<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 02:33:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-359018</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-359018</link>
      <description>EUVD-2026-359018</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-359018</guid>
    </item>
    <item>
      <title>fkie_cve-2026-65633</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-65633</link>
      <description>&lt;p&gt;Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification.&lt;/p&gt;
&lt;p&gt;The bearer-token authentication helper AshAuthentication.Plug.Helpers.retrieve_from_bearer/3 verifies an Authorization: Bearer JWT&amp;#39;s signature and rejects tokens containing an act claim, but performs no check that the token&amp;#39;s purpose claim equals user at the bearer boundary. When the resource is configured with require_token_presence_for_authentication?: false (the DSL default), the follow-on validate_token/3 helper returns {:ok, nil} without consulting the token resource, so no downstream check on purpose takes place either. As a result, any valid, non-expired JWT the library itself issued for a narrow, single-purpose flow (most notably the purpose: sign_in token that WebAuthn always emits during sign-in, and that the Password strategy emits when sign-in tokens are enabled) is accepted directly as a general-purpose bearer credential and resolves to a full current_user assignment.&lt;/p&gt;
&lt;p&gt;This bypasses the library&amp;#39;s intended token-exchange contract, in which the sign_in token is meant to be presented exactly once to a preparation that validates the purpose claim and immediately revokes the token. The first use of a still-valid sign-in token presented directly in the Authorization header succeeds because the stateless bearer path never scopes it to purpose == &amp;#34;user&amp;#34;.&lt;/p&gt;
&lt;p&gt;An attacker w…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification.&lt;/p&gt;
&lt;p&gt;The bearer-token authentication helper AshAuthentication.Plug.Helpers.retrieve_from_bearer/3 verifies an Authorization: Bearer JWT&amp;#39;s signature and rejects tokens containing an act claim, but performs no check that the token&amp;#39;s purpose claim equals user at the bearer boundary. When the resource is configured with require_token_presence_for_authentication?: false (the DSL default), the follow-on validate_token/3 helper returns {:ok, nil} without consulting the token resource, so no downstream check on purpose takes place either. As a result, any valid, non-expired JWT the library itself issued for a narrow, single-purpose flow (most notably the purpose: sign_in token that WebAuthn always emits during sign-in, and that the Password strategy emits when sign-in tokens are enabled) is accepted directly as a general-purpose bearer credential and resolves to a full current_user assignment.&lt;/p&gt;
&lt;p&gt;This bypasses the library&amp;#39;s intended token-exchange contract, in which the sign_in token is meant to be presented exactly once to a preparation that validates the purpose claim and immediately revokes the token. The first use of a still-valid sign-in token presented directly in the Authorization header succeeds because the stateless bearer path never scopes it to purpose == &amp;#34;user&amp;#34;.&lt;/p&gt;
&lt;p&gt;An attacker w…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-65633</guid>
    </item>
  </channel>
</rss>
