<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T04:43:06.751946+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00281</id>
    <title>bdu:2022-00281</title>
    <updated>2026-10-05T04:43:07.071922+00:00</updated>
    <content>bdu:2022-00281</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00281"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-14365</id>
    <title>BREW-ansible-CVE-2020-14365</title>
    <updated>2026-10-05T04:43:07.071977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-14365"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42400</id>
    <title>EUVD-2026-42400</title>
    <updated>2026-10-05T04:43:07.072032+00:00</updated>
    <content>EUVD-2026-42400</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42400"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-14365</id>
    <title>fkie_cve-2020-14365</title>
    <updated>2026-10-05T04:43:07.072047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-14365"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m429-fhmv-c6q2</id>
    <title>GHSA-m429-fhmv-c6q2 — Improper Verification of Cryptographic Signature in ansible</title>
    <updated>2026-10-05T04:43:07.072072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ansible</p>
<p>A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when `disable_gpg_check` is set to `False`, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m429-fhmv-c6q2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-14365</id>
    <title>gsd-2020-14365</title>
    <updated>2026-10-05T04:43:07.072097+00:00</updated>
    <content>gsd-2020-14365</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-14365"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2020-209</id>
    <title>PYSEC-2020-209</title>
    <updated>2026-10-05T04:43:07.072109+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: ansible</p>
<p>A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2020-209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:3600</id>
    <title>RHSA-2020:3600 — Red Hat Security Advisory: Ansible security and bug fix update (2.8.15)</title>
    <updated>2026-10-05T04:43:07.072129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ansible: atomic_move primitive sets permissive permissions Ansible: masked keys for uri module are exposed into content and json output Ansible: module_args does not censor properly in --check mode ansible: dnf module install packages with no GPG signature</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:3600"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1427-1</id>
    <title>SUSE-SU-2024:1427-1 — Security Beta update for SUSE Manager Client Tools and Salt</title>
    <updated>2026-10-05T04:43:07.072173+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security Beta update for SUSE Manager Client Tools and Salt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1427-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-14365</id>
    <title>UBUNTU-CVE-2020-14365</title>
    <updated>2026-10-05T04:43:07.072217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: ansible, Ubuntu:Pro:16.04:LTS: ansible, Ubuntu:Pro:18.04:LTS: ansible, Ubuntu:Pro:20.04:LTS: ansible, Ubuntu:Pro:22.04:LTS: ansible, Ubuntu:24.04:LTS: ansible, Ubuntu:25.10: ansible, Ubuntu:26.04:LTS: ansible</p>
<p>A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-14365"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2469</id>
    <title>WID-SEC-W-2023-2469 — Ansible: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-05T04:43:07.072279+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Ansible und Ansible Tower ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2469"/>
  </entry>
</feed>
