<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 22:44:30 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-374366</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-374366</link>
      <description>EUVD-2026-374366</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-374366</guid>
    </item>
    <item>
      <title>fkie_cve-2026-86064</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-86064</link>
      <description>&lt;p&gt;Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require authentication. The first client message is parsed as a logger Profile in network/api/logs/logSender.go and applied process-wide through Profile.Apply, allowing a remote client to change global log levels and formatting options until the connection closes. The same connection is registered as a log observer and can receive live process logs. An attacker can suppress normal logs, increase verbosity, distort operator visibility, and access operational information without credentials. This issue is fixed in version 1.7.20.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require authentication. The first client message is parsed as a logger Profile in network/api/logs/logSender.go and applied process-wide through Profile.Apply, allowing a remote client to change global log levels and formatting options until the connection closes. The same connection is registered as a log observer and can receive live process logs. An attacker can suppress normal logs, increase verbosity, distort operator visibility, and access operational information without credentials. This issue is fixed in version 1.7.20.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-86064</guid>
    </item>
    <item>
      <title>GHSA-9v8p-frvj-2pcm — Klever-Go: /log controls global node logging</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9v8p-frvj-2pcm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/klever-io/klever-go&lt;/p&gt;
&lt;p&gt;An unauthenticated client can connect to `GET /log`, send an arbitrary logger profile as the first WebSocket message, and mutate the node&amp;#39;s global logging configuration before receiving live logs from the process. I confirmed this against a local validator built from this repository: an unauthenticated client set the global log level to `*:NONE`, the node accepted the profile, and the node stopped emitting normal slot logs while the WebSocket connection remained open.&lt;/p&gt;
&lt;p&gt;This is not a duplicate of the published KVM or P2P advisories. It is a management-plane flaw in the public WebSocket logging endpoint.&lt;/p&gt;
&lt;p&gt;## Vulnerability details&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- Route exposed by default in `config/node/api.yaml`
- Route registration in `network/api/api.go`
- Unauthenticated upgrade in `network/api/api.go`
- First client message is parsed as a logger profile and applied globally in `network/api/logs/logSender.go`
- Global logger mutation happens in dependency `github.com/klever-io/klever-go-logger`, `profile.go`, `Apply()`&lt;/p&gt;
&lt;p&gt;### Root cause&lt;/p&gt;
&lt;p&gt;`/log` is enabled by default and does not require authentication. After the WebSocket upgrade, the server reads the first client message and treats it as a logger `Profile`. That profile is then applied process-wide through `profile.Apply()`, which changes global log level patterns and output formatting options for the whole node.&lt;/p&gt;
&lt;p&gt;After that handshake, the same unauthenticated connection is registered as a log observer and receives live logs from the r…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/klever-io/klever-go&lt;/p&gt;
&lt;p&gt;An unauthenticated client can connect to `GET /log`, send an arbitrary logger profile as the first WebSocket message, and mutate the node&amp;#39;s global logging configuration before receiving live logs from the process. I confirmed this against a local validator built from this repository: an unauthenticated client set the global log level to `*:NONE`, the node accepted the profile, and the node stopped emitting normal slot logs while the WebSocket connection remained open.&lt;/p&gt;
&lt;p&gt;This is not a duplicate of the published KVM or P2P advisories. It is a management-plane flaw in the public WebSocket logging endpoint.&lt;/p&gt;
&lt;p&gt;## Vulnerability details&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- Route exposed by default in `config/node/api.yaml`
- Route registration in `network/api/api.go`
- Unauthenticated upgrade in `network/api/api.go`
- First client message is parsed as a logger profile and applied globally in `network/api/logs/logSender.go`
- Global logger mutation happens in dependency `github.com/klever-io/klever-go-logger`, `profile.go`, `Apply()`&lt;/p&gt;
&lt;p&gt;### Root cause&lt;/p&gt;
&lt;p&gt;`/log` is enabled by default and does not require authentication. After the WebSocket upgrade, the server reads the first client message and treats it as a logger `Profile`. That profile is then applied process-wide through `profile.Apply()`, which changes global log level patterns and output formatting options for the whole node.&lt;/p&gt;
&lt;p&gt;After that handshake, the same unauthenticated connection is registered as a log observer and receives live logs from the r…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9v8p-frvj-2pcm</guid>
    </item>
  </channel>
</rss>
