<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:21:20.121106+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bo50567</id>
    <title>Withdrawn: CLEANSTART-2026-BO50567 — Security fixes in argo-cd 3.1.12-r0</title>
    <updated>2026-10-02T14:21:20.128119+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: argo-cd</p>
<p>Package argo-cd version 3.1.12-r0 fixes 3 vulnerabilities: CVE-2025-13281, CVE-2025-5187, CVE-2025-4563</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bo50567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-245564</id>
    <title>EUVD-2026-245564</title>
    <updated>2026-10-02T14:21:20.128168+00:00</updated>
    <content>EUVD-2026-245564</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-245564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-4563</id>
    <title>fkie_cve-2025-4563</title>
    <updated>2026-10-02T14:21:20.128184+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-4563"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hj2p-8wj8-pfq4</id>
    <title>GHSA-hj2p-8wj8-pfq4 — kubernetes allows nodes to bypass dynamic resource allocation authorization checks</title>
    <updated>2026-10-02T14:21:20.128207+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: k8s.io/kubernetes</p>
<p>A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hj2p-8wj8-pfq4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-4563</id>
    <title>msrc_CVE-2025-4563 — Nodes can bypass dynamic resource allocation authorization checks</title>
    <updated>2026-10-02T14:21:20.128230+00:00</updated>
    <content>msrc_CVE-2025-4563</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-4563"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</id>
    <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
    <updated>2026-10-02T14:21:20.128245+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4563</id>
    <title>Withdrawn: UBUNTU-CVE-2025-4563</title>
    <updated>2026-10-02T14:21:20.128284+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: kubernetes, Ubuntu:22.04:LTS: kubernetes, Ubuntu:24.04:LTS: kubernetes</p>
<p>A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4563"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1357</id>
    <title>WID-SEC-W-2025-1357 — Kubernetes: Schwachstelle ermöglicht umgehen von Sicherheitsmechanismen.</title>
    <updated>2026-10-02T14:21:20.128307+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um Sicheheritmechnismen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1357"/>
  </entry>
</feed>
