<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:14:52.859317+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03571</id>
    <title>bdu:2026-03571</title>
    <updated>2026-10-02T16:14:53.031700+00:00</updated>
    <content>bdu:2026-03571</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691</id>
    <title>Withdrawn: CLEANSTART-2026-AA33691 — Security fixes in calico-fips 3.28.5-r4</title>
    <updated>2026-10-02T16:14:53.031739+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: calico-fips</p>
<p>Package calico-fips version 3.28.5-r4 fixes 5 vulnerabilities: CVE-2026-33186, CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2025-13281</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-263520</id>
    <title>EUVD-2026-263520</title>
    <updated>2026-10-02T16:14:53.031771+00:00</updated>
    <content>EUVD-2026-263520</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-263520"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-13281</id>
    <title>fkie_cve-2025-13281</title>
    <updated>2026-10-02T16:14:53.031784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-13281"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r6j8-c6r2-37rr</id>
    <title>GHSA-r6j8-c6r2-37rr — kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass</title>
    <updated>2026-10-02T16:14:53.031808+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: k8s.io/kubernetes</p>
<p>A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r6j8-c6r2-37rr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-13281</id>
    <title>msrc_CVE-2025-13281 — Portworx Half-Blind SSRF in kube-controller-manager</title>
    <updated>2026-10-02T16:14:53.031832+00:00</updated>
    <content>msrc_CVE-2025-13281</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-13281"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2815</id>
    <title>OESA-2025-2815 — kubernetes security update</title>
    <updated>2026-10-02T16:14:53.031848+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kubernetes</p>
<p>Container cluster management.

Security Fix(es):</p>
<p>A vulnerability was found in Kubernetes kube-controller-manager up to versions 1.30.14, 1.31.14, 1.32.9, 1.33.5 and 1.34.1. It has been classified as CWE-918 (Server-Side Request Forgery). The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. This vulnerability impacts confidentiality, integrity, and availability.(CVE-2025-13281)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2705</id>
    <title>WID-SEC-W-2025-2705 — Kubernetes: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-02T16:14:53.031870+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2705"/>
  </entry>
</feed>
