<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 13:41:42 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-321543</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-321543</link>
      <description>EUVD-2026-321543</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-321543</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46430</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46430</link>
      <description>&lt;p&gt;Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent host default in engine/flags.go:39-46 set host = &amp;#34;&amp;#34; for non-Windows, and utils.JoinHostPort(&amp;#34;&amp;#34;, &amp;#34;:5553&amp;#34;) resolves to &amp;#34;:5553&amp;#34;. This vulnerability is fixed in 1.17.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent host default in engine/flags.go:39-46 set host = &amp;#34;&amp;#34; for non-Windows, and utils.JoinHostPort(&amp;#34;&amp;#34;, &amp;#34;:5553&amp;#34;) resolves to &amp;#34;:5553&amp;#34;. This vulnerability is fixed in 1.17.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46430</guid>
    </item>
    <item>
      <title>GHSA-gj84-924c-48fx — Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gj84-924c-48fx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/xyproto/algernon&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The SSE event server bound to `0.0.0.0:5553` on Linux/macOS by default because the platform-dependent host default in `engine/flags.go:39-46` set `host = &amp;#34;&amp;#34;` for non-Windows, and `utils.JoinHostPort(&amp;#34;&amp;#34;, &amp;#34;:5553&amp;#34;)` resolves to `&amp;#34;:5553&amp;#34;` — a Go `http.Server.Addr` of `&amp;#34;:5553&amp;#34;` listens on every interface. On Windows the same code chose `&amp;#34;localhost&amp;#34;`, binding loopback only.&lt;/p&gt;
&lt;p&gt;The result was a platform split where the OS Algernon&amp;#39;s dev workflow is most often used on (Linux/macOS) got the network-exposed default, and only Windows users got the loopback-safe one. A LAN peer with no developer interaction could connect to `&amp;lt;dev-laptop-ip&amp;gt;:5553` and read the file-change stream.&lt;/p&gt;
&lt;p&gt;This advisory covers the bind-address default in isolation. The fix is independent of authentication (#2a) and CORS (#2b) — switching the default to loopback can be done without touching either.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;#### Root cause — platform-dependent `host` default in `handleFlags`&lt;/p&gt;
&lt;p&gt;```go
// engine/flags.go:39-46  (1.17.6)
host := &amp;#34;&amp;#34;
if runtime.GOOS == &amp;#34;windows&amp;#34; {
    host = &amp;#34;localhost&amp;#34;
    // Default Bolt database file
    ac.defaultBoltFilename = filepath.Join(serverTempDir, &amp;#34;algernon.db&amp;#34;)
    // Default log file
    ac.defaultLogFile = filepath.Join(serverTempDir, &amp;#34;algernon.log&amp;#34;)
}
```&lt;/p&gt;
&lt;p&gt;```go
// engine/config.go:388-391  (1.17.6, finalConfiguration)
if ac.eventAddr == &amp;#34;&amp;#34; {
    ac.eventAddr = utils.JoinHostPort(host, ac.defaultEventColonPort)
}
```&lt;/p&gt;
&lt;p&gt;Result tabulated:&lt;/p&gt;
&lt;p&gt;| Platform | `host` | `eventAddr` a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/xyproto/algernon&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The SSE event server bound to `0.0.0.0:5553` on Linux/macOS by default because the platform-dependent host default in `engine/flags.go:39-46` set `host = &amp;#34;&amp;#34;` for non-Windows, and `utils.JoinHostPort(&amp;#34;&amp;#34;, &amp;#34;:5553&amp;#34;)` resolves to `&amp;#34;:5553&amp;#34;` — a Go `http.Server.Addr` of `&amp;#34;:5553&amp;#34;` listens on every interface. On Windows the same code chose `&amp;#34;localhost&amp;#34;`, binding loopback only.&lt;/p&gt;
&lt;p&gt;The result was a platform split where the OS Algernon&amp;#39;s dev workflow is most often used on (Linux/macOS) got the network-exposed default, and only Windows users got the loopback-safe one. A LAN peer with no developer interaction could connect to `&amp;lt;dev-laptop-ip&amp;gt;:5553` and read the file-change stream.&lt;/p&gt;
&lt;p&gt;This advisory covers the bind-address default in isolation. The fix is independent of authentication (#2a) and CORS (#2b) — switching the default to loopback can be done without touching either.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;#### Root cause — platform-dependent `host` default in `handleFlags`&lt;/p&gt;
&lt;p&gt;```go
// engine/flags.go:39-46  (1.17.6)
host := &amp;#34;&amp;#34;
if runtime.GOOS == &amp;#34;windows&amp;#34; {
    host = &amp;#34;localhost&amp;#34;
    // Default Bolt database file
    ac.defaultBoltFilename = filepath.Join(serverTempDir, &amp;#34;algernon.db&amp;#34;)
    // Default log file
    ac.defaultLogFile = filepath.Join(serverTempDir, &amp;#34;algernon.log&amp;#34;)
}
```&lt;/p&gt;
&lt;p&gt;```go
// engine/config.go:388-391  (1.17.6, finalConfiguration)
if ac.eventAddr == &amp;#34;&amp;#34; {
    ac.eventAddr = utils.JoinHostPort(host, ac.defaultEventColonPort)
}
```&lt;/p&gt;
&lt;p&gt;Result tabulated:&lt;/p&gt;
&lt;p&gt;| Platform | `host` | `eventAddr` a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gj84-924c-48fx</guid>
    </item>
  </channel>
</rss>
