<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:50:21.475805+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-10918</id>
    <title>bdu:2025-10918</title>
    <updated>2026-10-02T19:50:21.572759+00:00</updated>
    <content>bdu:2025-10918</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-10918"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-40918</id>
    <title>BELL-CVE-2025-40918</title>
    <updated>2026-10-02T19:50:21.572812+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: perl-authen-sasl, Alpaquita:25: perl-authen-sasl, Alpaquita:stream: perl-authen-sasl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-40918"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-git-cve-2025-40918</id>
    <title>BREW-git-CVE-2025-40918 — Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely</title>
    <updated>2026-10-02T19:50:21.572841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: git</p>
<p>Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely.</p>
<p>The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.</p>
<p>According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation
 depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-git-cve-2025-40918"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-259950</id>
    <title>EUVD-2026-259950</title>
    <updated>2026-10-02T19:50:21.572872+00:00</updated>
    <content>EUVD-2026-259950</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-259950"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40918</id>
    <title>fkie_cve-2025-40918</title>
    <updated>2026-10-02T19:50:21.572884+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely.</p>
<p>The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.</p>
<p>According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation
 depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-40918"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-496q-8ph2-c4fj</id>
    <title>GHSA-496q-8ph2-c4fj</title>
    <updated>2026-10-02T19:50:21.572909+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely.</p>
<p>The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.</p>
<p>According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation
 depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-496q-8ph2-c4fj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2422</id>
    <title>OESA-2026-2422 — perl-Authen-SASL security update</title>
    <updated>2026-10-02T19:50:21.572945+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: perl-Authen-SASL</p>
<p>Authen::SASL::Perl is the pure Perl implementation of SASL mechanisms in the Authen::SASL framework, At the time of this writing it provides the client part implementation for the following SASL mechanisms.

Security Fix(es):</p>
<p>Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID comes from a small set of numbers, and the epoch time may be guessed if not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. According to RFC 2831, the cnonce-value should be provided by the client and contain at least 64 bits of entropy to ensure security.(CVE-2025-40918)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2422"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15385-1</id>
    <title>openSUSE-SU-2025:15385-1 — perl-Authen-SASL-2.180.0-2.1 on GA media</title>
    <updated>2026-10-02T19:50:21.572969+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl-Authen-SASL-2.180.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15385-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:03088-1</id>
    <title>SUSE-SU-2025:03088-1 — Security update for perl-Authen-SASL, perl-Crypt-URandom</title>
    <updated>2026-10-02T19:50:21.572986+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for perl-Authen-SASL, perl-Crypt-URandom</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:03088-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40918</id>
    <title>UBUNTU-CVE-2025-40918</title>
    <updated>2026-10-02T19:50:21.573001+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:16.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:18.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:20.04:LTS: libauthen-sasl-perl, Ubuntu:22.04:LTS: libauthen-sasl-perl, Ubuntu:24.04:LTS: libauthen-sasl-perl, Ubuntu:25.10: libauthen-sasl-perl, Ubuntu:26.04:LTS: libauthen-sasl-perl</p>
<p>Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation  depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40918"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1032</id>
    <title>WID-SEC-W-2026-1032 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:50:21.573048+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1032"/>
  </entry>
</feed>
