<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:20:08.348315+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-14688</id>
    <title>bdu:2025-14688</title>
    <updated>2026-10-03T06:20:08.533994+00:00</updated>
    <content>bdu:2025-14688</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-14688"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1129</id>
    <title>certfr-2025-avi-1129 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T06:20:08.534051+00:00</updated>
    <content>certfr-2025-avi-1129</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad41794</id>
    <title>Withdrawn: CLEANSTART-2026-AD41794 — SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the c…</title>
    <updated>2026-10-03T06:20:08.534071+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cert-manager-webhook-pdns-fips</p>
<p>Multiple security vulnerabilities affect the cert-manager-webhook-pdns-fips package. SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ad41794"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261473</id>
    <title>EUVD-2026-261473</title>
    <updated>2026-10-03T06:20:08.534102+00:00</updated>
    <content>EUVD-2026-261473</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261473"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58181</id>
    <title>fkie_cve-2025-58181</title>
    <updated>2026-10-03T06:20:08.534115+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-58181"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j5w8-q4qc-rx2x</id>
    <title>GHSA-j5w8-q4qc-rx2x — golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption</title>
    <updated>2026-10-03T06:20:08.534137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: golang.org/x/crypto</p>
<p>SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j5w8-q4qc-rx2x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3398</id>
    <title>OESA-2026-3398 — buildah security update</title>
    <updated>2026-10-03T06:20:08.534157+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: buildah</p>
<p>The  package provides a command line tool which can be used to * create a working container from scratch or * create a working container from an image as a starting point * mount/umount a working container&amp;amp;apos;s root file system for manipulation * save container&amp;amp;apos;s root file system layer to create a new image * delete a working container or an image

Security Fix(es):</p>
<p>SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.(CVE-2025-47914)</p>
<p>SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.(CVE-2025-58181)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3398"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-ru-2026:20010-1</id>
    <title>openSUSE-RU-2026:20010-1 — Recommended update for trivy</title>
    <updated>2026-10-03T06:20:08.534183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for trivy</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-ru-2026:20010-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:15979</id>
    <title>RHSA-2026:15979 — Red Hat Security Advisory: Red Hat Ceph Storage</title>
    <updated>2026-10-03T06:20:08.534203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodemailer: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate js-yaml: js-yaml prototype pollution in merge glob: glob: Command Injection Vulnerability via Malicious Filenames github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:15979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0439-1</id>
    <title>SUSE-SU-2026:0439-1 — Security update for apptainer</title>
    <updated>2026-10-03T06:20:08.534229+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for apptainer</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0439-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58181</id>
    <title>UBUNTU-CVE-2025-58181</title>
    <updated>2026-10-03T06:20:08.534249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: google-guest-agent, Ubuntu:Pro:16.04:LTS: golang-go.crypto, Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:16.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: golang-go.crypto, Ubuntu:Pro:18.04:LTS: google-guest-agent, Ubuntu:Pro:20.04:LTS: google-guest-agent, Ubuntu:Pro:20.04:LTS: snapd and 13 more</p>
<p>SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58181"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2645</id>
    <title>WID-SEC-W-2025-2645 — Golang Go: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T06:20:08.534296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2645"/>
  </entry>
</feed>
