<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from github</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:45:07 +0000</lastBuildDate>
    <item>
      <title>GHSA-x4q3-gcj3-m6cf — gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged m…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x4q3-gcj3-m6cf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.com/gitea/runner&lt;/p&gt;
&lt;p&gt;### Summary
act_runner appends workflow-controlled `jobs.&amp;lt;job&amp;gt;.container.options` directly 
to the Docker HostConfig for the job container. When runner privileged mode is 
disabled, only `Privileged` is forced false. Host namespace flags, capability 
expansion, and security profile overrides from workflow YAML are preserved in 
the final HostConfig. A workflow author can enter host PID/IPC namespaces and 
execute commands on the runner host as root.&lt;/p&gt;
&lt;p&gt;### Details
Source-to-sink path in act_runner:&lt;/p&gt;
&lt;p&gt;- `ContainerSpec.Options` accepts workflow YAML `container.options`
- `RunContext.options()` appends workflow options to runner-level container options
- Job container is created with `Privileged: rc.Config.Privileged` but also 
  with `Options: rc.options(ctx)`
- `mergeContainerConfigs()` parses Docker CLI-style options into HostConfig
- When privileged mode is disabled, only `copts.privileged` is forced false
- `sanitizeConfig()` only filters `Binds` and `Mounts`
- Preserved dangerous HostConfig fields:&lt;/p&gt;
&lt;p&gt;```text
Privileged=false
PidMode=host
IpcMode=host
CapAdd=[&amp;#34;ALL&amp;#34;]
SecurityOpt=[&amp;#34;seccomp=unconfined&amp;#34;,&amp;#34;apparmor=unconfined&amp;#34;]
```&lt;/p&gt;
&lt;p&gt;Attacker workflow YAML:
```yaml
jobs:
  breakout:
    runs-on: ubuntu-latest
    container:
      image: ubuntu:22.04
      options: &amp;gt;-
        --pid=host --ipc=host --cap-add=ALL 
        --security-opt seccomp=unconfined 
        --security-opt apparmor=unconfined
    steps:
      - name: host namespace marker
        run: |
          nsenter -t 1 -m -…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gitea.com/gitea/runner&lt;/p&gt;
&lt;p&gt;### Summary
act_runner appends workflow-controlled `jobs.&amp;lt;job&amp;gt;.container.options` directly 
to the Docker HostConfig for the job container. When runner privileged mode is 
disabled, only `Privileged` is forced false. Host namespace flags, capability 
expansion, and security profile overrides from workflow YAML are preserved in 
the final HostConfig. A workflow author can enter host PID/IPC namespaces and 
execute commands on the runner host as root.&lt;/p&gt;
&lt;p&gt;### Details
Source-to-sink path in act_runner:&lt;/p&gt;
&lt;p&gt;- `ContainerSpec.Options` accepts workflow YAML `container.options`
- `RunContext.options()` appends workflow options to runner-level container options
- Job container is created with `Privileged: rc.Config.Privileged` but also 
  with `Options: rc.options(ctx)`
- `mergeContainerConfigs()` parses Docker CLI-style options into HostConfig
- When privileged mode is disabled, only `copts.privileged` is forced false
- `sanitizeConfig()` only filters `Binds` and `Mounts`
- Preserved dangerous HostConfig fields:&lt;/p&gt;
&lt;p&gt;```text
Privileged=false
PidMode=host
IpcMode=host
CapAdd=[&amp;#34;ALL&amp;#34;]
SecurityOpt=[&amp;#34;seccomp=unconfined&amp;#34;,&amp;#34;apparmor=unconfined&amp;#34;]
```&lt;/p&gt;
&lt;p&gt;Attacker workflow YAML:
```yaml
jobs:
  breakout:
    runs-on: ubuntu-latest
    container:
      image: ubuntu:22.04
      options: &amp;gt;-
        --pid=host --ipc=host --cap-add=ALL 
        --security-opt seccomp=unconfined 
        --security-opt apparmor=unconfined
    steps:
      - name: host namespace marker
        run: |
          nsenter -t 1 -m -…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x4q3-gcj3-m6cf</guid>
      <pubDate>Fri, 02 Oct 2026 23:18:12 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-gjj5-9665-rwrc — probe-image-size: Quadratic-time Denial of Service in the SVG Parser</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gjj5-9665-rwrc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: probe-image-size&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;`probe-image-size` scans the SVG header with a searching regular expression, `/&amp;lt;[-_.:a-zA-Z0-9][^&amp;gt;]*&amp;gt;/`. On input that contains many `&amp;lt;` characters but no `&amp;gt;`, the engine restarts the `[^&amp;gt;]*` scan at every `&amp;lt;` position and runs to end of input each time, giving quadratic time complexity.&lt;/p&gt;
&lt;p&gt;Both the synchronous and the streaming parser are affected.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Every entry point that reaches the SVG parser is affected: `probe.sync()`, `probe(stream)` and `probe(url)`. The URL form is the most exposed one — the input is fetched from a remote host, so an attacker only needs to supply a link.&lt;/p&gt;
&lt;p&gt;Processing a crafted buffer blocks the Node.js event loop at 100% CPU for the whole duration. In production environments such as upload validators, image proxies or link unfurl services, a small number of concurrent requests is enough to deny service.&lt;/p&gt;
&lt;p&gt;## Root Cause Analysis&lt;/p&gt;
&lt;p&gt;Two independent problems.&lt;/p&gt;
&lt;p&gt;1. **Absence of input size cap in the sync path.** `lib/parse_sync/svg.js` copied the entire buffer into a string and matched against it. There was no size limit at all, so cost scaled with the size of the attacker-supplied buffer.&lt;/p&gt;
&lt;p&gt;2. **Repeated rescanning in the stream path.** `lib/parse_stream/svg.js` did cap accumulated data at 64 KB, but called `parseSvg(str)` on the whole accumulated string on *every* chunk, giving `O(chunks × N²)`. The cap does not help here: the more chunks the input is split into, the more times the quadratic scan is repeated.&lt;/p&gt;
&lt;p&gt;Chunk size is influence…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: probe-image-size&lt;/p&gt;
&lt;p&gt;## Overview&lt;/p&gt;
&lt;p&gt;`probe-image-size` scans the SVG header with a searching regular expression, `/&amp;lt;[-_.:a-zA-Z0-9][^&amp;gt;]*&amp;gt;/`. On input that contains many `&amp;lt;` characters but no `&amp;gt;`, the engine restarts the `[^&amp;gt;]*` scan at every `&amp;lt;` position and runs to end of input each time, giving quadratic time complexity.&lt;/p&gt;
&lt;p&gt;Both the synchronous and the streaming parser are affected.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Every entry point that reaches the SVG parser is affected: `probe.sync()`, `probe(stream)` and `probe(url)`. The URL form is the most exposed one — the input is fetched from a remote host, so an attacker only needs to supply a link.&lt;/p&gt;
&lt;p&gt;Processing a crafted buffer blocks the Node.js event loop at 100% CPU for the whole duration. In production environments such as upload validators, image proxies or link unfurl services, a small number of concurrent requests is enough to deny service.&lt;/p&gt;
&lt;p&gt;## Root Cause Analysis&lt;/p&gt;
&lt;p&gt;Two independent problems.&lt;/p&gt;
&lt;p&gt;1. **Absence of input size cap in the sync path.** `lib/parse_sync/svg.js` copied the entire buffer into a string and matched against it. There was no size limit at all, so cost scaled with the size of the attacker-supplied buffer.&lt;/p&gt;
&lt;p&gt;2. **Repeated rescanning in the stream path.** `lib/parse_stream/svg.js` did cap accumulated data at 64 KB, but called `parseSvg(str)` on the whole accumulated string on *every* chunk, giving `O(chunks × N²)`. The cap does not help here: the more chunks the input is split into, the more times the quadratic scan is repeated.&lt;/p&gt;
&lt;p&gt;Chunk size is influence…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gjj5-9665-rwrc</guid>
      <pubDate>Fri, 02 Oct 2026 23:18:02 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-x8gv-g2g3-65fj — SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x8gv-g2g3-65fj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;# Security Advisory — SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of `CheckHostSSRF`)&lt;/p&gt;
&lt;p&gt;| Field | Value |
|---|---|
| **Disclosed by** | joysinleung (`joysinleung@gmail.com`) |
| **Report date** | 2026-08-13 |
| **Product** | SiYuan (思源笔记) — `siyuan-note/siyuan` |
| **Go module** | `github.com/siyuan-note/siyuan/kernel` |
| **Affected versions** | `&amp;lt;= 3.8.0` (latest release at report time; dynamically verified on v3.8.0) |
| **Patched versions** | 3.8.1 |
| **Component** | `kernel/util/httprequest.go` (`CheckHostSSRF`), `kernel/mcp/tools/http_request.go`, `kernel/util/webfetch.go`, `kernel/util/net.go` (`SSRFSafeDialer`) |
| **Relationship to prior advisory** | **Incomplete-fix variant of GHSA-rg26-cg95-gq6p** (SSRF main-vector remediation). See §Relationship. |
| **EPSS (exploitation probability)** | Low–Moderate. Requires the attacker to influence an AI Agent / MCP client into fetching an attacker-controlled domain (prompt-injection scenario documented by the tool itself). |
| **KEV (CISA Known Exploited)** | No (not listed in CISA KEV at report time). |
| **Default-config reachable** | **Yes** — exploitable under *both* `SafeMode` on and off; only requires the agent `http_request` / `web_fetch` tool to be reachable (default AI tooling). |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;SiYuan&amp;#39;s AI Agent tools `http_request` (`util.HTTPRequest`) and `web_fetch` (`util.WebFetch`) are the only SSRF gate for outbound requests from the kernel. That gate is `CheckHostSSRF`, which performs a **si…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;# Security Advisory — SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of `CheckHostSSRF`)&lt;/p&gt;
&lt;p&gt;| Field | Value |
|---|---|
| **Disclosed by** | joysinleung (`joysinleung@gmail.com`) |
| **Report date** | 2026-08-13 |
| **Product** | SiYuan (思源笔记) — `siyuan-note/siyuan` |
| **Go module** | `github.com/siyuan-note/siyuan/kernel` |
| **Affected versions** | `&amp;lt;= 3.8.0` (latest release at report time; dynamically verified on v3.8.0) |
| **Patched versions** | 3.8.1 |
| **Component** | `kernel/util/httprequest.go` (`CheckHostSSRF`), `kernel/mcp/tools/http_request.go`, `kernel/util/webfetch.go`, `kernel/util/net.go` (`SSRFSafeDialer`) |
| **Relationship to prior advisory** | **Incomplete-fix variant of GHSA-rg26-cg95-gq6p** (SSRF main-vector remediation). See §Relationship. |
| **EPSS (exploitation probability)** | Low–Moderate. Requires the attacker to influence an AI Agent / MCP client into fetching an attacker-controlled domain (prompt-injection scenario documented by the tool itself). |
| **KEV (CISA Known Exploited)** | No (not listed in CISA KEV at report time). |
| **Default-config reachable** | **Yes** — exploitable under *both* `SafeMode` on and off; only requires the agent `http_request` / `web_fetch` tool to be reachable (default AI tooling). |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;SiYuan&amp;#39;s AI Agent tools `http_request` (`util.HTTPRequest`) and `web_fetch` (`util.WebFetch`) are the only SSRF gate for outbound requests from the kernel. That gate is `CheckHostSSRF`, which performs a **si…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x8gv-g2g3-65fj</guid>
      <pubDate>Fri, 02 Oct 2026 23:17:16 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-p23f-cm6q-2qp8 — SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p23f-cm6q-2qp8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;# Security Advisory — SiYuan MCP `asset.upload` Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)&lt;/p&gt;
&lt;p&gt;| Field | Value |
|---|---|
| **Disclosed by** | joysinleung (`joysinleung@gmail.com`) |
| **Report date** | 2026-08-13 |
| **Product** | SiYuan (思源笔记) — `siyuan-note/siyuan` |
| **Go module** | `github.com/siyuan-note/siyuan/kernel` |
| **Affected versions** | `&amp;lt;= 3.8.0` (latest release at report time; statically confirmed on v3.8.0) |
| **Patched versions** | 3.8.1 |
| **Component** | `kernel/mcp/tools/asset.go` (`assetUpload`), `kernel/model/upload.go` (`InsertLocalAssets`) |
| **Relationship to prior advisory** | **Residual of CVE-2026-66012** (GHSA-cvhv-7xhj-xjp8) MCP remediation. See §Relationship. |
| **EPSS (exploitation probability)** | Low. Requires the AI Agent to invoke `asset.upload` and the user to approve the (category-level) confirmation; reachable via prompt-injection of the agent. |
| **KEV (CISA Known Exploited)** | No (not listed in CISA KEV at report time). |
| **Default-config reachable** | **Partial** — requires the Agent/MCP surface to be configured (admin) and a user approval click; the boundary check itself is entirely absent, so any approved upload reads outside the workspace. |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;SiYuan exposes a native MCP tool `asset` → `asset.upload`. Its `files` argument is documented as a **comma-separated list of absolute file paths**. The handler (`kernel/mcp/tools/asset.go:195`) only normalizes each entry with `filepath.Abs(...)`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;# Security Advisory — SiYuan MCP `asset.upload` Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)&lt;/p&gt;
&lt;p&gt;| Field | Value |
|---|---|
| **Disclosed by** | joysinleung (`joysinleung@gmail.com`) |
| **Report date** | 2026-08-13 |
| **Product** | SiYuan (思源笔记) — `siyuan-note/siyuan` |
| **Go module** | `github.com/siyuan-note/siyuan/kernel` |
| **Affected versions** | `&amp;lt;= 3.8.0` (latest release at report time; statically confirmed on v3.8.0) |
| **Patched versions** | 3.8.1 |
| **Component** | `kernel/mcp/tools/asset.go` (`assetUpload`), `kernel/model/upload.go` (`InsertLocalAssets`) |
| **Relationship to prior advisory** | **Residual of CVE-2026-66012** (GHSA-cvhv-7xhj-xjp8) MCP remediation. See §Relationship. |
| **EPSS (exploitation probability)** | Low. Requires the AI Agent to invoke `asset.upload` and the user to approve the (category-level) confirmation; reachable via prompt-injection of the agent. |
| **KEV (CISA Known Exploited)** | No (not listed in CISA KEV at report time). |
| **Default-config reachable** | **Partial** — requires the Agent/MCP surface to be configured (admin) and a user approval click; the boundary check itself is entirely absent, so any approved upload reads outside the workspace. |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;SiYuan exposes a native MCP tool `asset` → `asset.upload`. Its `files` argument is documented as a **comma-separated list of absolute file paths**. The handler (`kernel/mcp/tools/asset.go:195`) only normalizes each entry with `filepath.Abs(...)`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p23f-cm6q-2qp8</guid>
      <pubDate>Fri, 02 Oct 2026 23:16:56 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-x8mw-p69m-v3mx — @fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x8mw-p69m-v3mx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fastify/busboy&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Versions of `@fastify/busboy` from 1.0.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The multipart header parser stores part-header names on a plain JavaScript object, so a part header named `__proto__` or `constructor` resolves to an inherited value that is not an array, and the parser throws `TypeError: this.header[h].push is not a function`. Through the documented `req.pipe(busboy)` integration this surfaces as an `error` event, while direct `write()`/`end()` usage throws synchronously and can terminate the Node.js process if uncaught. The parser runs before application middleware, so any unauthenticated client that can submit multipart/form-data is affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in version 3.2.1.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Attach an `error` listener to the Busboy stream so the parser failure is handled rather than crashing the process, and wrap direct `write()`/`end()` calls in a try/catch. Upgrading to 3.2.1 removes the failure entirely.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fastify/busboy&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Versions of `@fastify/busboy` from 1.0.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The multipart header parser stores part-header names on a plain JavaScript object, so a part header named `__proto__` or `constructor` resolves to an inherited value that is not an array, and the parser throws `TypeError: this.header[h].push is not a function`. Through the documented `req.pipe(busboy)` integration this surfaces as an `error` event, while direct `write()`/`end()` usage throws synchronously and can terminate the Node.js process if uncaught. The parser runs before application middleware, so any unauthenticated client that can submit multipart/form-data is affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in version 3.2.1.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Attach an `error` listener to the Busboy stream so the parser failure is handled rather than crashing the process, and wrap direct `write()`/`end()` calls in a try/catch. Upgrading to 3.2.1 removes the failure entirely.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x8mw-p69m-v3mx</guid>
      <pubDate>Fri, 02 Oct 2026 23:16:36 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-xjh9-v7x6-24jw — @fastify/busboy vulnerable to Denial of Service via oversized multipart boundary</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xjh9-v7x6-24jw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fastify/busboy&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Versions of `@fastify/busboy` from 3.1.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The vendored streaming multipart search stores its default skip distance in a `Uint8Array(256)`. A multipart boundary of exactly 252 bytes makes the search needle 256 bytes, and the table entry wraps to zero, so a crafted request keeps the search in a CPU-bound loop and stalls the Node.js event loop. An unauthenticated client can trigger this with a single small request. Applications that use `@fastify/busboy` to parse multipart/form-data, directly or through `@fastify/multipart`, are affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in version 3.2.1.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Validate the multipart boundary before parsing and reject any boundary longer than the RFC 2046 limit of 70 characters (for example at a reverse proxy or in an onRequest hook). Upgrading to 3.2.1 removes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @fastify/busboy&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Versions of `@fastify/busboy` from 3.1.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The vendored streaming multipart search stores its default skip distance in a `Uint8Array(256)`. A multipart boundary of exactly 252 bytes makes the search needle 256 bytes, and the table entry wraps to zero, so a crafted request keeps the search in a CPU-bound loop and stalls the Node.js event loop. An unauthenticated client can trigger this with a single small request. Applications that use `@fastify/busboy` to parse multipart/form-data, directly or through `@fastify/multipart`, are affected.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Fixed in version 3.2.1.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Validate the multipart boundary before parsing and reject any boundary longer than the RFC 2046 limit of 70 characters (for example at a reverse proxy or in an onRequest hook). Upgrading to 3.2.1 removes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xjh9-v7x6-24jw</guid>
      <pubDate>Fri, 02 Oct 2026 23:16:17 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-mwm8-39rw-8826 — sqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mwm8-39rw-8826</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: sqlite3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Using `Database#create_aggregate`, `#create_aggregate_handler`, or `Database#define_aggregator` to define an aggregate function that takes two or more arguments, and then evaluating it over TEXT or BLOB column values, can free the Ruby objects holding those arguments while a later argument is still being converted, during ordinary garbage collection. The aggregate&amp;#39;s `step` method then receives an incorrect object, or the process crashes with a segmentation fault.&lt;/p&gt;
&lt;p&gt;## Mitigation&lt;/p&gt;
&lt;p&gt;Upgrade to sqlite3 gem v2.9.6 or later.&lt;/p&gt;
&lt;p&gt;There is no reliable workaround. If you cannot upgrade, avoid defining aggregate functions that take two or more arguments. Restricting column value sizes is not a mitigation: smaller values make the defect fire less often but do not prevent it.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;The sqlite3-ruby maintainers assess this as Medium severity (CVSS 4.0 score 6.3). It is reached through ordinary garbage collection without any unusual code structuring: an application is exposed whenever it evaluates a multi-argument aggregate over TEXT or BLOB values whose size an attacker can influence. The demonstrated impact is an incorrect value passed to the aggregate&amp;#39;s `step` method, or a process crash; no controlled memory write or general denial-of-service exploit has been demonstrated.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Reported by Jeremy Daer ([@jeremy](https://github.com/jeremy)).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: sqlite3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Using `Database#create_aggregate`, `#create_aggregate_handler`, or `Database#define_aggregator` to define an aggregate function that takes two or more arguments, and then evaluating it over TEXT or BLOB column values, can free the Ruby objects holding those arguments while a later argument is still being converted, during ordinary garbage collection. The aggregate&amp;#39;s `step` method then receives an incorrect object, or the process crashes with a segmentation fault.&lt;/p&gt;
&lt;p&gt;## Mitigation&lt;/p&gt;
&lt;p&gt;Upgrade to sqlite3 gem v2.9.6 or later.&lt;/p&gt;
&lt;p&gt;There is no reliable workaround. If you cannot upgrade, avoid defining aggregate functions that take two or more arguments. Restricting column value sizes is not a mitigation: smaller values make the defect fire less often but do not prevent it.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;The sqlite3-ruby maintainers assess this as Medium severity (CVSS 4.0 score 6.3). It is reached through ordinary garbage collection without any unusual code structuring: an application is exposed whenever it evaluates a multi-argument aggregate over TEXT or BLOB values whose size an attacker can influence. The demonstrated impact is an incorrect value passed to the aggregate&amp;#39;s `step` method, or a process crash; no controlled memory write or general denial-of-service exploit has been demonstrated.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Reported by Jeremy Daer ([@jeremy](https://github.com/jeremy)).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mwm8-39rw-8826</guid>
      <pubDate>Fri, 02 Oct 2026 23:11:51 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-cjcg-cxmh-9wcr — Praxis affected by HTTP/2 Bomb</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cjcg-cxmh-9wcr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: praxis-proxy&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Multiple denial-of-service vulnerabilities have been discovered in HTTP/2 server implementations. All have been rated with a severity impact of [Important](https://access.redhat.com/security/updates/classification). The vulnerabilities target HPACK, the header compression scheme in HTTP/2, where a small request can trigger large memory allocations on the server.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Credit to the original researcher, I&amp;#39;m mostly just run their tool against the code base.&lt;/p&gt;
&lt;p&gt;[Security Bulletins](https://access.redhat.com/security/vulnerabilities/RHSB-2026-007): https://access.redhat.com/security/vulnerabilities/RHSB-2026-007 
Exploit details: https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb&lt;/p&gt;
&lt;p&gt;This bug was fixed in upstream pingora v0.8.1, but our fork (v0.8.2) is missing this important [PR](https://github.com/praxis-proxy/pingora/commit/d193c8d49b8b7c1c1ede93183759caa4f6906bbd) to set the default h2 options. (edited)&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;* Generate certificates
```
openssl req -x509 -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -keyout server.key -out server.crt -days 3650 -nodes -subj &amp;#34;/CN=localhost&amp;#34;
```&lt;/p&gt;
&lt;p&gt;* Create praxis config as follow&lt;/p&gt;
&lt;p&gt;```
listeners:
  - name: web
    address: &amp;#34;0.0.0.0:8443&amp;#34;
    tls:
      certificates:
        - cert_path: /etc/praxis/server.crt
          key_path: /etc/praxis/server.key
    filter_chains: [main]&lt;/p&gt;
&lt;p&gt;filter_chains:
  - name: main
    filters:
      - filter: router
        routes:
          - path_prefix: &amp;#34;/&amp;#34;
            host: &amp;#34;examp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: praxis-proxy&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Multiple denial-of-service vulnerabilities have been discovered in HTTP/2 server implementations. All have been rated with a severity impact of [Important](https://access.redhat.com/security/updates/classification). The vulnerabilities target HPACK, the header compression scheme in HTTP/2, where a small request can trigger large memory allocations on the server.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Credit to the original researcher, I&amp;#39;m mostly just run their tool against the code base.&lt;/p&gt;
&lt;p&gt;[Security Bulletins](https://access.redhat.com/security/vulnerabilities/RHSB-2026-007): https://access.redhat.com/security/vulnerabilities/RHSB-2026-007 
Exploit details: https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb&lt;/p&gt;
&lt;p&gt;This bug was fixed in upstream pingora v0.8.1, but our fork (v0.8.2) is missing this important [PR](https://github.com/praxis-proxy/pingora/commit/d193c8d49b8b7c1c1ede93183759caa4f6906bbd) to set the default h2 options. (edited)&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;* Generate certificates
```
openssl req -x509 -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -keyout server.key -out server.crt -days 3650 -nodes -subj &amp;#34;/CN=localhost&amp;#34;
```&lt;/p&gt;
&lt;p&gt;* Create praxis config as follow&lt;/p&gt;
&lt;p&gt;```
listeners:
  - name: web
    address: &amp;#34;0.0.0.0:8443&amp;#34;
    tls:
      certificates:
        - cert_path: /etc/praxis/server.crt
          key_path: /etc/praxis/server.key
    filter_chains: [main]&lt;/p&gt;
&lt;p&gt;filter_chains:
  - name: main
    filters:
      - filter: router
        routes:
          - path_prefix: &amp;#34;/&amp;#34;
            host: &amp;#34;examp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cjcg-cxmh-9wcr</guid>
      <pubDate>Fri, 02 Oct 2026 23:09:37 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-h46j-26q3-rggf — Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h46j-26q3-rggf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: headroom-ai&lt;/p&gt;
&lt;p&gt;### Summary
The Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the browser has access to the Headroom proxy and the OpenAI API key is stored in the `OPENAI_API_KEY` environment variable.&lt;/p&gt;
&lt;p&gt;### Details
The Headroom server defines a WebSocket handler at `ws://&amp;lt;headroom_host&amp;gt;:8787/v1/responses` in `headroom/providers/proxy_routes.py`:
```python
    @app.websocket(&amp;#34;/v1/responses&amp;#34;)
    async def openai_responses_ws(websocket: WebSocket):
        await proxy.handle_openai_responses_ws(websocket)
```
In the `handle_openai_responses_ws()` method of the `OpenAIHandlerMixin` class, the `Origin` header of the WebSocket client handshake is not checked or verified before calling `websocket.accept()`, which grants any WebSocket client (including malicious clients) access to the server:
```python
    async def handle_openai_responses_ws(self, websocket: WebSocket) -&amp;gt; None:
        &amp;#34;&amp;#34;&amp;#34;WebSocket proxy for /v1/responses (Codex gpt-5.4+).&lt;/p&gt;
&lt;p&gt;Newer Codex versions use WebSocket instead of HTTP POST for the
        Responses API.  This handler:
        1. Accepts the client WebSocket
        2. Receives the first message (``response.create`` request)
        3. Opens an…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: headroom-ai&lt;/p&gt;
&lt;p&gt;### Summary
The Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the browser has access to the Headroom proxy and the OpenAI API key is stored in the `OPENAI_API_KEY` environment variable.&lt;/p&gt;
&lt;p&gt;### Details
The Headroom server defines a WebSocket handler at `ws://&amp;lt;headroom_host&amp;gt;:8787/v1/responses` in `headroom/providers/proxy_routes.py`:
```python
    @app.websocket(&amp;#34;/v1/responses&amp;#34;)
    async def openai_responses_ws(websocket: WebSocket):
        await proxy.handle_openai_responses_ws(websocket)
```
In the `handle_openai_responses_ws()` method of the `OpenAIHandlerMixin` class, the `Origin` header of the WebSocket client handshake is not checked or verified before calling `websocket.accept()`, which grants any WebSocket client (including malicious clients) access to the server:
```python
    async def handle_openai_responses_ws(self, websocket: WebSocket) -&amp;gt; None:
        &amp;#34;&amp;#34;&amp;#34;WebSocket proxy for /v1/responses (Codex gpt-5.4+).&lt;/p&gt;
&lt;p&gt;Newer Codex versions use WebSocket instead of HTTP POST for the
        Responses API.  This handler:
        1. Accepts the client WebSocket
        2. Receives the first message (``response.create`` request)
        3. Opens an…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h46j-26q3-rggf</guid>
      <pubDate>Fri, 02 Oct 2026 23:09:15 +0000</pubDate>
    </item>
    <item>
      <title>GHSA-4vpg-gwqq-w44c — SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by ano…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4vpg-gwqq-w44c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;Same CWE-862 family, found via an automated bulk sweep of every
`/api/block/*` handler in `kernel/api/block.go` for the presence of any
access-check reference (`IsReadOnlyRoleContext`, `checkBlockPublishAccess`,
`GetPublishAccess`) anywhere in the function body. 17 of 28 candidate
endpoints have none. Cross-checked against the file&amp;#39;s own sibling
functions (`getBlockInfo`, `getBlockDOM`, `getRefIDs`, etc.), which
correctly implement the check, confirming this is a real, uneven gap
rather than a deliberate design choice for the whole file.&lt;/p&gt;
&lt;p&gt;### Summary
17 handlers in `kernel/api/block.go`, all gated only by `model.CheckAuth`
with no admin-role requirement, return block content-derived text,
structural metadata, or existence information for any block ID supplied,
with no access check anywhere in the handler or, for the ones checked in
detail, the model functions they call. This is CWE-862 (Missing
Authorization), the same class as the companion advisories from this
review round, found in a different file via a systematic bulk check
rather than manual inspection of each function individually.&lt;/p&gt;
&lt;p&gt;### Details
Confirmed via automated extraction of every function body between
`func NAME(c *gin.Context) {` and the next such declaration, then
searching each for any of `IsReadOnlyRoleContext`,
`checkBlockPublishAccess`, `GetPublishAccess`, or `PublishAccess`. The
following contain none of these, at all:&lt;/p&gt;
&lt;p&gt;| Endpoint | What it discloses |
|---|---|
| `getRefText` | The block&amp;#39;s actual refe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;Same CWE-862 family, found via an automated bulk sweep of every
`/api/block/*` handler in `kernel/api/block.go` for the presence of any
access-check reference (`IsReadOnlyRoleContext`, `checkBlockPublishAccess`,
`GetPublishAccess`) anywhere in the function body. 17 of 28 candidate
endpoints have none. Cross-checked against the file&amp;#39;s own sibling
functions (`getBlockInfo`, `getBlockDOM`, `getRefIDs`, etc.), which
correctly implement the check, confirming this is a real, uneven gap
rather than a deliberate design choice for the whole file.&lt;/p&gt;
&lt;p&gt;### Summary
17 handlers in `kernel/api/block.go`, all gated only by `model.CheckAuth`
with no admin-role requirement, return block content-derived text,
structural metadata, or existence information for any block ID supplied,
with no access check anywhere in the handler or, for the ones checked in
detail, the model functions they call. This is CWE-862 (Missing
Authorization), the same class as the companion advisories from this
review round, found in a different file via a systematic bulk check
rather than manual inspection of each function individually.&lt;/p&gt;
&lt;p&gt;### Details
Confirmed via automated extraction of every function body between
`func NAME(c *gin.Context) {` and the next such declaration, then
searching each for any of `IsReadOnlyRoleContext`,
`checkBlockPublishAccess`, `GetPublishAccess`, or `PublishAccess`. The
following contain none of these, at all:&lt;/p&gt;
&lt;p&gt;| Endpoint | What it discloses |
|---|---|
| `getRefText` | The block&amp;#39;s actual refe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4vpg-gwqq-w44c</guid>
      <pubDate>Fri, 02 Oct 2026 23:05:33 +0000</pubDate>
    </item>
  </channel>
</rss>
