<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 00:12:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-367050</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-367050</link>
      <description>EUVD-2026-367050</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-367050</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49463</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49463</link>
      <description>&lt;p&gt;NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users’ document contents, decisions, audit trails, and decision attachments. Version 3.0.1 contains a patch. As a workaround, block the affected document-content and decision-related GraphQL operations at the API gateway or block their GraphQL types entirely.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users’ document contents, decisions, audit trails, and decision attachments. Version 3.0.1 contains a patch. As a workaround, block the affected document-content and decision-related GraphQL operations at the API gateway or block their GraphQL types entirely.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49463</guid>
    </item>
    <item>
      <title>GHSA-qpm9-h556-mwxm — NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qpm9-h556-mwxm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: nl.nl-portal:documenten-api, Maven: nl.nl-portal:besluiten&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;In versions up to and including 3.0.0, two parts of the GraphQL API returned data without checking whether the data belonged to the logged-in user:&lt;/p&gt;
&lt;p&gt;- **Document content.** A logged-in user could download the raw content of any document by its ID, regardless of who owned it. The resolver has lacked an authentication parameter since the initial commit of the project (2022-11-22) — so every version of `nl.nl-portal:documenten-api` ever published is affected (the earliest one on Maven Central is `0.2.2.RELEASE`, published 2023-08-31).
- **Decisions (`besluiten`).** A logged-in user could list, search, and read decision records — including their audit trails and the documents attached to them — for any user. The list query also accepted filters (decision type, identification, responsible organisation, related case), which made it easy to enumerate decisions across the user base. The `besluiten` module was introduced in the `1.5.x` release line (commit `9229460b`, 2024-08-19), so versions of `nl.nl-portal:besluiten` from `1.5.0` through `3.0.0` are affected.&lt;/p&gt;
&lt;p&gt;Decisions and their attachments often contain sensitive personal data (decisions on benefits, permits, objections, and similar), so the confidentiality impact is high. The two endpoints also chain naturally: once an attacker has discovered another user&amp;#39;s document IDs by enumerating decisions, they can pull those documents&amp;#39; contents through the document endpoint.&lt;/p&gt;
&lt;p&gt;### Why these two findings are reported together&lt;/p&gt;
&lt;p&gt;T…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: nl.nl-portal:documenten-api, Maven: nl.nl-portal:besluiten&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;In versions up to and including 3.0.0, two parts of the GraphQL API returned data without checking whether the data belonged to the logged-in user:&lt;/p&gt;
&lt;p&gt;- **Document content.** A logged-in user could download the raw content of any document by its ID, regardless of who owned it. The resolver has lacked an authentication parameter since the initial commit of the project (2022-11-22) — so every version of `nl.nl-portal:documenten-api` ever published is affected (the earliest one on Maven Central is `0.2.2.RELEASE`, published 2023-08-31).
- **Decisions (`besluiten`).** A logged-in user could list, search, and read decision records — including their audit trails and the documents attached to them — for any user. The list query also accepted filters (decision type, identification, responsible organisation, related case), which made it easy to enumerate decisions across the user base. The `besluiten` module was introduced in the `1.5.x` release line (commit `9229460b`, 2024-08-19), so versions of `nl.nl-portal:besluiten` from `1.5.0` through `3.0.0` are affected.&lt;/p&gt;
&lt;p&gt;Decisions and their attachments often contain sensitive personal data (decisions on benefits, permits, objections, and similar), so the confidentiality impact is high. The two endpoints also chain naturally: once an attacker has discovered another user&amp;#39;s document IDs by enumerating decisions, they can pull those documents&amp;#39; contents through the document endpoint.&lt;/p&gt;
&lt;p&gt;### Why these two findings are reported together&lt;/p&gt;
&lt;p&gt;T…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qpm9-h556-mwxm</guid>
    </item>
  </channel>
</rss>
