<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:20:28.945134+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0063</id>
    <title>certfr-2023-avi-0063 — Une vulnérabilité a été découverte dans Grafana. Elle permet à un
attaquant de provoquer une élévation de privilèges.</title>
    <updated>2026-10-03T06:20:29.112510+00:00</updated>
    <content>certfr-2023-avi-0063</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-233386</id>
    <title>EUVD-2026-233386</title>
    <updated>2026-10-03T06:20:29.112559+00:00</updated>
    <content>EUVD-2026-233386</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-233386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41912</id>
    <title>fkie_cve-2022-41912</title>
    <updated>2026-10-03T06:20:29.112578+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-41912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j2jp-wvqg-wc2g</id>
    <title>GHSA-j2jp-wvqg-wc2g — crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication</title>
    <updated>2026-10-03T06:20:29.112608+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/crewjam/saml</p>
<p>### Impact</p>
<p>The crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements.</p>
<p>### Patches</p>
<p>This issue has been corrected in version 0.4.9.</p>
<p>### Credit</p>
<p>This issue was reported by Felix Wilhelm from Google Project Zero.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j2jp-wvqg-wc2g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-41912</id>
    <title>gsd-2022-41912</title>
    <updated>2026-10-03T06:20:29.112638+00:00</updated>
    <content>gsd-2022-41912</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-41912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:9040</id>
    <title>RHSA-2022:9040 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.6.3 security update</title>
    <updated>2026-10-03T06:20:29.112651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-minimatch: ReDoS via the braceExpand function crewjam/saml: Authentication bypass when processing SAML responses containing multiple Assertion elements</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:9040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41912</id>
    <title>UBUNTU-CVE-2022-41912</title>
    <updated>2026-10-03T06:20:29.112670+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: golang-github-crewjam-saml</p>
<p>The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2338</id>
    <title>WID-SEC-W-2022-2338 — Red Hat Enterprise Linux (Advanced Cluster Management): Mehrere Schwachstellen</title>
    <updated>2026-10-03T06:20:29.112689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux Advanced Cluster Management ausnutzen, um einen Denial of Service Angriff durchzuführen oder die Authentisierung zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2338"/>
  </entry>
</feed>
