<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T03:10:37.884029+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-173008</id>
    <title>EUVD-2026-173008</title>
    <updated>2026-10-10T03:10:37.887839+00:00</updated>
    <content>EUVD-2026-173008</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-173008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21951</id>
    <title>fkie_cve-2022-21951</title>
    <updated>2026-10-10T03:10:37.887870+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network to read and change network data due to missing encryption of data transmitted via the network when a cluster is created from an RKE template with the CNI value overridden This issue affects: SUSE Rancher Rancher versions prior to 2.5.14; Rancher versions prior to 2.6.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-21951"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vrph-m5jj-c46c</id>
    <title>GHSA-vrph-m5jj-c46c — Rancher's weave CNI password is not configured when a cluster is created from an RKE template</title>
    <updated>2026-10-10T03:10:37.887901+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/rancher/rancher</p>
<p>### Impact</p>
<p>This vulnerability only affects customers using [Weave](https://rancher.com/docs/rancher/v2.6/en/faq/networking/cni-providers/#weave) CNI (Container Network Interface) when configured through [RKE templates](https://rancher.com/docs/rancher/v2.6/en/admin-settings/rke-templates/).</p>
<p>A flaw was discovered in Rancher versions from 2.5.0 up to and including 2.5.13 and from 2.6.0 up to and including 2.6.4, where a UI (user interface) issue with RKE templates does not include a value for the Weave password when Weave is chosen as the CNI.</p>
<p>If a cluster is created based on the mentioned template and Weave is configured as the CNI, no password will be created for [network encryption](https://www.weave.works/docs/net/latest/tasks/manage/security-untrusted-networks/) in Weave, therefore network traffic in the cluster will be sent unencrypted.</p>
<p>This issue does not happen when a cluster, with Weave configured as CNI, is created without using an RKE template.</p>
<p>The impact of this vulnerability is higher when nodes on the cluster are on different locations and communicate with one another through the Internet, where monitoring (sniffing) of the network traffic by third-party entities can be more easily achieved.</p>
<p>### Patches</p>
<p>Patched versions include releases 2.5.14, 2.6.5 and later versions of Rancher. Besides upgrading to a Rancher patched version, the workarounds listed below must be applied in order for Weave to properly encrypt the network traffic.</p>
<p>### Workarounds</p>
<p>1. A ma…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vrph-m5jj-c46c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-21951</id>
    <title>gsd-2022-21951</title>
    <updated>2026-10-10T03:10:37.887951+00:00</updated>
    <content>gsd-2022-21951</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-21951"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0258</id>
    <title>WID-SEC-W-2022-0258 — Rancher: Schwachstelle ermöglicht Manipulation von Daten</title>
    <updated>2026-10-10T03:10:37.887964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann eine Schwachstelle in Rancher ausnutzen, um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0258"/>
  </entry>
</feed>
