<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:09:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-360017</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-360017</link>
      <description>EUVD-2026-360017</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-360017</guid>
    </item>
    <item>
      <title>fkie_cve-2026-72701</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-72701</link>
      <description>&lt;p&gt;Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values byte-by-byte through multiple requests, weakening CSRF protection below its intended security margin.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values byte-by-byte through multiple requests, weakening CSRF protection below its intended security margin.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-72701</guid>
    </item>
    <item>
      <title>GHSA-38p6-h87p-r4cg — Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-38p6-h87p-r4cg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`Grav\Common\Utils::verifyNonce()`, the core function Grav and its plugins use to validate CSRF nonces, compares the submitted nonce to the expected value with PHP&amp;#39;s `===` operator instead of `hash_equals()`. `===` on strings short circuits at the first differing byte, so the comparison time leaks how many leading bytes of a guess are correct. This is CWE-208, Observable Timing Discrepancy.&lt;/p&gt;
&lt;p&gt;The codebase already knows to avoid this pattern. `hash_equals()` is used for the equivalent purpose in four other places I found: `system/src/Grav/Common/Session.php`, `system/src/Grav/Framework/Cache/Adapter/FileCache.php`, `system/src/Grav/Common/Scheduler/Scheduler.php` (the webhook token check), and `system/src/Grav/Common/Scheduler/JobQueue.php`. `Utils::verifyNonce()` is the one place I found that still uses a plain equality check for a secret comparison.&lt;/p&gt;
&lt;p&gt;## Affected product and version&lt;/p&gt;
&lt;p&gt;Product: Grav CMS, getgrav/grav
Confirmed present in: 2.0.15, commit c2b46866857a93a0aa7048e7ed707ed3ed45dbc3&lt;/p&gt;
&lt;p&gt;## Affected code&lt;/p&gt;
&lt;p&gt;`system/src/Grav/Common/Utils.php`, lines 1512 to 1521:
```php
public static function verifyNonce($nonce, $action)
{
    //Safety check for multiple nonces
    if (is_array($nonce)) {
        $nonce = array_shift($nonce);
    }&lt;/p&gt;
&lt;p&gt;//Nonce generated 0-12 hours ago
    if ($nonce === self::getNonce($action)) {
        return true;
    }&lt;/p&gt;
&lt;p&gt;//Nonce generated 12-24 hours ago
    return $nonce === self::getNonce($action, true);
}
```&lt;/p&gt;
&lt;p&gt;The nonce itself is `md5…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: getgrav/grav&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`Grav\Common\Utils::verifyNonce()`, the core function Grav and its plugins use to validate CSRF nonces, compares the submitted nonce to the expected value with PHP&amp;#39;s `===` operator instead of `hash_equals()`. `===` on strings short circuits at the first differing byte, so the comparison time leaks how many leading bytes of a guess are correct. This is CWE-208, Observable Timing Discrepancy.&lt;/p&gt;
&lt;p&gt;The codebase already knows to avoid this pattern. `hash_equals()` is used for the equivalent purpose in four other places I found: `system/src/Grav/Common/Session.php`, `system/src/Grav/Framework/Cache/Adapter/FileCache.php`, `system/src/Grav/Common/Scheduler/Scheduler.php` (the webhook token check), and `system/src/Grav/Common/Scheduler/JobQueue.php`. `Utils::verifyNonce()` is the one place I found that still uses a plain equality check for a secret comparison.&lt;/p&gt;
&lt;p&gt;## Affected product and version&lt;/p&gt;
&lt;p&gt;Product: Grav CMS, getgrav/grav
Confirmed present in: 2.0.15, commit c2b46866857a93a0aa7048e7ed707ed3ed45dbc3&lt;/p&gt;
&lt;p&gt;## Affected code&lt;/p&gt;
&lt;p&gt;`system/src/Grav/Common/Utils.php`, lines 1512 to 1521:
```php
public static function verifyNonce($nonce, $action)
{
    //Safety check for multiple nonces
    if (is_array($nonce)) {
        $nonce = array_shift($nonce);
    }&lt;/p&gt;
&lt;p&gt;//Nonce generated 0-12 hours ago
    if ($nonce === self::getNonce($action)) {
        return true;
    }&lt;/p&gt;
&lt;p&gt;//Nonce generated 12-24 hours ago
    return $nonce === self::getNonce($action, true);
}
```&lt;/p&gt;
&lt;p&gt;The nonce itself is `md5…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-38p6-h87p-r4cg</guid>
    </item>
  </channel>
</rss>
