<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 02:42:39 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-39364 — Vite has a `server.fs.deny` bypass with queries</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-39364</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vitejs vite, vitejs vite-plus, Red Hat Ansible Automation Platform 2.6, Red Hat Advanced Cluster Security 4, Red Hat Ansible Automation Platform 2, Red Hat Build of Keycloak, Red Hat Build of Podman Desktop, Red Hat Build of Podman Desktop - Tech Preview, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack and 1 more&lt;/p&gt;
&lt;p&gt;Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&amp;amp;raw, or ?import&amp;amp;url&amp;amp;inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vitejs vite, vitejs vite-plus, Red Hat Ansible Automation Platform 2.6, Red Hat Advanced Cluster Security 4, Red Hat Ansible Automation Platform 2, Red Hat Build of Keycloak, Red Hat Build of Podman Desktop, Red Hat Build of Podman Desktop - Tech Preview, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack and 1 more&lt;/p&gt;
&lt;p&gt;Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&amp;amp;raw, or ?import&amp;amp;url&amp;amp;inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-39364</guid>
    </item>
  </channel>
</rss>
