<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:17:21.637371+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06184</id>
    <title>bdu:2025-06184</title>
    <updated>2026-10-03T02:17:21.694428+00:00</updated>
    <content>bdu:2025-06184</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-vault-2022-41316</id>
    <title>BIT-vault-2022-41316</title>
    <updated>2026-10-03T02:17:21.694473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: vault</p>
<p>HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-vault-2022-41316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-239504</id>
    <title>EUVD-2026-239504</title>
    <updated>2026-10-03T02:17:21.694511+00:00</updated>
    <content>EUVD-2026-239504</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-239504"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41316</id>
    <title>fkie_cve-2022-41316</title>
    <updated>2026-10-03T02:17:21.694525+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-41316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9mh8-9j64-443f</id>
    <title>GHSA-9mh8-9j64-443f — HashiCorp Vault's revocation list not respected</title>
    <updated>2026-10-03T02:17:21.694549+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/hashicorp/vault</p>
<p>HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9mh8-9j64-443f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-41316</id>
    <title>gsd-2022-41316</title>
    <updated>2026-10-03T02:17:21.694574+00:00</updated>
    <content>gsd-2022-41316</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-41316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7399</id>
    <title>RHSA-2022:7399 — Red Hat Security Advisory: OpenShift Container Platform 4.12.0 bug fix and security update</title>
    <updated>2026-10-03T02:17:21.694585+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: out-of-bounds read in golang.org/x/text/language leads to DoS golang: net/http: improper sanitization of Transfer-Encoding header golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters prometheus/client_golang: Denial of service using InstrumentHandlerCounter golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working golang: net/url: JoinPath does not strip relative path components in all circumstances vault: insufficient certificate revocation list checking golang: regexp/syntax: limit memory used by parsing regexps openshift: etcd grpc-proxy vulnerable to The Birthday attack against 64-bit block cipher</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7399"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1542</id>
    <title>WID-SEC-W-2023-1542 — Red Hat OpenShift: Mehrere Schwachstellen</title>
    <updated>2026-10-03T02:17:21.694620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Zustand herbeizuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1542"/>
  </entry>
</feed>
