<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent vulnerabilities from the redhat CNA root</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Latest vulnerabilities published by the CNAs operating under the redhat root of the CVE Program.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:15 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-86345 (redhat)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-86345</link>
      <description>389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result</description>
      <content:encoded>389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-86345</guid>
      <pubDate>Thu, 01 Oct 2026 23:27:47 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-86344 (redhat)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-86344</link>
      <description>389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue</description>
      <content:encoded>389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-86344</guid>
      <pubDate>Thu, 01 Oct 2026 21:29:55 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103484 (PostgreSQL)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-103484</link>
      <description>pgvector buffer overflow in IVFFlat index build</description>
      <content:encoded>pgvector buffer overflow in IVFFlat index build</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-103484</guid>
      <pubDate>Thu, 01 Oct 2026 19:49:03 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103884 (redhat)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-103884</link>
      <description>Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read</description>
      <content:encoded>Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-103884</guid>
      <pubDate>Thu, 01 Oct 2026 17:16:21 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-56098 (redhat)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-56098</link>
      <description>Rubygem-katello: improper authorization logic allows resource enumeration</description>
      <content:encoded>Rubygem-katello: improper authorization logic allows resource enumeration</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-56098</guid>
      <pubDate>Thu, 01 Oct 2026 17:14:56 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-56097 (redhat)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-56097</link>
      <description>Rubygem-katello: sql injection in registry proxy via labels</description>
      <content:encoded>Rubygem-katello: sql injection in registry proxy via labels</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-56097</guid>
      <pubDate>Thu, 01 Oct 2026 17:14:50 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-12542 (redhat)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-12542</link>
      <description>Foreman: command injection in foreman-tail</description>
      <content:encoded>Foreman: command injection in foreman-tail</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-12542</guid>
      <pubDate>Thu, 01 Oct 2026 17:14:49 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-12545 (redhat)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-12545</link>
      <description>Rubygem-hammer_cli: command injection via insecure editor invocation</description>
      <content:encoded>Rubygem-hammer_cli: command injection via insecure editor invocation</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-12545</guid>
      <pubDate>Thu, 01 Oct 2026 17:14:49 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-96658 (redhat)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-96658</link>
      <description>Foreman: safemode bypass leading to rce</description>
      <content:encoded>Foreman: safemode bypass leading to rce</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-96658</guid>
      <pubDate>Thu, 01 Oct 2026 16:23:23 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-96659 (redhat)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-96659</link>
      <description>Foreman: excessive permissions for viewer role on preview</description>
      <content:encoded>Foreman: excessive permissions for viewer role on preview</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-96659</guid>
      <pubDate>Thu, 01 Oct 2026 16:23:23 +0000</pubDate>
    </item>
  </channel>
</rss>
