<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T12:35:11.655131+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04279</id>
    <title>bdu:2024-04279</title>
    <updated>2026-10-07T12:35:11.880813+00:00</updated>
    <content>bdu:2024-04279</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-225123</id>
    <title>EUVD-2026-225123</title>
    <updated>2026-10-07T12:35:11.880853+00:00</updated>
    <content>EUVD-2026-225123</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-225123"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-29156</id>
    <title>fkie_cve-2024-29156</title>
    <updated>2026-10-07T12:35:11.880867+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-29156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mvf6-hwxh-7v76</id>
    <title>GHSA-mvf6-hwxh-7v76 — Information leakage in YAQL</title>
    <updated>2026-10-07T12:35:11.880898+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: yaql</p>
<p>YAQL before 3.0.0 is used in Murano, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mvf6-hwxh-7v76"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-29156</id>
    <title>gsd-2024-29156</title>
    <updated>2026-10-07T12:35:11.880931+00:00</updated>
    <content>gsd-2024-29156</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-29156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1328</id>
    <title>OESA-2024-1328 — python-yaql security update</title>
    <updated>2026-10-07T12:35:11.880943+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS: python-yaql</p>
<p>YAQL (Yet Another Query Language) is an embeddable and extensible query language, that allows performing complex queries against arbitrary objects. It has a vast and comprehensive standard library of frequently used querying functions and can be extend even further with user-specified functions. YAQL is written in python and is distributed via PyPI.

Security Fix(es):

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service&amp;apos;s MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.(CVE-2024-29156)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1328"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2059</id>
    <title>PYSEC-2026-2059 — Information leakage in YAQL</title>
    <updated>2026-10-07T12:35:11.880966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: yaql</p>
<p>YAQL before 3.0.0 is used in Murano, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2059"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1930</id>
    <title>RHSA-2024:1930 — Red Hat Security Advisory: Red Hat OpenStack Platform 17.1 (openstack-tripleo-heat-templates and python-yaql) security…</title>
    <updated>2026-10-07T12:35:11.880984+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>YAQL: OpenStack Murano Component Information Leakage</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1930"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-29156</id>
    <title>UBUNTU-CVE-2024-29156</title>
    <updated>2026-10-07T12:35:11.881002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: murano, Ubuntu:18.04:LTS: murano, Ubuntu:20.04:LTS: murano, Ubuntu:22.04:LTS: murano, Ubuntu:24.04:LTS: murano</p>
<p>In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-29156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0940</id>
    <title>WID-SEC-W-2024-0940 — Red Hat OpenStack: Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-07T12:35:11.881026+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat OpenStack ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0940"/>
  </entry>
</feed>
