<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:27:53.639444+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:3318</id>
    <title>ALSA-2023:3318 — Important: go-toolset and golang security update</title>
    <updated>2026-10-03T14:27:54.485708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-race, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests</p>
<p>Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.</p>
<p>The golang packages provide the Go programming language compiler.</p>
<p>Security Fix(es):</p>
<p>* golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:3318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03471</id>
    <title>bdu:2023-03471</title>
    <updated>2026-10-03T14:27:54.485819+00:00</updated>
    <content>bdu:2023-03471</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-24540</id>
    <title>Withdrawn: BELL-CVE-2023-24540 — CVE-2023-24540 does not affect BellSoft software</title>
    <updated>2026-10-03T14:27:54.485838+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-24540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2023-24540</id>
    <title>BIT-golang-2023-24540 — Improper handling of JavaScript whitespace in html/template</title>
    <updated>2026-10-03T14:27:54.485855+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2023-24540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0500</id>
    <title>certfr-2023-avi-0500 — De multiples vulnérabilités ont été découvertes dans MongoDB. Elles
permettent à un attaquant de provoquer une exécutio…</title>
    <updated>2026-10-03T14:27:54.485878+00:00</updated>
    <content>certfr-2023-avi-0500</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-211748</id>
    <title>EUVD-2026-211748</title>
    <updated>2026-10-03T14:27:54.485894+00:00</updated>
    <content>EUVD-2026-211748</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-211748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-24540</id>
    <title>fkie_cve-2023-24540</title>
    <updated>2026-10-03T14:27:54.485905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-24540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7qhm-5mxq-x7vp</id>
    <title>GHSA-7qhm-5mxq-x7vp</title>
    <updated>2026-10-03T14:27:54.485927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7qhm-5mxq-x7vp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-24540</id>
    <title>gsd-2023-24540</title>
    <updated>2026-10-03T14:27:54.485943+00:00</updated>
    <content>gsd-2023-24540</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-24540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-24540</id>
    <title>msrc_CVE-2023-24540 — Improper handling of JavaScript whitespace in html/template</title>
    <updated>2026-10-03T14:27:54.485953+00:00</updated>
    <content>msrc_CVE-2023-24540</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-24540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1294</id>
    <title>OESA-2023-1294 — golang security update</title>
    <updated>2026-10-03T14:27:54.485970+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: golang, openEuler:20.03-LTS-SP3: golang, openEuler:22.03-LTS: golang, openEuler:22.03-LTS-SP1: golang</p>
<p>The Go Programming Language.

Security Fix(es):

Templates containing actions in unquoted HTML attributes (e.g. &amp;quot;attr={{.}}&amp;quot;) executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.(CVE-2023-29400)

Angle brackets (&amp;lt;&amp;gt;) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a &amp;apos;/&amp;apos; character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.(CVE-2023-24539)

Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set &amp;quot;\t\n\f\r\u0020\u2028\u2029&amp;quot; in JavaScript contexts that also contain actions may not be properly sanitized during execution.(CVE-2023-24540)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1294"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12907-1</id>
    <title>openSUSE-SU-2024:12907-1 — go1.19-1.19.9-1.1 on GA media</title>
    <updated>2026-10-03T14:27:54.486002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.19-1.19.9-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12907-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2023:4275</id>
    <title>RHBA-2023:4275 — Red Hat Bug Fix Advisory: Red Hat Quay v3.8.11 bug fix release</title>
    <updated>2026-10-03T14:27:54.486020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/http: handle server errors after sending GOAWAY golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags golang: net/url: JoinPath does not strip relative path components in all circumstances golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values golang: html/template: improper handling of JavaScript whitespace golang: html/template: improper handling of empty HTML attributes</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2023:4275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:2105-2</id>
    <title>SUSE-SU-2023:2105-2 — Security update for go1.20</title>
    <updated>2026-10-03T14:27:54.486061+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.20</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:2105-2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-24540</id>
    <title>Withdrawn: UBUNTU-CVE-2023-24540</title>
    <updated>2026-10-03T14:27:54.486081+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:20.04:LTS: golang-1.20, Ubuntu:22.04:LTS: golang-1.20</p>
<p>Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-24540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-062</id>
    <title>VDE-2023-062 — Phoenix Contact: WIBU-SYSTEMS CodeMeter Runtime vulnerabilities in multiple products</title>
    <updated>2026-10-03T14:27:54.486103+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A heap-based buffer overflow caused by libcurl and wrong whitespace character interpretationin Javascript, both used in CodeMeter Runtime affecting multiple products by PHOENIX CONTACT.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-001</id>
    <title>VDE-2024-001 — TRUMPF: Multiple products contain WIBU CodeMeter vulnerabilities</title>
    <updated>2026-10-03T14:27:54.486120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60d) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes these vulnerabilities is available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-007</id>
    <title>VDE-2024-007 — WAGO: WIBU-SYSTEMS CodeMeter Runtime vulnerabilities in multiple products</title>
    <updated>2026-10-03T14:27:54.486139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A heap-based buffer overflow caused by libcurl and wrong whitespace character interpretation in Javascript, both used in CodeMeter Runtime affecting multiple products by WAGO. WIBU-SYSTEMS Codemeter is installed by default during e!COCKPIT and WAGO-I/O-Pro (CODESYS 2.3) installations.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1167</id>
    <title>WID-SEC-W-2023-1167 — Gitea: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T14:27:54.486155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1167"/>
  </entry>
</feed>
