<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 11:00:58 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-342326</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342326</link>
      <description>EUVD-2026-342326</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342326</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49447</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49447</link>
      <description>&lt;p&gt;Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In 0.22.18, `GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty Authorization header. The handler strips the string Bearer  from the header but never validates the resulting token and never uses it in the database query. This vulnerability is fixed in 0.22.19.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In 0.22.18, `GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty Authorization header. The handler strips the string Bearer  from the header but never validates the resulting token and never uses it in the database query. This vulnerability is fixed in 0.22.19.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49447</guid>
    </item>
    <item>
      <title>GHSA-5fqm-cc34-fcf5 — Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5fqm-cc34-fcf5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/azukaar/cosmos-server&lt;/p&gt;
&lt;p&gt;### Summary
`GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty `Authorization` header. The handler strips the string `Bearer ` from the header but never validates the resulting token and never uses it in the database query.&lt;/p&gt;
&lt;p&gt;This was confirmed locally by routing a request through the real `tokenMiddleware` with `Authorization: Bearer not-a-real-token`. The request returned public Constellation device metadata from a disposable fixture. A missing-header negative control returned `401 Unauthorized`, proving the bypass is specifically the acceptance of arbitrary bearer values.&lt;/p&gt;
&lt;p&gt;### Details
Source-to-sink path:&lt;/p&gt;
&lt;p&gt;- `src/httpServer.go:690` registers `/api/constellation/public-devices` on the authenticated admin API router.
- `src/httpServer.go:815-817` applies `SecureAPI(..., public=false, ...)`, which runs `tokenMiddleware`.
- `src/httpServer.go:231-237` only treats `Authorization: Bearer cosmos_...` as a Cosmos API token for validation. Other bearer strings are not validated by the middleware and fall through to the handler.
- `src/constellation/api_devices_public.go:42-47` checks only that the `Authorization` header is present.
- `src/constellation/api_devices_public.go:49-50` strips `Bearer ` but does not verify the token or compare it with a device/API key.
- `src/constellation/api_devices_public.go:63-67` queries all non-blocked and non-invisible devices without including the stripped auth value i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/azukaar/cosmos-server&lt;/p&gt;
&lt;p&gt;### Summary
`GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty `Authorization` header. The handler strips the string `Bearer ` from the header but never validates the resulting token and never uses it in the database query.&lt;/p&gt;
&lt;p&gt;This was confirmed locally by routing a request through the real `tokenMiddleware` with `Authorization: Bearer not-a-real-token`. The request returned public Constellation device metadata from a disposable fixture. A missing-header negative control returned `401 Unauthorized`, proving the bypass is specifically the acceptance of arbitrary bearer values.&lt;/p&gt;
&lt;p&gt;### Details
Source-to-sink path:&lt;/p&gt;
&lt;p&gt;- `src/httpServer.go:690` registers `/api/constellation/public-devices` on the authenticated admin API router.
- `src/httpServer.go:815-817` applies `SecureAPI(..., public=false, ...)`, which runs `tokenMiddleware`.
- `src/httpServer.go:231-237` only treats `Authorization: Bearer cosmos_...` as a Cosmos API token for validation. Other bearer strings are not validated by the middleware and fall through to the handler.
- `src/constellation/api_devices_public.go:42-47` checks only that the `Authorization` header is present.
- `src/constellation/api_devices_public.go:49-50` strips `Bearer ` but does not verify the token or compare it with a device/API key.
- `src/constellation/api_devices_public.go:63-67` queries all non-blocked and non-invisible devices without including the stripped auth value i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5fqm-cc34-fcf5</guid>
    </item>
  </channel>
</rss>
