<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T02:22:25.507908+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-01638</id>
    <title>bdu:2019-01638</title>
    <updated>2026-10-04T02:22:25.514219+00:00</updated>
    <content>bdu:2019-01638</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-01638"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-09043</id>
    <title>cnvd-2019-09043</title>
    <updated>2026-10-04T02:22:25.514263+00:00</updated>
    <content>cnvd-2019-09043</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-09043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-65637</id>
    <title>EUVD-2026-65637</title>
    <updated>2026-10-04T02:22:25.514285+00:00</updated>
    <content>EUVD-2026-65637</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-65637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-12029</id>
    <title>fkie_cve-2018-12029</title>
    <updated>2026-10-04T02:22:25.514304+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-12029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jjcj-fgfm-9g9r</id>
    <title>GHSA-jjcj-fgfm-9g9r — Phusion Passenger Race Condition Allows Privilege Escalation</title>
    <updated>2026-10-04T02:22:25.514361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: passenger</p>
<p>A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jjcj-fgfm-9g9r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-12029</id>
    <title>gsd-2018-12029</title>
    <updated>2026-10-04T02:22:25.514455+00:00</updated>
    <content>gsd-2018-12029</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-12029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11341-1</id>
    <title>openSUSE-SU-2024:11341-1 — ruby2.7-rubygem-passenger-6.0.8-3.2 on GA media</title>
    <updated>2026-10-04T02:22:25.514484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby2.7-rubygem-passenger-6.0.8-3.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11341-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:2039-1</id>
    <title>SUSE-SU-2018:2039-1 — Security update for rubygem-passenger</title>
    <updated>2026-10-04T02:22:25.514510+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-passenger</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:2039-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-12029</id>
    <title>UBUNTU-CVE-2018-12029</title>
    <updated>2026-10-04T02:22:25.514526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: passenger, Ubuntu:18.04:LTS: passenger</p>
<p>A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-12029"/>
  </entry>
</feed>
