<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:54:33.898228+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-11338</id>
    <title>bdu:2024-11338</title>
    <updated>2026-10-02T14:54:34.167854+00:00</updated>
    <content>bdu:2024-11338</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-11338"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0256</id>
    <title>certfr-2025-avi-0256 — De multiples vulnérabilités ont été découvertes dans Broadcom VMware Tanzu Greenplum. Elles permettent à un attaquant d…</title>
    <updated>2026-10-02T14:54:34.167937+00:00</updated>
    <content>certfr-2025-avi-0256</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bm41238</id>
    <title>Withdrawn: CLEANSTART-2026-BM41238 — Security fixes for CVE-2024-45337, ghsa-6v2p-p943-phr9, ghsa-c6gw-w398-hv78, ghsa-f6x5-jh6r-wrfv, ghsa-hcg3-p754-cr77,…</title>
    <updated>2026-10-02T14:54:34.167958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: rabbitmq-messaging-topology-operator</p>
<p>Multiple security vulnerabilities affect the rabbitmq-messaging-topology-operator package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bm41238"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-218167</id>
    <title>EUVD-2026-218167</title>
    <updated>2026-10-02T14:54:34.167996+00:00</updated>
    <content>EUVD-2026-218167</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-218167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45337</id>
    <title>fkie_cve-2024-45337</title>
    <updated>2026-10-02T14:54:34.168009+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B for which the attacker does not actually control the private key. Since this API is widely misused, as a partial mitigation golang.org/x/cry...@v0.31.0 enforces the property that, when successfully authenticating via public key, the last key passed to ServerConfig.PublicKeyCallback will be the key used to authenticate the connection. PublicKeyCallback will now be called…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-45337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v778-237x-gjrc</id>
    <title>GHSA-v778-237x-gjrc — Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto</title>
    <updated>2026-10-02T14:54:34.168047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: golang.org/x/crypto</p>
<p>Applications and libraries which misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass.</p>
<p>The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions.</p>
<p>For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B for which the attacker does not actually control the private key.</p>
<p>Since this API is widely misused, as a partial mitigation golang.org/x/crypto@v0.31.0 enforces the property that, when successfully authenticating via public key, the last key passed to ServerConfig.PublicKeyCallback will be the key used to authenticate the connection. PublicKeyCallback will now be called multiple times with the same key, i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v778-237x-gjrc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-45337</id>
    <title>msrc_CVE-2024-45337 — Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto</title>
    <updated>2026-10-02T14:54:34.168087+00:00</updated>
    <content>msrc_CVE-2024-45337</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-45337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2257</id>
    <title>OESA-2025-2257 — buildah security update</title>
    <updated>2026-10-02T14:54:34.168105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP2: buildah</p>
<p>The  package provides a command line tool which can be used to * create a working container from scratch or * create a working container from an image as a starting point * mount/umount a working container&amp;amp;apos;s root file system for manipulation * save container&amp;amp;apos;s root file system layer to create a new image * delete a working container or an image

Security Fix(es):</p>
<p>Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that &amp;quot;A call to this function does not guarantee that the key offered is in fact used to authenticate.&amp;quot; Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization d…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2257"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14573-1</id>
    <title>openSUSE-SU-2024:14573-1 — teleport-17.0.5-1.1 on GA media</title>
    <updated>2026-10-02T14:54:34.168142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>teleport-17.0.5-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14573-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:0301</id>
    <title>RHBA-2025:0301 — Red Hat Bug Fix Advisory: Red Hat Quay v3.13.3 bug fix release</title>
    <updated>2026-10-02T14:54:34.168160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto nanoid: nanoid mishandles non-integer values jinja2: Jinja has a sandbox breakout through malicious filenames jinja2: Jinja has a sandbox breakout through indirect reference to format method</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:0301"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01985-1</id>
    <title>SUSE-SU-2025:01985-1 — Security update 4.3.15 for Multi-Linux Manager Server</title>
    <updated>2026-10-02T14:54:34.168182+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update 4.3.15 for Multi-Linux Manager Server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01985-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-45337</id>
    <title>UBUNTU-CVE-2024-45337</title>
    <updated>2026-10-02T14:54:34.168202+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: golang-go.crypto, Ubuntu:Pro:16.04:LTS: google-guest-agent, Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: golang-go.crypto, Ubuntu:Pro:18.04:LTS: google-guest-agent, Ubuntu:Pro:20.04:LTS: google-guest-agent, Ubuntu:Pro:20.04:LTS: golang-go.crypto, Ubuntu:22.04:LTS: google-guest-agent, Ubuntu:Pro:22.04:LTS: golang-go.crypto and 3 more</p>
<p>Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B for which the attacker does not actually control the private key. Since this API is widely misused, as a partial mitigation golang.org/x/cry...@v0.31.0 enforces the property that, when successfully authenticating via public key, the last key passed to ServerConfig.PublicKeyCallback will be the key used to authenticate the connection. PublicKeyCallback will now be called…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-45337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3690</id>
    <title>WID-SEC-W-2024-3690 — Gitea: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-02T14:54:34.168252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Gitea ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3690"/>
  </entry>
</feed>
