<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 06:44:57 +0000</lastBuildDate>
    <item>
      <title>BIT-concourse-2026-49826 — Concourse login flow has an open redirect issue</title>
      <link>https://cve.radiocsirt.org/vuln/bit-concourse-2026-49826</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: concourse&lt;/p&gt;
&lt;p&gt;Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user&amp;#39;s credentials. This has been fixed in 8.2.3. No known workarounds are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: concourse&lt;/p&gt;
&lt;p&gt;Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user&amp;#39;s credentials. This has been fixed in 8.2.3. No known workarounds are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-concourse-2026-49826</guid>
    </item>
    <item>
      <title>EUVD-2026-352817</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352817</link>
      <description>EUVD-2026-352817</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352817</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49826</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49826</link>
      <description>&lt;p&gt;Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user&amp;#39;s credentials. This has been fixed in 8.2.3. No known workarounds are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user&amp;#39;s credentials. This has been fixed in 8.2.3. No known workarounds are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49826</guid>
    </item>
    <item>
      <title>GHSA-8w27-c4vc-88q9 — Concourse login flow has an open redirect issue</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8w27-c4vc-88q9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/concourse/concourse&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user&amp;#39;s credentials.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been fixed in 8.2.3&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;### Exploit&lt;/p&gt;
&lt;p&gt;Vulnerable code was in: https://github.com/concourse/concourse/blob/ea7b812e3a88fdd070f0faece874e8a2d4fbb31c/skymarshal/skyserver/skyserver.go#L162-L170&lt;/p&gt;
&lt;p&gt;The issue stems from the underlying processing logic of Go&amp;#39;s `url` package. Normally, `ParseRequestURI()` will eventually reach an internal `url.setPath()` function, where the URL will be decoded. However, if `RawPath` is not empty and `validEncoded(RawPath)` is true, and the decoded result equals `Path`, then return `RawPath` as is; otherwise, escape `Path` again, i.e., decode it again.&lt;/p&gt;
&lt;p&gt;In other words, if the URL contains dangerous characters that should be escaped, such as backslashes (`\`), then an extra decoding step will be performed. Therefore, `/%2Fexample.com` will be parsed as `//example.com`.&lt;/p&gt;
&lt;p&gt;On vulnerable versions of Concourse, add `/sky/login?redirect_uri=/%252Fexample.com/\` to your Concourse external URL, login as usual, and you should be redirected to `example.com` instead of your Concourse web server. The redirect happens after the login flow completes. No credentials are leaked.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/concourse/concourse&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;An attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user&amp;#39;s credentials.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This has been fixed in 8.2.3&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;None.&lt;/p&gt;
&lt;p&gt;### Exploit&lt;/p&gt;
&lt;p&gt;Vulnerable code was in: https://github.com/concourse/concourse/blob/ea7b812e3a88fdd070f0faece874e8a2d4fbb31c/skymarshal/skyserver/skyserver.go#L162-L170&lt;/p&gt;
&lt;p&gt;The issue stems from the underlying processing logic of Go&amp;#39;s `url` package. Normally, `ParseRequestURI()` will eventually reach an internal `url.setPath()` function, where the URL will be decoded. However, if `RawPath` is not empty and `validEncoded(RawPath)` is true, and the decoded result equals `Path`, then return `RawPath` as is; otherwise, escape `Path` again, i.e., decode it again.&lt;/p&gt;
&lt;p&gt;In other words, if the URL contains dangerous characters that should be escaped, such as backslashes (`\`), then an extra decoding step will be performed. Therefore, `/%2Fexample.com` will be parsed as `//example.com`.&lt;/p&gt;
&lt;p&gt;On vulnerable versions of Concourse, add `/sky/login?redirect_uri=/%252Fexample.com/\` to your Concourse external URL, login as usual, and you should be redirected to `example.com` instead of your Concourse web server. The redirect happens after the login flow completes. No credentials are leaked.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8w27-c4vc-88q9</guid>
    </item>
  </channel>
</rss>
