<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:40:56.705660+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-13936</id>
    <title>bdu:2025-13936</title>
    <updated>2026-10-02T11:40:57.273100+00:00</updated>
    <content>bdu:2025-13936</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-13936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-61725</id>
    <title>BELL-CVE-2025-61725</title>
    <updated>2026-10-02T11:40:57.273153+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-61725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2025-61725</id>
    <title>BIT-golang-2025-61725 — Excessive CPU consumption in ParseAddress in net/mail</title>
    <updated>2026-10-02T11:40:57.273191+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2025-61725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0966</id>
    <title>certfr-2025-avi-0966 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T11:40:57.273216+00:00</updated>
    <content>certfr-2025-avi-0966</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ab43319</id>
    <title>Withdrawn: CLEANSTART-2026-AB43319 — Security fixes for CVE-2025-47911, CVE-2025-58183, CVE-2025-58185, CVE-2025-58187, CVE-2025-58188, CVE-2025-58189, CVE-…</title>
    <updated>2026-10-02T11:40:57.273232+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: stakater-reloader</p>
<p>Multiple security vulnerabilities affect the stakater-reloader package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ab43319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-262980</id>
    <title>EUVD-2026-262980</title>
    <updated>2026-10-02T11:40:57.273263+00:00</updated>
    <content>EUVD-2026-262980</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-262980"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-61725</id>
    <title>fkie_cve-2025-61725</title>
    <updated>2026-10-02T11:40:57.273306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-61725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qh38-484v-w52x</id>
    <title>GHSA-qh38-484v-w52x</title>
    <updated>2026-10-02T11:40:57.273326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The ParseAddress function constructeds domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qh38-484v-w52x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-61725</id>
    <title>msrc_CVE-2025-61725 — Excessive CPU consumption in ParseAddress in net/mail</title>
    <updated>2026-10-02T11:40:57.273340+00:00</updated>
    <content>msrc_CVE-2025-61725</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-61725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4067</id>
    <title>OESA-2026-4067 — git-lfs security update</title>
    <updated>2026-10-02T11:40:57.273355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: git-lfs</p>
<p>Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.

Security Fix(es):</p>
<p>Processing an incomplete post-handshake message for a QUIC connection can cause a panic.(CVE-2023-39321)</p>
<p>QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.(CVE-2023-39322)</p>
<p>Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.(CVE-2025-22874)</p>
<p>Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository&amp;apos;s working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. The git lfs checkout and git lfs pull commands do not check for symbolic links before writing to files in the working tree, allowing an attacker to craft a repository containing symbolic or hard links that cause Git LFS to write to arbitrary file system locations accessible to the user running these comman…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15608-1</id>
    <title>openSUSE-SU-2025:15608-1 — go1.24-1.24.8-1.1 on GA media</title>
    <updated>2026-10-02T11:40:57.273404+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.24-1.24.8-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15608-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:7291</id>
    <title>RHSA-2026:7291 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T11:40:57.273425+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>os: os: Information disclosure via path traversal using specially crafted filenames net/http: CrossOriginProtection bypass in net/http golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html net/url: Insufficient validation of bracketed IPv6 hostnames in net/url golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication golang: archive/tar: Unbounded allocation when parsing GNU sparse map encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 golang.org/net/http: Lack of limit when parsing cookies can cause memory exhaustion in net/http crypto/x509: Quadratic complexity when checking name constraints in crypto/x509 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information golang.org/x/net/html: Infinite parsing loop in golang.org/x/net encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem net/textproto: Excessive CPU consumption in Reader.ReadResponse in net/textproto net/mail: Excessive CPU consumption in ParseAddress in net/mail golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs golang: archive/zip: Excessive CPU co…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:7291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:21192-1</id>
    <title>SUSE-SU-2025:21192-1 — Security update for go1.25</title>
    <updated>2026-10-02T11:40:57.273500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.25</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:21192-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-61725</id>
    <title>UBUNTU-CVE-2025-61725</title>
    <updated>2026-10-02T11:40:57.273522+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 26 more</p>
<p>The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-61725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-088</id>
    <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
    <updated>2026-10-02T11:40:57.273583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.</p>
<p>The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25</p>
<p>All other vulnerabilities are to be fixed in the upcoming releases.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2227</id>
    <title>WID-SEC-W-2025-2227 — Golang Go: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:40:57.273638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Denial of Service Angriff durchzuführen  oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2227"/>
  </entry>
</feed>
