<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 23:58:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-351600</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351600</link>
      <description>EUVD-2026-351600</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351600</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73431</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73431</link>
      <description>&lt;p&gt;Vulnerability-Lookup contains an 
authentication weakness in its account activation and password-recovery 
mechanism. Activation and recovery links were generated using stateless 
signed tokens containing only the user&amp;#39;s login. Although the token 
signature and age were validated, the application did not track whether a
 token had already been successfully used. As a result, a captured 
activation or password-recovery link remained valid for the entire 
configured TOKEN_VALIDITY_PERIOD, even after the associated password had been changed.&lt;/p&gt;
&lt;p&gt;An attacker who obtains a valid 
activation or recovery token could therefore replay it multiple times 
during its validity period to set a new password and repeatedly take 
control of the affected account. In addition, tokens were not bound to a
 specific purpose, allowing the same token mechanism to be used across 
activation and recovery workflows. The patch introduces purpose-bound 
tokens and a random nonce whose SHA-256 digest is stored with the user 
account. The nonce is invalidated after a successful password change, 
making tokens single-use, while issuing a new token invalidates any 
previously issued token.  The password-setting operation now explicitly consumes the token before committing the account change.&lt;/p&gt;
&lt;p&gt;Successful exploitation requires 
the attacker to obtain a currently valid activation or recovery link, 
but does not require knowledge of the victim&amp;#39;s existing password or an 
authenticated session.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerability-Lookup contains an 
authentication weakness in its account activation and password-recovery 
mechanism. Activation and recovery links were generated using stateless 
signed tokens containing only the user&amp;#39;s login. Although the token 
signature and age were validated, the application did not track whether a
 token had already been successfully used. As a result, a captured 
activation or password-recovery link remained valid for the entire 
configured TOKEN_VALIDITY_PERIOD, even after the associated password had been changed.&lt;/p&gt;
&lt;p&gt;An attacker who obtains a valid 
activation or recovery token could therefore replay it multiple times 
during its validity period to set a new password and repeatedly take 
control of the affected account. In addition, tokens were not bound to a
 specific purpose, allowing the same token mechanism to be used across 
activation and recovery workflows. The patch introduces purpose-bound 
tokens and a random nonce whose SHA-256 digest is stored with the user 
account. The nonce is invalidated after a successful password change, 
making tokens single-use, while issuing a new token invalidates any 
previously issued token.  The password-setting operation now explicitly consumes the token before committing the account change.&lt;/p&gt;
&lt;p&gt;Successful exploitation requires 
the attacker to obtain a currently valid activation or recovery link, 
but does not require knowledge of the victim&amp;#39;s existing password or an 
authenticated session.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73431</guid>
    </item>
    <item>
      <title>GHSA-w4vj-gm7w-293h</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w4vj-gm7w-293h</link>
      <description>&lt;p&gt;Vulnerability-Lookup contains an 
authentication weakness in its account activation and password-recovery 
mechanism. Activation and recovery links were generated using stateless 
signed tokens containing only the user&amp;#39;s login. Although the token 
signature and age were validated, the application did not track whether a
 token had already been successfully used. As a result, a captured 
activation or password-recovery link remained valid for the entire 
configured TOKEN_VALIDITY_PERIOD, even after the associated password had been changed.&lt;/p&gt;
&lt;p&gt;An attacker who obtains a valid 
activation or recovery token could therefore replay it multiple times 
during its validity period to set a new password and repeatedly take 
control of the affected account. In addition, tokens were not bound to a
 specific purpose, allowing the same token mechanism to be used across 
activation and recovery workflows. The patch introduces purpose-bound 
tokens and a random nonce whose SHA-256 digest is stored with the user 
account. The nonce is invalidated after a successful password change, 
making tokens single-use, while issuing a new token invalidates any 
previously issued token.  The password-setting operation now explicitly consumes the token before committing the account change.&lt;/p&gt;
&lt;p&gt;Successful exploitation requires 
the attacker to obtain a currently valid activation or recovery link, 
but does not require knowledge of the victim&amp;#39;s existing password or an 
authenticated session.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerability-Lookup contains an 
authentication weakness in its account activation and password-recovery 
mechanism. Activation and recovery links were generated using stateless 
signed tokens containing only the user&amp;#39;s login. Although the token 
signature and age were validated, the application did not track whether a
 token had already been successfully used. As a result, a captured 
activation or password-recovery link remained valid for the entire 
configured TOKEN_VALIDITY_PERIOD, even after the associated password had been changed.&lt;/p&gt;
&lt;p&gt;An attacker who obtains a valid 
activation or recovery token could therefore replay it multiple times 
during its validity period to set a new password and repeatedly take 
control of the affected account. In addition, tokens were not bound to a
 specific purpose, allowing the same token mechanism to be used across 
activation and recovery workflows. The patch introduces purpose-bound 
tokens and a random nonce whose SHA-256 digest is stored with the user 
account. The nonce is invalidated after a successful password change, 
making tokens single-use, while issuing a new token invalidates any 
previously issued token.  The password-setting operation now explicitly consumes the token before committing the account change.&lt;/p&gt;
&lt;p&gt;Successful exploitation requires 
the attacker to obtain a currently valid activation or recovery link, 
but does not require knowledge of the victim&amp;#39;s existing password or an 
authenticated session.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w4vj-gm7w-293h</guid>
    </item>
  </channel>
</rss>
