<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T13:43:02.880700+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-195168</id>
    <title>EUVD-2026-195168</title>
    <updated>2026-10-05T13:43:02.977791+00:00</updated>
    <content>EUVD-2026-195168</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-195168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47877</id>
    <title>fkie_cve-2024-47877</title>
    <updated>2026-10-05T13:43:02.977831+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 will require to implement the new methods that have been added.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-47877"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8rm2-93mq-jqhc</id>
    <title>GHSA-8rm2-93mq-jqhc — Extract has insufficient checks allowing attacker to create symlinks outside the extraction directory.</title>
    <updated>2026-10-05T13:43:02.977866+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/codeclysm/extract/v3, Go: github.com/codeclysm/extract/v4, Go: github.com/codeclysm/extract</p>
<p>### Impact
A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory.</p>
<p>### Patches
Please use version 4.0.0 or later `github.com/codeclysm/extract/v4`. Any previous version is affected by the bug.</p>
<p>### Workarounds
No knows workarounds.</p>
<p>### Backward compatibility notes about upgrading to `/v4` from `/v3`</p>
<p>If you're not using the `extract.Extractor.FS` interface, you will not face any breaking changes and upgrading should be as simple as changing the import to `/v4`. This should be the case for most of the userbase.</p>
<p>If you're using the `Extractor.FS` interface, then upgrading to `/v4` will require to implement the new methods that have been added:</p>
<p>```go
type FS interface {
    Link(string, string) error
    MkdirAll(string, os.FileMode) error
    OpenFile(name string, flag int, perm os.FileMode) (*os.File, error)
    Symlink(string, string) error</p>
<p>// The following methods have been added in the /v4 interface:</p>
<p>Remove(path string) error
    Stat(name string) (os.FileInfo, error)
    Chmod(name string, mode os.FileMode) error
}
```</p>
<p>There should be no other breaking changes in the `/v4` API.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8rm2-93mq-jqhc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</id>
    <title>openSUSE-SU-2024:0350-1 — Security update for govulncheck-vulndb</title>
    <updated>2026-10-05T13:43:02.977911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for govulncheck-vulndb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1</id>
    <title>SUSE-SU-2024:3911-1 — Security update for govulncheck-vulndb</title>
    <updated>2026-10-05T13:43:02.977961+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for govulncheck-vulndb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1"/>
  </entry>
</feed>
