<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 17:49:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-326981</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326981</link>
      <description>EUVD-2026-326981</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326981</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46717</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46717</link>
      <description>&lt;p&gt;Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&amp;amp;M tool. From version 1.4.0 to before version 2.0.8, nezha&amp;#39;s dashboard supports two user roles: RoleAdmin (Role==0) and RoleMember (Role==1). The notification routes POST /api/v1/notification and PATCH /api/v1/notification/:id are wired through commonHandler rather than adminHandler — so a RoleMember user can call them. These handlers synchronously Send() an HTTP request to a user-controlled URL and reflect the entire response body (no size limit) back to the caller on any non-2xx response. This issue has been patched in version 2.0.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&amp;amp;M tool. From version 1.4.0 to before version 2.0.8, nezha&amp;#39;s dashboard supports two user roles: RoleAdmin (Role==0) and RoleMember (Role==1). The notification routes POST /api/v1/notification and PATCH /api/v1/notification/:id are wired through commonHandler rather than adminHandler — so a RoleMember user can call them. These handlers synchronously Send() an HTTP request to a user-controlled URL and reflect the entire response body (no size limit) back to the caller on any non-2xx response. This issue has been patched in version 2.0.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46717</guid>
    </item>
    <item>
      <title>GHSA-w4g9-mxgg-j532 — Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w4g9-mxgg-j532</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/nezhahq/nezha&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;nezha&amp;#39;s dashboard supports two user roles: `RoleAdmin` (Role==0) and `RoleMember` (Role==1). The notification routes `POST /api/v1/notification` and `PATCH /api/v1/notification/:id` are wired through `commonHandler` rather than `adminHandler` — so a `RoleMember` user can call them. These handlers synchronously `Send()` an HTTP request to a user-controlled URL and reflect the *entire* response body (no size limit) back to the caller on any non-2xx response.&lt;/p&gt;
&lt;p&gt;Net effect: a low-privilege `RoleMember` can read intranet HTTP response bodies via the dashboard&amp;#39;s hub.&lt;/p&gt;
&lt;p&gt;## Affected versions&lt;/p&gt;
&lt;p&gt;Commit `50dc8e660326b9f22990898142c58b7a5312b42a` and earlier on `master`.&lt;/p&gt;
&lt;p&gt;## Reachability chain&lt;/p&gt;
&lt;p&gt;```
cmd/dashboard/controller/controller.go:121-122
    auth.GET(&amp;#34;/notification&amp;#34;, listHandler(listNotification))
    auth.POST(&amp;#34;/notification&amp;#34;, commonHandler(createNotification))   // &amp;lt;-- commonHandler, not adminHandler
```&lt;/p&gt;
&lt;p&gt;For comparison, `/user` routes ARE gated by `adminHandler`:&lt;/p&gt;
&lt;p&gt;```
auth.GET(&amp;#34;/user&amp;#34;, adminHandler(listUser))
auth.POST(&amp;#34;/user&amp;#34;, adminHandler(createUser))
auth.POST(&amp;#34;/batch-delete/user&amp;#34;, adminHandler(batchDeleteUser))
```&lt;/p&gt;
&lt;p&gt;`adminHandler` (controller.go:220-236) explicitly enforces `user.Role.IsAdmin()`. `commonHandler` (controller.go:214-218) does not.&lt;/p&gt;
&lt;p&gt;## The vulnerable handler&lt;/p&gt;
&lt;p&gt;```go
// cmd/dashboard/controller/notification.go:46-83
func createNotification(c *gin.Context) (uint64, error) {
    var nf model.NotificationForm
    if err := c.ShouldBindJSON(&amp;amp;nf); err != ni…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/nezhahq/nezha&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;nezha&amp;#39;s dashboard supports two user roles: `RoleAdmin` (Role==0) and `RoleMember` (Role==1). The notification routes `POST /api/v1/notification` and `PATCH /api/v1/notification/:id` are wired through `commonHandler` rather than `adminHandler` — so a `RoleMember` user can call them. These handlers synchronously `Send()` an HTTP request to a user-controlled URL and reflect the *entire* response body (no size limit) back to the caller on any non-2xx response.&lt;/p&gt;
&lt;p&gt;Net effect: a low-privilege `RoleMember` can read intranet HTTP response bodies via the dashboard&amp;#39;s hub.&lt;/p&gt;
&lt;p&gt;## Affected versions&lt;/p&gt;
&lt;p&gt;Commit `50dc8e660326b9f22990898142c58b7a5312b42a` and earlier on `master`.&lt;/p&gt;
&lt;p&gt;## Reachability chain&lt;/p&gt;
&lt;p&gt;```
cmd/dashboard/controller/controller.go:121-122
    auth.GET(&amp;#34;/notification&amp;#34;, listHandler(listNotification))
    auth.POST(&amp;#34;/notification&amp;#34;, commonHandler(createNotification))   // &amp;lt;-- commonHandler, not adminHandler
```&lt;/p&gt;
&lt;p&gt;For comparison, `/user` routes ARE gated by `adminHandler`:&lt;/p&gt;
&lt;p&gt;```
auth.GET(&amp;#34;/user&amp;#34;, adminHandler(listUser))
auth.POST(&amp;#34;/user&amp;#34;, adminHandler(createUser))
auth.POST(&amp;#34;/batch-delete/user&amp;#34;, adminHandler(batchDeleteUser))
```&lt;/p&gt;
&lt;p&gt;`adminHandler` (controller.go:220-236) explicitly enforces `user.Role.IsAdmin()`. `commonHandler` (controller.go:214-218) does not.&lt;/p&gt;
&lt;p&gt;## The vulnerable handler&lt;/p&gt;
&lt;p&gt;```go
// cmd/dashboard/controller/notification.go:46-83
func createNotification(c *gin.Context) (uint64, error) {
    var nf model.NotificationForm
    if err := c.ShouldBindJSON(&amp;amp;nf); err != ni…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w4g9-mxgg-j532</guid>
    </item>
  </channel>
</rss>
