<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:06:41.885319+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00268</id>
    <title>bdu:2026-00268</title>
    <updated>2026-10-02T13:06:42.177780+00:00</updated>
    <content>bdu:2026-00268</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-61727</id>
    <title>BELL-CVE-2025-61727</title>
    <updated>2026-10-02T13:06:42.177827+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: docker, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-61727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2025-61727</id>
    <title>BIT-golang-2025-61727 — Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509</title>
    <updated>2026-10-02T13:06:42.177865+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2025-61727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1078</id>
    <title>certfr-2025-avi-1078 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T13:06:42.177891+00:00</updated>
    <content>certfr-2025-avi-1078</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1078"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad15516</id>
    <title>Withdrawn: CLEANSTART-2026-AD15516 — Security fixes in prometheus-redis-exporter-fips 1.77.0-r0</title>
    <updated>2026-10-02T13:06:42.177907+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: prometheus-redis-exporter-fips</p>
<p>Package prometheus-redis-exporter-fips version 1.77.0-r0 fixes 2 vulnerabilities: CVE-2025-61727, CVE-2025-61729</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ad15516"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-262521</id>
    <title>EUVD-2026-262521</title>
    <updated>2026-10-02T13:06:42.177928+00:00</updated>
    <content>EUVD-2026-262521</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-262521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-61727</id>
    <title>fkie_cve-2025-61727</title>
    <updated>2026-10-02T13:06:42.177939+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-61727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5mh9-3jwc-rp59</id>
    <title>GHSA-5mh9-3jwc-rp59</title>
    <updated>2026-10-02T13:06:42.177960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5mh9-3jwc-rp59"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-61727</id>
    <title>msrc_CVE-2025-61727 — Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509</title>
    <updated>2026-10-02T13:06:42.177974+00:00</updated>
    <content>msrc_CVE-2025-61727</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-61727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2863</id>
    <title>OESA-2025-2863 — golang security update</title>
    <updated>2026-10-02T13:06:42.177989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: golang</p>
<p>.

Security Fix(es):</p>
<p>crypto/x509: Exclude subdomain constraints do not restrict wildcard SANs Exclude subdomain constraints in certificate chains do not restrict the use of wildcard SANs in leaf certificates. For example, excluding the constraint on the subdomain test.example.com does not prevent the leaf certificate from claiming SAN*. example.com.(CVE-2025-61727)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15795-1</id>
    <title>openSUSE-SU-2025:15795-1 — go1.25-1.25.5-1.1 on GA media</title>
    <updated>2026-10-02T13:06:42.178010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.25-1.25.5-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15795-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:0990</id>
    <title>RHSA-2026:0990 — Red Hat Security Advisory: cert-manager Operator for Red Hat OpenShift 1.18.1</title>
    <updated>2026-10-02T13:06:42.178025+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:0990"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:21192-1</id>
    <title>SUSE-SU-2025:21192-1 — Security update for go1.25</title>
    <updated>2026-10-02T13:06:42.178046+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.25</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:21192-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-61727</id>
    <title>UBUNTU-CVE-2025-61727</title>
    <updated>2026-10-02T13:06:42.178065+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: golang-1.24, Ubuntu:24.04:LTS: golang-1.24, Ubuntu:25.10: golang-1.24, Ubuntu:25.10: golang-1.25, Ubuntu:26.04:LTS: golang-1.24, Ubuntu:26.04:LTS: golang-1.25</p>
<p>An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-61727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2724</id>
    <title>WID-SEC-W-2025-2724 — Golang Go: Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:06:42.178091+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2724"/>
  </entry>
</feed>
