p&gt;`debugMode` activates the `PrettyError` renderer, which on any Lua or template error response dumps:&lt;/p&gt;
&lt;p&gt;1. The **absolute path** of the file that errored (`Filename` field of the error template).
2. The **complete byte contents** of that file, HTML-escaped, with the offending line wrapped in `&amp;lt;font style=&amp;#39;color: red !important&amp;#39;&amp;gt;…&amp;lt;/font&amp;gt;`.
3. The exception or parser error text — which in turn often quotes additional file content (Pongo2 errors include surrounding template lines; Lua tracebacks include argument values).&lt;/p&gt;
&lt;p&gt;This response is served with `HTTP 200 OK` to whoever sent the request that triggered the error. There is no authentication, no rate limit specific to errors, no redaction, and no opt-out short of avoiding single-file invocations entirely. Any client able to reach the server and able to provoke a runtime error in the served script obtains the full server-side source of that script and of any sibling Lua data file consulted during the request.&lt;/p&gt;
&lt;p&gt;This combines particularly badly wi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/xyproto/algernon&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When Algernon is invoked with a single file path instead of a directory — the documented &amp;#34;quick demo&amp;#34; workflow (`algernon foo.lua`, `algernon page.po2`, `algernon index.html`, `algernon mywebsite.alg`) — `singleFileMode` is set to true and **`debugMode` is forcibly enabled** with no opt-out:&lt;/p&gt;
&lt;p&gt;```go
// engine/config.go:498-502
// Make a few changes to the defaults if we are serving a single file
if ac.singleFileMode {
    ac.debugMode = true
    ac.serveJustHTTP = true
}
```&lt;/p&gt;
&lt;p&gt;`debugMode` activates the `PrettyError` renderer, which on any Lua or template error response dumps:&lt;/p&gt;
&lt;p&gt;1. The **absolute path** of the file that errored (`Filename` field of the error template).
2. The **complete byte contents** of that file, HTML-escaped, with the offending line wrapped in `&amp;lt;font style=&amp;#39;color: red !important&amp;#39;&amp;gt;…&amp;lt;/font&amp;gt;`.
3. The exception or parser error text — which in turn often quotes additional file content (Pongo2 errors include surrounding template lines; Lua tracebacks include argument values).&lt;/p&gt;
&lt;p&gt;This response is served with `HTTP 200 OK` to whoever sent the request that triggered the error. There is no authentication, no rate limit specific to errors, no redaction, and no opt-out short of avoiding single-file invocations entirely. Any client able to reach the server and able to provoke a runtime error in the served script obtains the full server-side source of that script and of any sibling Lua data file consulted during the request.&lt;/p&gt;
&lt;p&gt;This combines particularly badly wi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fwqx-8365-9983</guid>
    </item>
  </channel>
</rss>
