<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:15:04.387745+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264436</id>
    <title>EUVD-2026-264436</title>
    <updated>2026-10-02T16:15:04.507950+00:00</updated>
    <content>EUVD-2026-264436</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264436"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14925</id>
    <title>fkie_cve-2025-14925</title>
    <updated>2026-10-02T16:15:04.508006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Accelerate. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.</p>
<p>The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27985.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-14925"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7qqq-mmf5-fj73</id>
    <title>GHSA-7qqq-mmf5-fj73</title>
    <updated>2026-10-02T16:15:04.508044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Accelerate. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.</p>
<p>The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27985.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7qqq-mmf5-fj73"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:2695</id>
    <title>RHSA-2026:2695 — Red Hat Security Advisory: RHOAI 2.25.2 - Red Hat OpenShift AI</title>
    <updated>2026-10-02T16:15:04.508065+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>llama-stack-k8s-operator: Llama Stack service exposed across namespaces due to missing NetworkPolicy node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications accelerate: Hugging Face Accelerate: Remote Code Execution via Deserialization of Untrusted Data runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects fonttools: fontTools: Arbitrary file write leading to remote code execution via malicious .designspace file urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token github.com/argoproj/argo-workflows: argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation github.com/kedacore/keda: KEDA: Arbitrary file read vulnerability in Vault authentication aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:2695"/>
  </entry>
</feed>
