<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:58:01.823284+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362219</id>
    <title>EUVD-2026-362219</title>
    <updated>2026-10-02T14:58:01.851169+00:00</updated>
    <content>EUVD-2026-362219</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362219"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-4953</id>
    <title>fkie_cve-2025-4953</title>
    <updated>2026-10-02T14:58:01.851217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-4953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m68q-4hqr-mc6f</id>
    <title>GHSA-m68q-4hqr-mc6f — Podman Creates Temporary File with Insecure Permissions</title>
    <updated>2026-10-02T14:58:01.851264+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/containers/podman/v5</p>
<p>A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m68q-4hqr-mc6f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-4953</id>
    <title>msrc_CVE-2025-4953 — Podman: build context bind mount</title>
    <updated>2026-10-02T14:58:01.851300+00:00</updated>
    <content>msrc_CVE-2025-4953</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-4953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15564-1</id>
    <title>openSUSE-SU-2025:15564-1 — govulncheck-vulndb-0.0.20250917T170349-1.1 on GA media</title>
    <updated>2026-10-02T14:58:01.851333+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250917T170349-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15564-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:8690</id>
    <title>RHSA-2024:8690 — Red Hat Security Advisory: OpenShift Container Platform 4.13.53 packages and  security update</title>
    <updated>2026-10-02T14:58:01.851379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library buildah: Buildah allows arbitrary directory mount Podman: Buildah: CRI-O: symlink traversal vulnerability in the containers/storage library can cause Denial of Service (DoS) go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion podman: Build Context Bind Mount</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:8690"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4953</id>
    <title>UBUNTU-CVE-2025-4953</title>
    <updated>2026-10-02T14:58:01.851442+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: libpod, Ubuntu:Pro:24.04:LTS: libpod, Ubuntu:25.10: podman, Ubuntu:26.04:LTS: podman</p>
<p>A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2075</id>
    <title>WID-SEC-W-2025-2075 — Podman: Schwachstelle ermöglicht Manipulation von Dateien</title>
    <updated>2026-10-02T14:58:01.851470+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Podman ausnutzen, um Dateien zu manipulieren und Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2075"/>
  </entry>
</feed>
