Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/tandoorrecipes/recipes

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import functionality. This vulnerability allows an authenticated user to crash the server or make a significantly degrade its performance by uploading a large size ZIP file (ZIP Bomb). This vulnerability is fixed in 2.6.5.

Join the discussion

CVE-2026-35489 is a high-severity vulnerability in Tandoor Recipes versions prior to 2.6.4. It involves the POST /api/food/{id}/shopping/ endpoint improperly handling user-supplied amount and unit data without validation. This can cause unhandled exceptions resulting in HTTP 500 errors and allows cross-space association of unit IDs, leading to potential leakage of foreign-key references across tenant boundaries. The issue is fixed in version 2.6.4.

Join the discussion

CVE-2026-35046 is a cross-site scripting (XSS) vulnerability in Tandoor Recipes versions prior to 2.6.4. Authenticated users can inject arbitrary <style> tags into recipe step instructions because the sanitizer used (bleach.clean()) explicitly allows the <style> tag. This results in unsanitized CSS being stored and served via the API. Clients that render these instructions as HTML without further sanitization may execute attacker-controlled CSS, potentially enabling UI redressing, phishing overlays, visual defacement, and CSS-based data exfiltration. The vulnerability is fixed in version 2.6.4.

Join the discussion

CVE-2026-35045 is an authorization bypass vulnerability in Tandoor Recipes versions prior to 2.6.4. It affects the batch update API endpoint, allowing any authenticated user within a Space to modify any recipe in that Space, including private recipes owned by other users. This bypasses object-level authorization checks present in single-recipe endpoints, enabling unauthorized access and modification of private recipe data. The vulnerability is fixed in version 2.6.4.

Join the discussion

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework with BasicAuthentication as one of the default authentication backends. The AllAuth rate limiting configuration (ACCOUNT_RATE_LIMITS: login: 5/m/ip) only applies to the HTML-based login endpoint at /accounts/login/. Any API endpoint that accepts authenticated requests can be targeted via Authorization: Basic headers with zero rate limiting, zero account lockout, and unlimited attempts. An attacker can perform high-speed password guessing against any known username. Version 2.6.0 patches the issue.

Join the discussion

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the FDC (USDA FoodData Central) search endpoint constructs an upstream API URL by directly interpolating the user-supplied `query` parameter into the URL string without URL-encoding. An attacker can inject additional URL parameters by including `&` characters in the query value. This allows overriding the API key, manipulating upstream query behavior, and causing server crashes (HTTP 500) via malformed requests — a Denial of Service condition. Version 2.6.0 patches the issue.

Join the discussion

Tandoor Recipes versions prior to 2.6.0 do not strip EXIF metadata from uploaded WebP and GIF images. This leads to exposure of sensitive information such as GPS coordinates, camera model, timestamps, and software details to any user who can view the recipe images. The issue is fixed in version 2.6.0.

Join the discussion

CVE-2026-28503 is an authorization bypass vulnerability in Tandoor Recipes versions prior to 2.6.0. The flaw exists in the SyncViewSet.query_synced_folder() function, which fetches Sync objects without properly restricting access by space. This allows an admin user in one space to trigger sync operations and view sync logs belonging to another space. The issue is fixed in version 2.6.0.

Join the discussion

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which causes Django to accept any value in the HTTP Host header without validation. The application uses request.build_absolute_uri() to generate absolute URLs in multiple contexts, including invite link emails, API pagination, and OpenAPI schema generation. An attacker who can send requests to the application with a crafted Host header can manipulate all server-generated absolute URLs. The most critical impact is invite link poisoning: when an admin creates an invite and the application sends the invite email, the link points to the attacker's server instead of the real application. When the victim clicks the link, the invite token is sent to the attacker, who can then use it at the real application. As of time of publication, it is unknown if a patched version is available.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/tandoorrecipes/recipes
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses