<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title><![CDATA[Advisories]]></title><link>https://ole-hartwig.eu/en/advisories</link><description><![CDATA[Security advisories for the stack I run myself: TYPO3, PHP, Composer, FrankenPHP, Sylius, GitLab, nginx and the npm supply chain. With context and sources.]]></description><language>en-GB</language><lastBuildDate>Thu, 01 Oct 2026 10:05:28 +0200</lastBuildDate><atom:link href="https://ole-hartwig.eu/en/advisories/feed.xml" rel="self" type="application/rss+xml" /><item><title><![CDATA[Review 2026: Security advisories from May to September]]></title><link>https://ole-hartwig.eu/en/advisories/review-2026</link><guid isPermaLink="false">https://ole-hartwig.eu/page-3753</guid><description><![CDATA[Security advisories from May to September 2026 for PHP, TYPO3 and Kubernetes operators: npm supply chain, Linux kernel, web servers, AI agents. Briefly put in context.]]></description><pubDate>Tue, 29 Sep 2026 21:48:43 +0200</pubDate></item><item><title><![CDATA[Sylius Security Release 1.12.25 / 1.13.17 / 1.14.20 / 2.1.16 / 2.2.9: JWT Audience Confusion Lets a Shop Customer Take Over the Admin API]]></title><link>https://ole-hartwig.eu/en/advisories/sylius-security-release-1-12-25-1-13-17-1-14-20-2-1-16-2-2-9-jwt-audience-confusion</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2885</guid><description><![CDATA[Sylius 1.12.25/1.13.17/1.14.20/2.1.16/2.2.9 fix four flaws: JWT audience confusion (admin takeover), password-reset host poisoning, order-total inflation after payment capture, and unchecked payment-request actions.]]></description><pubDate>Thu, 24 Sep 2026 08:33:19 +0200</pubDate></item><item><title><![CDATA[TYPO3 14.3.7 and 13.4.35: Information Disclosure in the Localization Wizard and Missing Authorization for Configuration Commands Fixed]]></title><link>https://ole-hartwig.eu/en/advisories/typo3-14-3-7-13-4-35-security-release-sa-022-sa-023</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2877</guid><description><![CDATA[TYPO3 14.3.7 and 13.4.35 fix two security issues: information disclosure in the localization wizard (CVE-2026-77132) and missing authorization for configuration commands (CVE-2026-85400).]]></description><pubDate>Sat, 19 Sep 2026 08:22:15 +0200</pubDate></item><item><title><![CDATA[redis-parser CVE-2026-93435: Unbounded Recursion in RESP Parsing Crashes ioredis Clients]]></title><link>https://ole-hartwig.eu/en/advisories/redis-parser-cve-2026-93435-ioredis-resp-recursion-dos</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2875</guid><description><![CDATA[redis-parser CVE-2026-93435: unbounded recursion in RESP parsing crashes ioredis clients via stack overflow. CVSS 7.5/8.7, no patch available yet.]]></description><pubDate>Sat, 19 Sep 2026 08:19:54 +0200</pubDate></item><item><title><![CDATA[GitLab CVE-2026-85706: Path Traversal in the Commits API Allows Unauthenticated Reading of Arbitrary Files — Actively Exploited, CVSS 10.0, Now in the CISA KEV]]></title><link>https://ole-hartwig.eu/en/advisories/gitlab-cve-2026-85706-commits-api-path-traversal-unauthenticated-file-read-kev</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2837</guid><description><![CDATA[GitLab CVE-2026-85706: unauthenticated path traversal in the commits API of self-managed instances. CVSS 10.0, actively exploited, CISA KEV. Affected versions, patch and detection.]]></description><pubDate>Thu, 17 Sep 2026 08:21:20 +0200</pubDate></item><item><title><![CDATA[TYPO3-EXT-SA-2026-025: Five CVEs in “Apache Solr for TYPO3” — from broken access control to PHP object injection]]></title><link>https://ole-hartwig.eu/en/advisories/typo3-ext-sa-2026-025-apache-solr-broken-access-control-deserialization</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2776</guid><description><![CDATA[TYPO3-EXT-SA-2026-025: five vulnerabilities in the “Apache Solr for TYPO3” extension — broken access control, information disclosure, and PHP object injection via unserialize(). Affected versions, patch, and detection.]]></description><pubDate>Sat, 29 Aug 2026 08:23:47 +0200</pubDate></item><item><title><![CDATA[SCTPhantom (CVE-2026-64564): An 18-Year-Old Use-After-Free in the Linux Kernel's SCTP Stack — Root Claim Disputed]]></title><link>https://ole-hartwig.eu/en/advisories/cve-2026-64564-sctphantom-linux-kernel-sctp-use-after-free-container-escape</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2763</guid><description><![CDATA[Tencent's Zhuque Lab used an AI-assisted tool called “Corvus AI” to find a use-after-free in SCTP's dynamic address reconfiguration (ASCONF) that has existed since kernel 2.6.25 (2008). Fixes have shipped since August 3, 2026 across four kernel branches; Tencent claims root access with container escape on several distros — a claim that remains independently unconfirmed. I break down what's solid, what's disputed, and how to simply turn SCTP off if you don't need it.]]></description><pubDate>Sat, 08 Aug 2026 08:21:53 +0200</pubDate></item><item><title><![CDATA[Keyv/Cacheable npm Compromise: Mini Shai-Hulud Worm Poisons Hundreds of Packages via preinstall Hook and Claude Code/VS Code Autostart]]></title><link>https://ole-hartwig.eu/en/advisories/keyv-cacheable-npm-mini-shai-hulud-supply-chain-worm</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2759</guid><description><![CDATA[On 4 August 2026, the release pipeline for keyv and roughly a dozen related npm packages (the cacheable family, flat-cache, file-entry-cache, cache-manager and others) was compromised. A newly inserted preinstall hook loads an encrypted Bun-runtime payload that harvests cloud (AWS/GCP/Azure), CI/CD, and npm/GitHub credentials, self-propagates via npm Trusted Publishing, and additionally drops autostart hooks in .claude/settings.json and .vscode/tasks.json — executing as soon as a cloned repo is opened, even without npm install. Snyk tracks the incident as SNYK-JS-KEYV-18515941 (Critical); no official CVE number had been assigned at the time of this article.]]></description><pubDate>Wed, 05 Aug 2026 08:25:15 +0200</pubDate></item><item><title><![CDATA[TYPO3-EXT-SA-2026-013 (CVE-2026-46725): Insecure Deserialization in “Content Element Selector” (ceselector) — Unauthenticated RCE, Fixed in 6.0.1/5.0.1/4.0.2/3.0.3]]></title><link>https://ole-hartwig.eu/en/advisories/typo3-cve-2026-46725-ceselector-deserialization-rce</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2758</guid><description><![CDATA[TYPO3-EXT-SA-2026-013 / CVE-2026-46725 (CVSS 4.0, Critical): the third-party extension “Content Element Selector” (mmc/ceselector) passes a client-controlled cookie straight into PHP's unserialize(). On content elements configured with “Persistent Mode: Static” this enables PHP object injection — and, via a publicly documented gadget chain through Monolog classes, unauthenticated remote code execution. Affected: ceselector ≤6.0.0, ≤5.0.0, 4.0.0–4.0.1, ≤3.0.2. Fix: 6.0.1/5.0.1/4.0.2/3.0.3.]]></description><pubDate>Wed, 05 Aug 2026 08:20:26 +0200</pubDate></item><item><title><![CDATA[PHP 8.5.9, 8.4.24, 8.3.33, 8.2.33: coordinated security release fixes PostgreSQL SQL injection and BCMath memory corruption]]></title><link>https://ole-hartwig.eu/en/advisories/php-8-5-9-8-4-24-8-3-33-8-2-33-security-release-cve-2026-17543-17544</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2755</guid><description><![CDATA[Between 28 and 30 July 2026, the PHP project published a coordinated security release for all four supported branches: 8.2.33, 8.3.33, 8.4.24 and 8.5.9. It fixes four flaws. CVE-2026-17543 (GHSA-7qpv-r5mr-78m4) is an SQL injection in the PGSQL and PDO_PGSQL extensions, caused by a gap in escaping the E'...' backslash syntax. CVE-2026-17544 (GHSA-x692-q9x7-8c3f) is an out-of-bounds write in bc_str2num(), reached through BCMath's bccomp(). CVE-2026-7260 (GHSA-vc5h-9ppw-p5f3) is a denial-of-service crash in Phar caused by recursive symlinks. CVE-2026-9672 is an upgrade of the bundled libgd library, with no public technical detail. php.net has published no official CVSS scores. No active exploitation is known so far. In practice, CVE-2026-17543 matters most for any codebase that inserts user input into PostgreSQL string literals with E'...' syntax without parameter binding.]]></description><pubDate>Thu, 30 Jul 2026 18:05:02 +0200</pubDate></item><item><title><![CDATA[Langflow CVE-2026-0770: exec_globals Enables Unauthenticated RCE — Langflow's Second CISA KEV Entry, No Patch in Sight]]></title><link>https://ole-hartwig.eu/en/advisories/langflow-cve-2026-0770-exec-globals-unauthenticated-rce</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2706</guid><description><![CDATA[CVE-2026-0770 (GHSA-g22f-v6f7-2hrh, ZDI-CAN-27325) is an unauthenticated remote code execution flaw in Langflow: the /api/v1/validate/code endpoint passes the exec_globals parameter unchecked into Python's exec(). GitHub's Advisory Database scores it CVSS 4.0 8.9; NVD and ZDI score it CVSS 3.0 9.8. Actively exploited since around 27 Jun 2026, added to CISA's KEV catalog on 21 Jul 2026 — Langflow's second vulnerability there. No confirmed patch exists as of this writing.]]></description><pubDate>Mon, 27 Jul 2026 08:22:01 +0200</pubDate></item><item><title><![CDATA[NGINX CVE-2026-42533: Heap Buffer Overflow from Capture-Variable Ordering in map/regex — Patch Mandatory for Kubernetes Ingress]]></title><link>https://ole-hartwig.eu/en/advisories/nginx-cve-2026-42533-heap-buffer-overflow-map-regex</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2674</guid><description><![CDATA[CVE-2026-42533 is a heap buffer overflow (CWE-122) in NGINX Open Source and NGINX Plus, triggered by a race condition between the two evaluation passes of the map directive mechanism: if a string expression references a regex-based map's numbered capture variables ($1, $2, …) before referencing the map's own output variable, NGINX's internal re-evaluation of the regex overwrites the shared capture state — with an attacker-controlled request supplying both the length and content of the overflow. Affected are NGINX 0.9.6 through 1.31.2 and NGINX Plus prior to 37.0.3.1; fixed in 1.31.3 (mainline), 1.30.4 (stable), and Plus 37.0.3.1. CVSSv4 9.2 (Critical) / CVSSv3.1 8.1 (High); the DoS path (worker crash) is reliably reproducible, an RCE path via ASLR bypass is plausible but not yet publicly demonstrated. The vulnerability is configuration-dependent and notably affects NGINX Ingress Controller, Gateway Fabric, App Protect WAF, and Instance Manager, which embed the NGINX engine.]]></description><pubDate>Thu, 23 Jul 2026 08:20:08 +0200</pubDate></item><item><title><![CDATA[LiteLLM CVE-2026-47101, -47102, -40217: From a Low-Privilege User to proxy_admin and RCE — a Three-Bug Chain in the AI Gateway]]></title><link>https://ole-hartwig.eu/en/advisories/litellm-cve-2026-47101-47102-40217-privilege-escalation-rce-chain</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2564</guid><description><![CDATA[GHSA-qrc4-49gv-mv9m / CVE-2026-47101 (CVSS 4.0 8.7, CWE-863): LiteLLM does not validate the allowed_routes field against the requesting user's role when generating API keys (/key/generate and similar) — an internal_user can mint a key with access to admin-only routes. CVE-2026-47102: /user/update and /user/bulk_update do not check which fields a user may write on their own account — the user sets their own user_role field to proxy_admin. CVE-2026-40217: the Custom Code Guardrail executes Python code via exec() without stripping __builtins__ — __import__, open and eval remain reachable; a separate regex bypass on the playground endpoint additionally allows bytecode manipulation. Chained together, the three flaws provide a path from an ordinary internal account to full remote code execution on the LiteLLM proxy server — with access to provider API keys, database credentials and all prompts/responses passing through. Affects LiteLLM prior to v1.83.14-stable. No confirmed in-the-wild exploitation is known so far, but a working public proof-of-concept exists. Covered retroactively: first published 21 May 2026, GHSA updated 11 June 2026 — not a 48-hour find, but given the severity and the fact that LiteLLM has repeatedly been a topic on this blog, a deliberate follow-up.]]></description><pubDate>Sat, 18 Jul 2026 09:17:20 +0200</pubDate></item><item><title><![CDATA[TYPO3 SA-2026-020 (CVE-2026-15305): the Form Framework's MimeTypeValidator was never registered — fixed in 14.3.5]]></title><link>https://ole-hartwig.eu/en/advisories/typo3-cve-2026-15305-form-framework-mimetypevalidator</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2394</guid><description><![CDATA[TYPO3-CORE-SA-2026-020 / CVE-2026-15305 (CVSS 4.0, Medium): the MimeTypeValidator for FileUpload and ImageUpload elements in the Form Framework was registered while the form object was being built — before the concrete form definition was applied — so it never made it into the active processing pipeline. Result: users could upload files of any MIME type regardless of the allowlist configured in the form. Affects TYPO3 14.2.0 through 14.3.4; 13.4 LTS is not affected. PHP file uploads stayed blocked through a separate, independent check. Fix: TYPO3 14.3.5 LTS, no database update required.]]></description><pubDate>Thu, 16 Jul 2026 08:28:00 +0200</pubDate></item><item><title><![CDATA[Sylius Mollie Plugin: payment webhook forgery and order ID enumeration — fixed in 2.2.9 / 3.2.5 / 3.3.2]]></title><link>https://ole-hartwig.eu/en/advisories/sylius-mollie-plugin-payment-webhook-forgery-order-enumeration</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2386</guid><description><![CDATA[GHSA-rc52-c4hv-w89p (High) and GHSA-x83g-979r-f5fh (Moderate): the payment webhook in sylius/mollie-plugin doesn't verify that an incoming Mollie payment ID belongs to the affected order — attackers can mark other people's orders as paid without paying. The QR-code and thank-you endpoints also allow enumerating order IDs to harvest customer data. Affected: 2.2.8, 3.2.4, 3.3.1 and earlier, plus the deprecated third-party packages bitbag/mollie-plugin and mollie/sylius-plugin. Fix: 2.2.9 / 3.2.5 / 3.3.2. CVE numbers are still pending.]]></description><pubDate>Wed, 15 Jul 2026 10:28:30 +0200</pubDate></item><item><title><![CDATA[GhostLock (CVE-2026-43499): a 15-year-old futex race in the Linux kernel opens the door to root and container escape]]></title><link>https://ole-hartwig.eu/en/advisories/ghostlock-cve-2026-43499-linux-kernel-futex-use-after-free-root-container-escape</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2378</guid><description><![CDATA[CVE-2026-43499 (GhostLock, CVSS 7.8, disclosed 8 Jul 2026): use-after-free in the Linux kernel's futex priority-inheritance cleanup logic, present in the code since 2011. Local privilege escalation to root in roughly 5 seconds, demonstrated container escape from Docker/Kubernetes/K3s to the host. Public exploit code on GitHub. Patch rollout uneven across distributions.]]></description><pubDate>Tue, 14 Jul 2026 11:09:08 +0200</pubDate></item><item><title><![CDATA[npm v12: install scripts are now off by default — what it means for your CI]]></title><link>https://ole-hartwig.eu/en/advisories/npm-v12-install-scripts-off-by-default</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2373</guid><description><![CDATA[npm v12 (release announced for July 2026) flips allowScripts to off by default — preinstall/install/postinstall and implicit node-gyp builds no longer run automatically, and git/remote-URL dependencies are blocked without explicit approval. Migration via npm approve-scripts.]]></description><pubDate>Tue, 14 Jul 2026 10:58:30 +0200</pubDate></item><item><title><![CDATA[GitLab patch release 19.0.2 / 18.11.5 / 18.10.8: two High flaws allow account takeover and XSS — update self-managed now]]></title><link>https://ole-hartwig.eu/en/advisories/gitlab-patch-release-19-0-2-18-11-5-18-10-8-cve-2026-6552-10087</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2123</guid><description><![CDATA[Scheduled GitLab batch patch release (10 June 2026): twelve fixes, four High. The headline is two CVSS 8.7 Enterprise Edition flaws — CVE-2026-6552 (account takeover via the Group SAML identity API, owner precondition) and CVE-2026-10087 (XSS in the Analytics Dashboard). Plus CVE-2026-7250 (unauthenticated DoS in the Grape API, CE/EE) and CVE-2026-9204 (SSRF in the Gitaly repository import, CE/EE). Only self-managed below 18.10.8 / 18.11.5 / 19.0.2 is affected; GitLab.com and Dedicated are covered. A CI/CD hub holds code and secrets at once — patch cadence is supply-chain security.]]></description><pubDate>Sat, 13 Jun 2026 11:32:22 +0200</pubDate></item><item><title><![CDATA[TYPO3 14.3.3 & 13.4.31: 14 security advisories in one day — every one of the 15 vulnerabilities analysed individually]]></title><link>https://ole-hartwig.eu/en/advisories/typo3-14-3-3-13-4-31-security-release-14-advisories</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2047</guid><description><![CDATA[TYPO3 14.3.3 and 13.4.31: 14 security advisories (SA-2026-006 to -019) with 15 CVEs, each vulnerability analysed individually — Form Framework SQLi,…]]></description><pubDate>Tue, 09 Jun 2026 14:16:00 +0200</pubDate></item><item><title><![CDATA[Miasma moves from the package manager into the editor: a clone + “open folder” in Claude Code, Cursor, Gemini CLI or VS Code is enough — and it hit Azure/durabletask too]]></title><link>https://ole-hartwig.eu/en/advisories/miasma-ai-coding-agent-config-injection-claude-cursor-gemini-vscode</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2027</guid><description><![CDATA[The Miasma family follows the developer from the package manager into the editor: a commit plants six files, five of them triggers (SessionStart hook in .claude/.gemini, alwaysApply rule in .cursor, folderOpen task in .vscode, test-script hijack) for a 4.3 MB Bun dropper. Cloning is safe, opening is not. 113 repos (floor) incl. Azure/durabletask. --ignore-scripts does not catch a SessionStart hook. With mitigation, detection, operator guidance.]]></description><pubDate>Sun, 07 Jun 2026 09:29:00 +0200</pubDate></item><item><title><![CDATA[PHP SOAP: CVE-2026-6722 — unauthenticated use-after-free RCE in ext-soap (plus four more PHP findings in the same release)]]></title><link>https://ole-hartwig.eu/en/advisories/php-soap-cve-2026-6722-use-after-free-rce-cluster</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2029</guid><description><![CDATA[CVE-2026-6722: use-after-free in PHP ext-soap (object dedup via id/href without refcount increment, Apache-map UAF, heap grooming via strings) — unauthenticated RCE on SoapServer exposure. Plus CVE-2026-7261 (UAF SoapServer/session), -7262 (NULL deref/DoS), -7258 (OOB read in urldecode, SOAP-independent) and -6104 (mbstring overrun). Fix 8.2.31/8.3.31/8.4.21/8.5.6. My own practice: SOAP practically retired — disabled is not the same as not loaded. Deliberately not a 48h daily item (disclosure 12 May 2026).]]></description><pubDate>Sat, 06 Jun 2026 10:30:00 +0200</pubDate></item><item><title><![CDATA[IronWorm: a Rust npm worm that abuses npm Trusted Publishing, vanishes behind an eBPF rootkit and exfiltrates without C2]]></title><link>https://ole-hartwig.eu/en/advisories/ironworm-rust-npm-worm-trusted-publishing-ebpf-rootkit</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2127</guid><description><![CDATA[The Rust npm worm IronWorm runs via a preinstall hook, harvests 86 environment variables including AI provider keys and ~/.claude credentials, self-publishes in CI via npm Trusted Publishing, exfiltrates without C2 through swapped GitHub Actions workflows, and hides behind an eBPF rootkit (which fails under kernel lockdown). With mitigation, detection IOCs, a root-cause deep dive and operator guidance; package list delegated to JFrog.]]></description><pubDate>Sat, 06 Jun 2026 07:26:00 +0200</pubDate></item><item><title><![CDATA[binding.gyp - an npm supply chain worm that abuses node-gyp instead of postinstall — and harvests CI/CD credentials]]></title><link>https://ole-hartwig.eu/en/advisories/binding-gyp-npm-node-gyp-supply-chain-worm-credential-harvesting</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2010</guid><description><![CDATA[Ongoing npm supply chain incident: a self-replicating worm uses binding.gyp/node-gyp instead of postinstall, downloads the Bun runtime, harvests cloud/registry credentials, injects setup-bun into GitHub Actions workflows and poisons further packages of the victim. With mitigation, detection IOCs and operator guidance — package list delegated to the primary source.]]></description><pubDate>Thu, 04 Jun 2026 21:37:06 +0200</pubDate></item><item><title><![CDATA[FrankenPHP 1.12.4 closes underscore-header spoofing — and bundles the security patches from Caddy 2.11.4 and Mercure 0.24.2]]></title><link>https://ole-hartwig.eu/en/advisories/frankenphp-1-12-4-underscore-header-spoofing-caddy-2-11-4-mercure-0-24-2</link><guid isPermaLink="false">https://ole-hartwig.eu/page-2004</guid><description><![CDATA[Hardening release FrankenPHP 1.12.4: underscore-header spoofing closed at the server, bundled Caddy 2.11.4 and Mercure 0.24.2 security patches, plus worker-mode crash and data-race fixes. No active 0-day, but „every user should upgrade“ — with mitigation, detection and operator guidance.]]></description><pubDate>Thu, 04 Jun 2026 16:37:00 +0200</pubDate></item><item><title><![CDATA[Sylius security release 2.0.18 / 2.1.15 / 2.2.6 — three flaws in the shop and payment API path (cart LiveComponent, payment IDOR, channel bypass)]]></title><link>https://ole-hartwig.eu/en/advisories/sylius-security-release-cart-livecomponent-payment-idor-channel-bypass</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1991</guid><description><![CDATA[Incident analysis (cluster post) of the Sylius security release of 2 June 2026. Three advisories in the shop/payment API path: GHSA-5597-7rmh-97q5 (cart FormComponent deletes/alters a completed order, CVSS 6.5, CWE-672/841), GHSA-mr9r-h354-966r (IDOR on shop payment-request endpoints, CWE-639) and GHSA-6955-hrm5-c4qp (channel-based payment-method restriction bypass, CVSS 4.3, CWE-863). Affected: 2.0.0-2.0.17, 2.1.0-2.1.14, 2.2.0-2.2.5. Fixed in 2.0.18 / 2.1.15 / 2.2.6. No CVE IDs, all Moderate, no known active exploitation. Fix via composer update; each flaw has a documented service-override workaround.]]></description><pubDate>Wed, 03 Jun 2026 17:13:59 +0200</pubDate></item><item><title><![CDATA[CVE-2026-1784: OpenShift Ingress Operator — RCE via HAProxy config injection in the Route spec.path]]></title><link>https://ole-hartwig.eu/en/advisories/cve-2026-1784-openshift-ingress-operator-haproxy-config-injection-route-path-rce</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1927</guid><description><![CDATA[Incident analysis of CVE-2026-1784: config injection leading to RCE in the OpenShift ingress operator. The spec.path field of a Route object is insufficiently validated; tenant-controlled content flows into the HAProxy configuration generated by the ose-cluster-ingress-operator for the shared router. CVSS v3.1 8.8 (AV:L/AC:L/PR:L/S:C/C:H/I:H/A:H), CWE-15. Entry condition: write access to Route objects in a namespace. Scope Changed — the impact leaves the tenant namespace and hits the cluster-wide ingress. Fix via Red Hat errata for the relevant 4.x line; stopgap: an admission policy on spec.path.]]></description><pubDate>Tue, 02 Jun 2026 15:52:00 +0200</pubDate></item><item><title><![CDATA[Miasma: The Spreading Blight — when a trusted npm namespace becomes the supply chain for a cloud-identity worm]]></title><link>https://ole-hartwig.eu/en/advisories/miasma-redhat-cloud-services-npm-mini-shai-hulud-cloud-identity-worm</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1919</guid><description><![CDATA[Incident analysis of the Miasma wave: 32 compromised @redhat-cloud-services npm packages, a variant of TeamPCP's open-sourced Mini Shai-Hulud. Patient zero was a compromised Red Hat employee GitHub account with orphan commits to two RedHatInsights repos; publishing ran via GitHub Actions OIDC trusted publishing including Sigstore. A preinstall hook runs a 4.2 MB obfuscated loader, harvests GitHub/AWS/GCP/Azure/Kubernetes/Vault/npm/SSH/Docker credentials, newly also collects GCP and Azure cloud identities, installs kitty-monitor persistence and a destructive gh-token-monitor dead-man switch. Operational assessment: critical. Order: isolate, remove persistence, then rotate.]]></description><pubDate>Tue, 02 Jun 2026 09:37:00 +0200</pubDate></item><item><title><![CDATA[CVE-2026-48736: SSRF bypass in Symfony's NoPrivateNetworkHttpClient — when the IPv6 transition forms aren't on the block list]]></title><link>https://ole-hartwig.eu/en/advisories/cve-2026-48736-symfony-noprivatenetworkhttpclient-ipv6-transition-ssrf</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1914</guid><description><![CDATA[Incident analysis of CVE-2026-48736: SSRF protection bypass in Symfony HTTP Client / HTTP Foundation. NoPrivateNetworkHttpClient blocks private networks via IpUtils::PRIVATE_SUBNETS, but the list omitted 6to4 (2002::/16), Teredo (2001::/32), NAT64 (64:ff9b::/96, 64:ff9b:1::/48) and IPv4-compatible (::/96). checkIp6() is a pure CIDR comparison and never extracts the embedded IPv4. Impact is deployment-dependent (IPv6/NAT64 routing). Recommendation: patch plus egress defense-in-depth. Operational rating medium, no official CVSS (NVD still RESERVED). Sister issue to CVE-2026-48489, shared patch path.]]></description><pubDate>Sun, 31 May 2026 22:44:23 +0200</pubDate></item><item><title><![CDATA[CVE-2026-48489: Symfony Firewall Bypass via failure_forward — when an internal subrequest skips the access_control line]]></title><link>https://ole-hartwig.eu/en/advisories/cve-2026-48489-symfony-firewall-bypass-failure-forward-subrequest</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1913</guid><description><![CDATA[Incident analysis of CVE-2026-48489: authorization bypass / local request forgery in Symfony Security HTTP. With a form-login firewall and failure_forward: true, the DefaultAuthenticationFailureHandler uses the client-controlled _failure_path as the target of an internal subrequest; because the firewall deliberately skips subrequests, the access_control AccessListener does not run. An unauthenticated POST with _failure_path=/admin/... reads GET routes behind a ^/admin rule — with no misconfiguration. Entry condition failure_forward: true (non-default). Fixed in 5.4.53 / 6.4.41 / 7.4.13 / 8.0.13. Operational rating high, no official CVSS (NVD still RESERVED).]]></description><pubDate>Sun, 31 May 2026 22:22:07 +0200</pubDate></item><item><title><![CDATA[BadHost (CVE-2026-48710): One line in the Host header switches auth off — Starlette, FastAPI and every MCP server below 1.0.1 are the line]]></title><link>https://ole-hartwig.eu/en/advisories/cve-2026-48710-badhost-starlette-mcp-fastapi-host-header-auth-bypass</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1861</guid><description><![CDATA[Incident analysis of the BadHost vulnerability (CVE-2026-48710): Starlette rebuilds request.url from the Host header via string concatenation, while the ASGI router reads scope['path']. A path-based auth middleware therefore sees a different path than the router decides on. MCP servers are particularly exposed because the specification enforces unauthenticated OAuth discovery endpoints. Disclosure 22 May 2026, fix in Starlette 1.0.1.]]></description><pubDate>Thu, 28 May 2026 19:18:41 +0200</pubDate></item><item><title><![CDATA[Six TYPO3 extension advisories on 19 May 2026 — two RCEs, two SQL injections, ke_search times three, one access-control gap, and what patch order the cluster demands]]></title><link>https://ole-hartwig.eu/en/advisories/typo3-ext-sa-2026-008-to-013-extension-cluster-may-2026</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1625</guid><description><![CDATA[On the evening of 19 May 2026 the TYPO3 Security Team published six extension advisories — from Critical (ceselector RCE via unserialize cookie) to High (news SQLi, crawler RCE) to Medium (tt_address, sf_register, ke_search). For anyone running a patch-pipeline-managed stack (Renovate, Dependabot or similar), the six patch releases flow automatically into the build. A technical analysis per vulnerability, including the two recurring patterns (PHP object injection and unsanitised SQL input) and the ke_search three-pack of XXE, path traversal and information disclosure.]]></description><pubDate>Sun, 24 May 2026 14:00:00 +0200</pubDate></item><item><title><![CDATA[Twin Composer Incident on 22 May 2026 — Laravel-Lang Tag Injection (Aikido) and Postinstall Wave in 8 Composer Packages + 700+ GitHub Repositories (Socket)]]></title><link>https://ole-hartwig.eu/en/advisories/laravel-lang-tag-injection-supply-chain-may-2026</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1836</guid><description><![CDATA[Two parallel Composer incidents on 22 May 2026: tag injection through GitHub fork commits (Laravel-Lang, Aikido) and postinstall hooks in package.json plus branch-tracking versions (Socket, 8 Composer packages + 700+ repos). C2 endpoints flipboxstudio.info and parikhpreyash4/systemd-network-helper-aa5c751f.]]></description><pubDate>Sat, 23 May 2026 06:28:33 +0200</pubDate></item><item><title><![CDATA[Symfony 5.4.52 / 6.4.40 / 7.4.12 / 8.0.12 — seven CVEs in a single maintenance window, from SMTP header injection in Mime\Address to the UrlGenerator route-requirement bypass]]></title><link>https://ole-hartwig.eu/en/advisories/symfony-5-4-52-6-4-40-7-4-12-8-0-12-disclosure-wave-cve-45064-45065-45066-45753-50340</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1633</guid><description><![CDATA[Analysis of the Symfony disclosure wave from 20 May 2026 with seven CVEs across the four supported lines — HtmlSanitizer trio, UrlGenerator route-requirement bypass, Mime\Address CRLF injection, X509Authenticator, SymfonyRuntime bypass. Stack mapping per component for Symfony-direct, Sylius, and TYPO3 v12.4 LTS / v13.4 LTS / v14.x. Concrete call chains: Sylius Customer Mailer, TYPO3 EXT:form email finisher, custom mailer services. Operational decision block plus a PCRE-regex-precedence explanation.]]></description><pubDate>Wed, 20 May 2026 13:40:00 +0200</pubDate></item><item><title><![CDATA[FrankenPHP 1.12.3 closes CVE-2026-45062 — when Unicode path splitting becomes an RCE path]]></title><link>https://ole-hartwig.eu/en/advisories/frankenphp-cve-2026-45062-unicode-cgi-rce-may-2026</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1436</guid><description><![CDATA[FrankenPHP 1.12.3 closes CVE-2026-45062 (GHSA-3g8v-8r37-cgjm, CVSS 8.1 high): the <code>splitPos()</code> function in <code>cgi.go</code> used <code>search.IgnoreCase</code> Unicode equivalence folding for non-ASCII path bytes. Two logic flaws allow files like <code>shell﹒php</code> or <code>shell.ｐhp</code> to be executed as PHP scripts. Wherever an attacker can place a file in the FrankenPHP web root (uploads, file storage), this becomes unauthenticated RCE. I rebuilt the TYPO3 and Sylius container images with FrankenPHP 1.12.3 and rolled them out via Renovate.]]></description><pubDate>Fri, 15 May 2026 18:00:00 +0200</pubDate></item><item><title><![CDATA[NGINX Rift CVE-2026-42945: How an 18-year-old assumption in the rewrite module rips through the reverse proxy — what 1.30.1 actually changes]]></title><link>https://ole-hartwig.eu/en/advisories/nginx-rift-cve-2026-42945-rewrite-module-may-2026</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1415</guid><description><![CDATA[CVE-2026-42945 NGINX Rift hits every nginx 0.6.27–1.30.0 and NGINX Plus R32–R36 when the configuration contains a rewrite directive with an unnamed capture, a question-mark replacement and a follow-up directive. The patch has been available since 13 May 2026; the more durable mitigation is configuration discipline on named captures.]]></description><pubDate>Fri, 15 May 2026 14:00:00 +0200</pubDate></item><item><title><![CDATA[Composer token leak in CI logs (GHSA-f9f8-rm49-7jv2): patch to 2.9.8 / 2.2.28 / 1.10.28 now]]></title><link>https://ole-hartwig.eu/en/advisories/composer-token-leak-ghsa-f9f8-rm49-7jv2-may-2026</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1165</guid><description><![CDATA[What triggers the Composer token leak vulnerability, which CI setups are critical, how to patch — and which token TTLs you must assume for self-hosted runners and GitHub Apps.]]></description><pubDate>Wed, 13 May 2026 12:00:00 +0200</pubDate></item><item><title><![CDATA[Apache HTTP/2 double-free (CVE-2026-23918) — why the mod_http2 layer in Apache 2.4.66 sat open for eight days]]></title><link>https://ole-hartwig.eu/en/advisories/apache-http2-cve-2026-23918-may-2026</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1193</guid><description><![CDATA[[Translate to English:] Apache mod_http2 Double-Free in Apache 2.4.66 (CVE-2026-23918, CVSS 8.8). DoS trivial, RCE remote auf Debian-/Ubuntu-Default mit APR-mmap-Allokator. Zwei öffentliche PoCs seit Disclosure-Woche, fix in 2.4.67. Wir prüfen, patchen und validieren TYPO3- und Sylius-Hosting-Frontlines.]]></description><pubDate>Wed, 13 May 2026 12:00:00 +0200</pubDate></item><item><title><![CDATA[When the image builder accepts the wrong letter: three flaws in apko (CVE-2026-42574 / -42575 / -42576) and what Wolfi build pipelines need today]]></title><link>https://ole-hartwig.eu/en/advisories/apko-cve-2026-42574-42575-42576-wolfi-image-build-supply-chain-may-2026</link><guid isPermaLink="false">https://ole-hartwig.eu/page-1067</guid><description><![CDATA[Three vulnerabilities in apko, disclosed on 9 May 2026, push the boundaries of trust in the Wolfi/Chainguard build pipeline: path traversal, a missing hash comparison against the signed index, and a type-assert panic. Patch directly to 1.2.7, plus a dedicated SBOM verification stage as a structural response.]]></description><pubDate>Mon, 11 May 2026 22:26:06 +0200</pubDate></item><item><title><![CDATA[Broadly executable MCP servers: what the Anthropic SDK chain means for AI agents in the mid-market]]></title><link>https://ole-hartwig.eu/en/advisories/mcp-stdio-rce-anthropic-sdk-may-2026</link><guid isPermaLink="false">https://ole-hartwig.eu/page-874</guid><description><![CDATA[[Translate to English:] Der STDIO-Transport im MCP-SDK ruft jedes Kommando direkt als Subprozess auf. ~200.000 erreichbare Server, 7.000+ Pakete, 150 Mio. Downloads. Anthropic patcht das nicht. Verantwortung bleibt bei den Implementierern.]]></description><pubDate>Thu, 07 May 2026 22:03:26 +0200</pubDate></item><item><title><![CDATA[When a composer install becomes code execution: CVE-2026-40176 and CVE-2026-40261 in the Composer supply chain]]></title><link>https://ole-hartwig.eu/en/advisories/composer-cve-2026-supply-chain</link><guid isPermaLink="false">https://ole-hartwig.eu/page-863</guid><description><![CDATA[CVE-2026-40176 and CVE-2026-40261 affect Composer in all versions before 2.9.6 / 2.2.27 LTS. What follows for your build pipeline — without panic, with clear steps.]]></description><pubDate>Thu, 07 May 2026 10:03:57 +0200</pubDate></item><item><title><![CDATA[When the CMS writes backend passwords in plain text: TYPO3 14.2 and CVE-2026-6553]]></title><link>https://ole-hartwig.eu/en/advisories/typo3-cve-2026-6553-cleartext-passwords</link><guid isPermaLink="false">https://ole-hartwig.eu/page-862</guid><description><![CDATA[CVE-2026-6553 affects TYPO3 14.2.0. Patch 14.3.0 closes the vulnerability but does not remove the plain-text data already stored. What mid-market companies running TYPO3 in production should do now.]]></description><pubDate>Thu, 07 May 2026 10:00:43 +0200</pubDate></item></channel></rss>
