<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:42:31 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-13426 — Client4 fails to validate path parameters</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-13426</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mattermost github.com/mattermost/mattermost/server/public&lt;/p&gt;
&lt;p&gt;The Mattermost Go module github.com/mattermost/mattermost/server/public versions &amp;lt; v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal components. Mattermost Advisory ID: MMSA-2025-00532&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mattermost github.com/mattermost/mattermost/server/public&lt;/p&gt;
&lt;p&gt;The Mattermost Go module github.com/mattermost/mattermost/server/public versions &amp;lt; v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal components. Mattermost Advisory ID: MMSA-2025-00532&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-13426</guid>
    </item>
  </channel>
</rss>
