<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:42:27.978212+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:0401</id>
    <title>ALSA-2025:0401 — Important: grafana security update</title>
    <updated>2026-10-03T13:42:28.654637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: grafana, AlmaLinux:8: grafana-selinux</p>
<p>Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp; OpenTSDB.</p>
<p>Security Fix(es):</p>
<p>* go-git: argument injection via the URL field (CVE-2025-21613)
  * go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies (CVE-2025-21614)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:0401"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-00210</id>
    <title>bdu:2025-00210</title>
    <updated>2026-10-03T13:42:28.654724+00:00</updated>
    <content>bdu:2025-00210</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-00210"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0337</id>
    <title>certfr-2025-avi-0337 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T13:42:28.654742+00:00</updated>
    <content>certfr-2025-avi-0337</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-209116</id>
    <title>EUVD-2026-209116</title>
    <updated>2026-10-03T13:42:28.654759+00:00</updated>
    <content>EUVD-2026-209116</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-209116"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21613</id>
    <title>fkie_cve-2025-21613</title>
    <updated>2026-10-03T13:42:28.654780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-21613"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v725-9546-7q7m</id>
    <title>GHSA-v725-9546-7q7m — go-git has an Argument Injection via the URL field</title>
    <updated>2026-10-03T13:42:28.654804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: gopkg.in/src-d/go-git.v4, Go: github.com/go-git/go-git/v5</p>
<p>### Impact
An argument injection vulnerability was discovered in `go-git` versions prior to `v5.13`.</p>
<p>Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to [git-upload-pack flags](https://git-scm.com/docs/git-upload-pack). This only happens when the `file` transport protocol is being used, as that is the only protocol that shells out to `git` binaries.</p>
<p>### Affected versions
Users running versions of `go-git` from `v4` and above are recommended to upgrade to `v5.13` in order to mitigate this vulnerability.</p>
<p>### Workarounds
In cases where a bump to the latest version of `go-git` is not possible, we recommend users to enforce restrict validation rules for values passed in the URL field.</p>
<p>## Credit
Thanks to @vin01 for responsibly disclosing this vulnerability to us.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v725-9546-7q7m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21613</id>
    <title>msrc_CVE-2025-21613 — go-git has an Argument Injection via the URL field</title>
    <updated>2026-10-03T13:42:28.654834+00:00</updated>
    <content>msrc_CVE-2025-21613</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-21613"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:0056-1</id>
    <title>openSUSE-SU-2025:0056-1 — Security update for trivy</title>
    <updated>2026-10-03T13:42:28.654851+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for trivy</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:0056-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:6121</id>
    <title>RHSA-2024:6121 — Red Hat Security Advisory: OpenShift Container Platform 4.18.1 security and extras update</title>
    <updated>2026-10-03T13:42:28.654871+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>helm: shows secrets with --dry-run option in clear text PostCSS: Improper input validation in PostCSS cross-spawn: regular expression denial of service golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html body-parser: Denial of Service Vulnerability in body-parser dompurify: DOMPurify vulnerable to tampering by prototype pollution path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x nanoid: nanoid mishandles non-integer values jinja2: Jinja has a sandbox breakout through malicious filenames jinja2: Jinja has a sandbox breakout through indirect reference to format method go-git: argument injection via the URL field go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:6121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0060-1</id>
    <title>SUSE-SU-2025:0060-1 — Security update for govulncheck-vulndb</title>
    <updated>2026-10-03T13:42:28.654909+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for govulncheck-vulndb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0060-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21613</id>
    <title>UBUNTU-CVE-2025-21613</title>
    <updated>2026-10-03T13:42:28.654931+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: golang-github-go-git-go-git, Ubuntu:Pro:24.04:LTS: golang-github-go-git-go-git</p>
<p>go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21613"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0123</id>
    <title>WID-SEC-W-2025-0123 — Red Hat Enterprise Linux und and OpenShift (go-git): Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:42:28.654953+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in der Grafana Komponente ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen preiszugeben und einen Denial-of-Service-Zustand zu erzeugen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0123"/>
  </entry>
</feed>
