<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:18:40.698556+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-08556</id>
    <title>bdu:2025-08556</title>
    <updated>2026-10-03T03:18:40.851064+00:00</updated>
    <content>bdu:2025-08556</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-08556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-22874</id>
    <title>BELL-CVE-2025-22874</title>
    <updated>2026-10-03T03:18:40.851116+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-22874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2025-22874</id>
    <title>BIT-golang-2025-22874 — Usage of ExtKeyUsageAny disables policy validation in crypto/x509</title>
    <updated>2026-10-03T03:18:40.851157+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2025-22874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</id>
    <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T03:18:40.851184+00:00</updated>
    <content>certfr-2025-avi-0622</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-244453</id>
    <title>EUVD-2026-244453</title>
    <updated>2026-10-03T03:18:40.851200+00:00</updated>
    <content>EUVD-2026-244453</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-244453"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22874</id>
    <title>fkie_cve-2025-22874</title>
    <updated>2026-10-03T03:18:40.851211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-22874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6f52-wpx2-hvf2</id>
    <title>GHSA-6f52-wpx2-hvf2</title>
    <updated>2026-10-03T03:18:40.851252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6f52-wpx2-hvf2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-22874</id>
    <title>msrc_CVE-2025-22874 — Usage of ExtKeyUsageAny disables policy validation in crypto/x509</title>
    <updated>2026-10-03T03:18:40.851279+00:00</updated>
    <content>msrc_CVE-2025-22874</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-22874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4067</id>
    <title>OESA-2026-4067 — git-lfs security update</title>
    <updated>2026-10-03T03:18:40.851313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: git-lfs</p>
<p>Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.

Security Fix(es):</p>
<p>Processing an incomplete post-handshake message for a QUIC connection can cause a panic.(CVE-2023-39321)</p>
<p>QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.(CVE-2023-39322)</p>
<p>Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.(CVE-2025-22874)</p>
<p>Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository&amp;apos;s working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. The git lfs checkout and git lfs pull commands do not check for symbolic links before writing to files in the working tree, allowing an attacker to craft a repository containing symbolic or hard links that cause Git LFS to write to arbitrary file system locations accessible to the user running these comman…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15224-1</id>
    <title>openSUSE-SU-2025:15224-1 — go1.24-1.24.4-1.1 on GA media</title>
    <updated>2026-10-03T03:18:40.851363+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.24-1.24.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15224-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:10677</id>
    <title>RHSA-2025:10677 — Red Hat Security Advisory: golang security update</title>
    <updated>2026-10-03T03:18:40.851381+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/http: Sensitive headers not cleared on cross-origin redirect in net/http crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:10677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22874</id>
    <title>UBUNTU-CVE-2025-22874</title>
    <updated>2026-10-03T03:18:40.851399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 22 more</p>
<p>Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1205</id>
    <title>WID-SEC-W-2025-1205 — Golang Go: Mehrere Schwachstellen</title>
    <updated>2026-10-03T03:18:40.851458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder weitere nicht spezifizierte Auswirkungen zu erziehlen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1205"/>
  </entry>
</feed>
