<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T07:10:01.504890+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2025-19</id>
    <title>PYSEC-2025-19</title>
    <updated>2026-10-02T07:10:01.509324+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: picklescan</p>
<p>picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file extension. Because the malicious pickle file inclusion is not considered as part of the scope of picklescan, the file would pass security checks and appear to be safe, when it could instead prove to be problematic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2025-19"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2024-115</id>
    <title>PYSEC-2024-115</title>
    <updated>2026-10-02T07:10:01.509405+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: langchain-community</p>
<p>A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain-community version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2024-115"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:71658</id>
    <title>RLSA-2026:71658 — Important: python-cryptography security update</title>
    <updated>2026-10-02T07:10:01.509444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: python-cryptography</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* python-cryptography: python-cryptography: Duplicate self-signed intermediates can cause exponential path-building (CVE-2026-69249)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:71658"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:73998</id>
    <title>RLSA-2026:73998 — Important: gvfs security update</title>
    <updated>2026-10-02T07:10:01.509500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: gvfs</p>
<p>GVFS is the GNOME Desktop Virtual File System layer that allows users to easily access local and remote data using File Transfer Protocol (FTP), Secure Shell File Transfer Protocol (SFTP), Web Distributed Authoring and Versioning (WebDAV), Common Internet File System (CIFS), Server Message Block (SMB), and other protocols. GVFS integrates with the GNOME I/O (GIO) abstraction layer.</p>
<p>Security Fix(es):</p>
<p>* gvfs: SFTP: heap-based buffer overflow in read_reply() (CVE-2026-84268)</p>
<p>* gvfs: gvfs-admin socket ownership race permits local root (CVE-2026-88924)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:73998"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:74001</id>
    <title>RLSA-2026:74001 — Important: expat security update</title>
    <updated>2026-10-02T07:10:01.509543+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: expat</p>
<p>Expat is a C library for parsing XML documents.</p>
<p>Security Fix(es):</p>
<p>* expat: Expat: Denial of Service via quadratic complexity in attribute processing (CVE-2026-66046)</p>
<p>* expat: Expat: XML Injection via Malformed UTF-16 Input (CVE-2026-93990)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:74001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:73954</id>
    <title>RLSA-2026:73954 — Moderate: openssh security update</title>
    <updated>2026-10-02T07:10:01.509581+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: openssh</p>
<p>OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.</p>
<p>Security Fix(es):</p>
<p>* openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay (CVE-2026-60001)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:73954"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:73765</id>
    <title>RLSA-2026:73765 — Important: dogtag-pki security update</title>
    <updated>2026-10-02T07:10:01.509617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: dogtag-pki</p>
<p>IdM PKI is an enterprise software system designed to manage enterprise Public Key Infrastructure deployments.  IdM PKI consists of the following components: 
  * Certificate Authority (CA)
  * Key Recovery Authority (KRA)
  * Online Certificate Status Protocol (OCSP) Manager
  * Token Key Service (TKS)
  * Token Processing Service (TPS)
  * Automatic Certificate Management Environment (ACME) Responder
  * Enrollment over Secure Transport (EST) Responder</p>
<p>Security Fix(es):</p>
<p>* pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint) (CVE-2026-76561)</p>
<p>* pki-core: Dogtag PKI v2 REST ACL filter's reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint (CVE-2026-80110)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:73765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:73429</id>
    <title>RLSA-2026:73429 — Moderate: gawk security update</title>
    <updated>2026-10-02T07:10:01.509662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: gawk</p>
<p>The gawk packages contain the GNU version of awk, a text processing utility. Awk interprets a special-purpose programming language to do quick and easy text pattern matching and reformatting jobs.</p>
<p>Security Fix(es):</p>
<p>* gawk: gawk: Memory corruption via integer overflow (CVE-2026-40468)</p>
<p>* gawk: Gawk: Buffer overflow in ftype() routine may lead to code execution or denial of service (CVE-2026-40553)</p>
<p>* gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c (CVE-2026-40467)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:73429"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:73428</id>
    <title>RLSA-2026:73428 — Important: nodejs24 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T07:10:01.509702+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: nodejs24</p>
<p>Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.</p>
<p>Security Fix(es):</p>
<p>* undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152)</p>
<p>* undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961)</p>
<p>* undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* nodejs24: Rebase to the latest Node.js 24 release [rhel-10] (JIRA:Rocky Linux-249187)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:73428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:73427</id>
    <title>RLSA-2026:73427 — Important: gdb security update</title>
    <updated>2026-10-02T07:10:01.509750+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: gdb</p>
<p>The GNU Debugger (GDB) allows debugging of programs written in C, C++, and
other languages by executing them in a controlled fashion and printing their
data.</p>
<p>Security Fix(es):</p>
<p>* gdb: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF (CVE-2026-13732)</p>
<p>For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:73427"/>
  </entry>
</feed>
