<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:54:24.121727+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07201</id>
    <title>bdu:2023-07201</title>
    <updated>2026-10-02T15:54:24.143231+00:00</updated>
    <content>bdu:2023-07201</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07201"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-39323</id>
    <title>BELL-CVE-2023-39323</title>
    <updated>2026-10-02T15:54:24.143314+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-39323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2023-39323</id>
    <title>BIT-golang-2023-39323 — Arbitrary code execution during build via line directives in cmd/go</title>
    <updated>2026-10-02T15:54:24.143346+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2023-39323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0061</id>
    <title>certfr-2024-avi-0061 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Splunk&lt;/span&gt;. Certaines d'entre…</title>
    <updated>2026-10-02T15:54:24.143372+00:00</updated>
    <content>certfr-2024-avi-0061</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0061"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-244183</id>
    <title>EUVD-2026-244183</title>
    <updated>2026-10-02T15:54:24.143388+00:00</updated>
    <content>EUVD-2026-244183</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-244183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-39323</id>
    <title>fkie_cve-2023-39323</title>
    <updated>2026-10-02T15:54:24.143399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-39323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-679v-hh23-h5jh</id>
    <title>GHSA-679v-hh23-h5jh</title>
    <updated>2026-10-02T15:54:24.143421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-679v-hh23-h5jh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-39323</id>
    <title>gsd-2023-39323</title>
    <updated>2026-10-02T15:54:24.143436+00:00</updated>
    <content>gsd-2023-39323</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-39323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-39323</id>
    <title>msrc_CVE-2023-39323 — Arbitrary code execution during build via line directives in cmd/go</title>
    <updated>2026-10-02T15:54:24.143446+00:00</updated>
    <content>msrc_CVE-2023-39323</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-39323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1789</id>
    <title>OESA-2023-1789 — golang security update</title>
    <updated>2026-10-02T15:54:24.143460+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: golang, openEuler:20.03-LTS-SP3: golang, openEuler:22.03-LTS: golang, openEuler:22.03-LTS-SP1: golang, openEuler:22.03-LTS-SP2: golang</p>
<p>.

Security Fix(es):

The html/template package does not properly handle HTML-like &amp;quot;&amp;quot; comment tokens, nor hashbang &amp;quot;#!&amp;quot; comment tokens, in &amp;lt;script&amp;gt; contexts. This may cause the template parser to improperly interpret the contents of &amp;lt;script&amp;gt; contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack.(CVE-2023-39318)

The html/template package does not apply the proper rules for handling occurrences of &amp;quot;&amp;lt;script&amp;quot;, &amp;quot;&amp;lt;!--&amp;quot;, and &amp;quot;&amp;lt;/script&amp;quot; within JS literals in &amp;lt;script&amp;gt; contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack.(CVE-2023-39319)

Line directives (&amp;quot;//line&amp;quot;) can be used to bypass the restrictions on &amp;quot;//go:cgo_&amp;quot; directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running &amp;quot;go build&amp;quot;. The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.(CVE-2023-39323)

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resett…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2023:0360-1</id>
    <title>openSUSE-SU-2023:0360-1 — Security update for go1.21</title>
    <updated>2026-10-02T15:54:24.143503+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.21</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2023:0360-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhea-2023:7311</id>
    <title>RHEA-2023:7311 — Red Hat Enhancement Advisory: go-toolset-container bug fix and enhancement update</title>
    <updated>2026-10-02T15:54:24.143523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: cmd/go: line directives allows arbitrary execution during build</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhea-2023:7311"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-39323</id>
    <title>UBUNTU-CVE-2023-39323</title>
    <updated>2026-10-02T15:54:24.143538+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.20, Ubuntu:20.04:LTS: golang-1.21, Ubuntu:22.04:LTS: golang-1.17, Ubuntu:22.04:LTS: golang-1.18, Ubuntu:22.04:LTS: golang-1.20, Ubuntu:22.04:LTS: golang-1.21</p>
<p>Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-39323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2516</id>
    <title>WID-SEC-W-2023-2516 — Golang Go: Mehre Schwachstellen</title>
    <updated>2026-10-02T15:54:24.143567+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein  Angreifer kann eine Schwachstelle in Golang Go ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2516"/>
  </entry>
</feed>
