<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:43:56.181201+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:4212</id>
    <title>ALSA-2024:4212 — Moderate: golang security update</title>
    <updated>2026-10-04T09:43:56.333131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests</p>
<p>The golang packages provide the Go programming language compiler.</p>
<p>Security Fix(es):</p>
<p>* golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789)
* golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses (CVE-2024-24790)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:4212"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04485</id>
    <title>bdu:2024-04485</title>
    <updated>2026-10-04T09:43:56.333225+00:00</updated>
    <content>bdu:2024-04485</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04485"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-24789</id>
    <title>BELL-CVE-2024-24789</title>
    <updated>2026-10-04T09:43:56.333242+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-24789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2024-24789</id>
    <title>BIT-golang-2024-24789 — Mishandling of corrupt central directory record in archive/zip</title>
    <updated>2026-10-04T09:43:56.333266+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2024-24789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0873</id>
    <title>certfr-2024-avi-0873 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T09:43:56.333288+00:00</updated>
    <content>certfr-2024-avi-0873</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0873"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-217245</id>
    <title>EUVD-2026-217245</title>
    <updated>2026-10-04T09:43:56.333304+00:00</updated>
    <content>EUVD-2026-217245</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-217245"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-24789</id>
    <title>fkie_cve-2024-24789</title>
    <updated>2026-10-04T09:43:56.333315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-24789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-236w-p7wf-5ph8</id>
    <title>GHSA-236w-p7wf-5ph8</title>
    <updated>2026-10-04T09:43:56.333338+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-236w-p7wf-5ph8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-24789</id>
    <title>gsd-2024-24789</title>
    <updated>2026-10-04T09:43:56.333353+00:00</updated>
    <content>gsd-2024-24789</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-24789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-24789</id>
    <title>msrc_CVE-2024-24789 — Mishandling of corrupt central directory record in archive/zip</title>
    <updated>2026-10-04T09:43:56.333363+00:00</updated>
    <content>msrc_CVE-2024-24789</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-24789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1769</id>
    <title>OESA-2024-1769 — golang security update</title>
    <updated>2026-10-04T09:43:56.333378+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: golang</p>
<p>The Go Programming Language.

Security Fix(es):

The archive/zip package&amp;apos;s handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.(CVE-2024-24789)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1769"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14020-1</id>
    <title>openSUSE-SU-2024:14020-1 — go1.22-1.22.4-1.1 on GA media</title>
    <updated>2026-10-04T09:43:56.333400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.22-1.22.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14020-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhea-2025:0507</id>
    <title>RHEA-2025:0507 — Red Hat Enhancement Advisory: Advisory for publishing Helm 3.15.4 GA release</title>
    <updated>2026-10-04T09:43:56.333417+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net: malformed DNS message can cause infinite loop golang: archive/zip: Incorrect handling of certain ZIP files golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhea-2025:0507"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1935-1</id>
    <title>SUSE-SU-2024:1935-1 — Security update for go1.22</title>
    <updated>2026-10-04T09:43:56.333437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.22</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1935-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24789</id>
    <title>UBUNTU-CVE-2024-24789</title>
    <updated>2026-10-04T09:43:56.333451+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: golang-1.10, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.21 and 13 more</p>
<p>The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1287</id>
    <title>WID-SEC-W-2024-1287 — Golang Go: Mehrere Schwachstellen</title>
    <updated>2026-10-04T09:43:56.333497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1287"/>
  </entry>
</feed>
