<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:30:04.101807+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05122</id>
    <title>bdu:2026-05122</title>
    <updated>2026-10-02T15:30:04.318676+00:00</updated>
    <content>bdu:2026-05122</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05122"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-14017</id>
    <title>BELL-CVE-2025-14017</title>
    <updated>2026-10-02T15:30:04.318720+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-14017"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0010</id>
    <title>certfr-2026-avi-0010 — De multiples vulnérabilités ont été découvertes dans Curl. Elles permettent à un attaquant de provoquer une atteinte à…</title>
    <updated>2026-10-02T15:30:04.318750+00:00</updated>
    <content>certfr-2026-avi-0010</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368394</id>
    <title>EUVD-2026-368394</title>
    <updated>2026-10-02T15:30:04.318768+00:00</updated>
    <content>EUVD-2026-368394</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368394"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14017</id>
    <title>fkie_cve-2025-14017</title>
    <updated>2026-10-02T15:30:04.318780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,
changing TLS options in one thread would inadvertently change them globally
and therefore possibly also affect other concurrently setup transfers.</p>
<p>Disabling certificate verification for a specific transfer could
unintentionally disable the feature for other threads as well.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-14017"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jh4h-2cg6-889h</id>
    <title>GHSA-jh4h-2cg6-889h</title>
    <updated>2026-10-02T15:30:04.318805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,
changing TLS options in one thread would inadvertently change them globally
and therefore possibly also affect other concurrently setup transfers.</p>
<p>Disabling certificate verification for a specific transfer could
unintentionally disable the feature for other threads as well.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jh4h-2cg6-889h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-14017</id>
    <title>msrc_CVE-2025-14017 — broken TLS options for threaded LDAPS</title>
    <updated>2026-10-02T15:30:04.318821+00:00</updated>
    <content>msrc_CVE-2025-14017</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-14017"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0127</id>
    <title>NCSC-2026-0127 — Kwetsbaarheden verholpen in Oracle PeopleSoft</title>
    <updated>2026-10-02T15:30:04.318837+00:00</updated>
    <content>NCSC-2026-0127</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10017-1</id>
    <title>openSUSE-SU-2026:10017-1 — curl-8.18.0-1.1 on GA media</title>
    <updated>2026-10-02T15:30:04.318868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl-8.18.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10017-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:6893</id>
    <title>RHSA-2026:6893 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T15:30:04.318886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl: libcurl: Curl out of bounds read for cookie path curl: predictable WebSocket mask curl: Curl missing SFTP host verification with wolfSSH backend curl: Public key pinning bypass via QUIC and GnuTLS allows server impersonation curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token curl: libcurl: Improper certificate validation due to cached TLS settings reuse curl: Host verification bypass during SSH transfers curl: libssh key passphrase bypass without agent set curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect curl: curl: Unauthorized access due to improper HTTP proxy connection reuse curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:6893"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0077-1</id>
    <title>SUSE-SU-2026:0077-1 — Security update for curl</title>
    <updated>2026-10-02T15:30:04.318923+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0077-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14017</id>
    <title>UBUNTU-CVE-2025-14017</title>
    <updated>2026-10-02T15:30:04.318938+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: curl, Ubuntu:Pro:16.04:LTS: curl, Ubuntu:Pro:18.04:LTS: curl, Ubuntu:Pro:20.04:LTS: curl, Ubuntu:22.04:LTS: curl, Ubuntu:24.04:LTS: curl, Ubuntu:25.10: curl</p>
<p>When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14017"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0030</id>
    <title>WID-SEC-W-2026-0030 — cURL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:30:04.318967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0030"/>
  </entry>
</feed>
