<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 16:44:54 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-369708</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-369708</link>
      <description>EUVD-2026-369708</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-369708</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54628</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54628</link>
      <description>&lt;p&gt;Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without restricting outbound destinations. A remote attacker can provide a loopback, private-network, or link-local cloud metadata URL, causing go-getter in the Anyquery server process to fetch the selected resource and expose its response as queryable table data. This permits internal network probing, access to internal APIs, and disclosure of cloud credentials; low-integrity impact is possible when a reached internal API performs state-changing actions. This issue is fixed in version 0.4.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without restricting outbound destinations. A remote attacker can provide a loopback, private-network, or link-local cloud metadata URL, causing go-getter in the Anyquery server process to fetch the selected resource and expose its response as queryable table data. This permits internal network probing, access to internal APIs, and disclosure of cloud credentials; low-integrity impact is possible when a reached internal API performs state-changing actions. This issue is fixed in version 0.4.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54628</guid>
    </item>
    <item>
      <title>GHSA-hwrq-8wxh-q4xv — Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hwrq-8wxh-q4xv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/julien040/anyquery&lt;/p&gt;
&lt;p&gt;## Summary
Anyquery&amp;#39;s `server` mode does not restrict outbound HTTP requests initiated by its built-in SQLite virtual table modules (e.g., `json_reader`, `log_reader`). Unauthenticated attackers connecting to the MySQL-compatible server port can create virtual tables pointing to internal network endpoints or Cloud Metadata IPs (e.g., `http://169.254.169.254/latest/meta-data/`). This allows attackers to perform Server-Side Request Forgery (SSRF), bypassing external firewalls to scan internal ports and exfiltrate cloud credentials.&lt;/p&gt;
&lt;p&gt;## Details
When Anyquery is launched in **Server Mode** (`anyquery server`), it binds to a TCP port and accepts MySQL protocol connections. The server handler allows the creation of dynamic virtual tables using modules like `json_reader` or `log_reader`, which internally use `go-getter` to fetch URLs. There is no protection mechanism to prevent fetches to local (127.0.0.0/8), private (10.0.0.0/8), or special (169.254.169.254) IP addresses.&lt;/p&gt;
&lt;p&gt;An attacker can use this to map internal networks, interact with internal APIs, or steal IAM tokens from cloud metadata servers by fetching the data and reading it as a database table.&lt;/p&gt;
&lt;p&gt;## PoC (Proof of Concept)
1. Start the server on the victim machine (e.g., an AWS EC2 instance):
   ```bash
   anyquery server --host 0.0.0.0 --port 8070
   ```
2. Connect from an attacker machine:
   ```bash
   mysql -u root -h &amp;lt;VICTIM_IP&amp;gt; -P 8070
   ```
3. Execute the payload to fetch AWS Metadata or hit a local API:
   ```sql…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/julien040/anyquery&lt;/p&gt;
&lt;p&gt;## Summary
Anyquery&amp;#39;s `server` mode does not restrict outbound HTTP requests initiated by its built-in SQLite virtual table modules (e.g., `json_reader`, `log_reader`). Unauthenticated attackers connecting to the MySQL-compatible server port can create virtual tables pointing to internal network endpoints or Cloud Metadata IPs (e.g., `http://169.254.169.254/latest/meta-data/`). This allows attackers to perform Server-Side Request Forgery (SSRF), bypassing external firewalls to scan internal ports and exfiltrate cloud credentials.&lt;/p&gt;
&lt;p&gt;## Details
When Anyquery is launched in **Server Mode** (`anyquery server`), it binds to a TCP port and accepts MySQL protocol connections. The server handler allows the creation of dynamic virtual tables using modules like `json_reader` or `log_reader`, which internally use `go-getter` to fetch URLs. There is no protection mechanism to prevent fetches to local (127.0.0.0/8), private (10.0.0.0/8), or special (169.254.169.254) IP addresses.&lt;/p&gt;
&lt;p&gt;An attacker can use this to map internal networks, interact with internal APIs, or steal IAM tokens from cloud metadata servers by fetching the data and reading it as a database table.&lt;/p&gt;
&lt;p&gt;## PoC (Proof of Concept)
1. Start the server on the victim machine (e.g., an AWS EC2 instance):
   ```bash
   anyquery server --host 0.0.0.0 --port 8070
   ```
2. Connect from an attacker machine:
   ```bash
   mysql -u root -h &amp;lt;VICTIM_IP&amp;gt; -P 8070
   ```
3. Execute the payload to fetch AWS Metadata or hit a local API:
   ```sql…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hwrq-8wxh-q4xv</guid>
    </item>
  </channel>
</rss>
