<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:16:35.612229+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:7466</id>
    <title>ALSA-2025:7466 — Moderate: delve and golang security update</title>
    <updated>2026-10-04T01:16:36.402819+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: delve, AlmaLinux:10: go-toolset, AlmaLinux:10: golang, AlmaLinux:10: golang-bin, AlmaLinux:10: golang-docs, AlmaLinux:10: golang-misc, AlmaLinux:10: golang-src, AlmaLinux:10: golang-tests</p>
<p>Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you're using a debugger, things aren't going your way. With that in mind, Delve should stay out of your way as much as possible.</p>
<p>Security Fix(es):</p>
<p>* golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints (CVE-2024-45341)
  * golang: net/[http:](http:) net/[http:](http:) sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336)
  * crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:7466"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-03456</id>
    <title>bdu:2025-03456</title>
    <updated>2026-10-04T01:16:36.402933+00:00</updated>
    <content>bdu:2025-03456</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-03456"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-22866</id>
    <title>Withdrawn: BELL-CVE-2025-22866 — CVE-2025-22866 does not affect BellSoft software</title>
    <updated>2026-10-04T01:16:36.402953+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-22866"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2025-22866</id>
    <title>BIT-golang-2025-22866 — Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec</title>
    <updated>2026-10-04T01:16:36.402969+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2025-22866"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0256</id>
    <title>certfr-2025-avi-0256 — De multiples vulnérabilités ont été découvertes dans Broadcom VMware Tanzu Greenplum. Elles permettent à un attaquant d…</title>
    <updated>2026-10-04T01:16:36.402992+00:00</updated>
    <content>certfr-2025-avi-0256</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cr41732</id>
    <title>Withdrawn: CLEANSTART-2026-CR41732 — net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines</title>
    <updated>2026-10-04T01:16:36.403007+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: ingress-nginx-controller</p>
<p>Multiple security vulnerabilities affect the ingress-nginx-controller package. The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cr41732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-218592</id>
    <title>EUVD-2026-218592</title>
    <updated>2026-10-04T01:16:36.403028+00:00</updated>
    <content>EUVD-2026-218592</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-218592"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22866</id>
    <title>fkie_cve-2025-22866</title>
    <updated>2026-10-04T01:16:36.403039+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-22866"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3whm-j4xm-rv8x</id>
    <title>GHSA-3whm-j4xm-rv8x</title>
    <updated>2026-10-04T01:16:36.403061+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3whm-j4xm-rv8x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-22866</id>
    <title>msrc_CVE-2025-22866 — Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec</title>
    <updated>2026-10-04T01:16:36.403076+00:00</updated>
    <content>msrc_CVE-2025-22866</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-22866"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14735-1</id>
    <title>openSUSE-SU-2025:14735-1 — go1.24-1.24rc3-1.1 on GA media</title>
    <updated>2026-10-04T01:16:36.403092+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.24-1.24rc3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14735-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhea-2025:3039</id>
    <title>RHEA-2025:3039 — Red Hat Enhancement Advisory: RHEA: Submariner 0.19.3 - bug fix and enhancement update</title>
    <updated>2026-10-04T01:16:36.403108+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhea-2025:3039"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:67148</id>
    <title>RLSA-2026:67148 — Important: osbuild-composer security update</title>
    <updated>2026-10-04T01:16:36.403125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: osbuild-composer</p>
<p>A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.</p>
<p>Security Fix(es):</p>
<p>* crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)</p>
<p>* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)</p>
<p>* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)</p>
<p>* mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)</p>
<p>* github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)</p>
<p>* github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:67148"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0392-1</id>
    <title>SUSE-SU-2025:0392-1 — Security update for go1.22</title>
    <updated>2026-10-04T01:16:36.403156+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.22</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0392-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22866</id>
    <title>UBUNTU-CVE-2025-22866</title>
    <updated>2026-10-04T01:16:36.403170+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 24 more</p>
<p>Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22866"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0263</id>
    <title>WID-SEC-W-2025-0263 — Golang Go: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-04T01:16:36.403245+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Golang Go ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0263"/>
  </entry>
</feed>
