<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:14:21.686542+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:3428</id>
    <title>ALSA-2026:3428 — Important: container-tools:rhel8 security update</title>
    <updated>2026-10-02T21:14:23.340859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more</p>
<p>The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.</p>
<p>Security Fix(es):</p>
<p>* golang: html/template: errors returned from MarshalJSON methods may break template escaping (CVE-2024-24785)
  * crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
  * github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload (CVE-2025-65637)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:3428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06592</id>
    <title>bdu:2026-06592</title>
    <updated>2026-10-02T21:14:23.341013+00:00</updated>
    <content>bdu:2026-06592</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06592"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-65637</id>
    <title>BELL-CVE-2025-65637</title>
    <updated>2026-10-02T21:14:23.341032+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: skopeo</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-65637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1082</id>
    <title>certfr-2025-avi-1082 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T21:14:23.341051+00:00</updated>
    <content>certfr-2025-avi-1082</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1082"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cx82241</id>
    <title>Withdrawn: CLEANSTART-2026-CX82241 — Security fixes in runc 1.1.14-r0</title>
    <updated>2026-10-02T21:14:23.341067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: runc</p>
<p>Package runc version 1.1.14-r0 fixes 40 vulnerabilities: ghsa-vvgc-356p-c3xw, CVE-2026-25679, CVE-2025-22873, CVE-2025-22872, CVE-2025-22871...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cx82241"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-262712</id>
    <title>EUVD-2026-262712</title>
    <updated>2026-10-02T21:14:23.341088+00:00</updated>
    <content>EUVD-2026-262712</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-262712"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-65637</id>
    <title>fkie_cve-2025-65637</title>
    <updated>2026-10-02T21:14:23.341100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions &lt; 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-65637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4f99-4q7p-p3gh</id>
    <title>GHSA-4f99-4q7p-p3gh — Logrus is vulnerable to DoS when using Entry.Writer()</title>
    <updated>2026-10-02T21:14:23.341126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/sirupsen/logrus</p>
<p>A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions &lt; 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4f99-4q7p-p3gh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-65637</id>
    <title>msrc_CVE-2025-65637 — A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line p…</title>
    <updated>2026-10-02T21:14:23.341152+00:00</updated>
    <content>msrc_CVE-2025-65637</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-65637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1270</id>
    <title>OESA-2026-1270 — runc security update</title>
    <updated>2026-10-02T21:14:23.341170+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: runc</p>
<p>runc is a CLI tool for spawning and running containers according to the OCI specification.

Security Fix(es):</p>
<p>A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with &amp;quot;token too long&amp;quot; and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions &amp;lt; 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.(CVE-2025-65637)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1270"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:0327</id>
    <title>RHSA-2026:0327 — Red Hat Security Advisory: OpenShift Container Platform 4.16.55 bug fix and security update</title>
    <updated>2026-10-02T21:14:23.341195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:0327"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:3428</id>
    <title>RHSA-2026:3428 — Red Hat Security Advisory: container-tools:rhel8 security update</title>
    <updated>2026-10-02T21:14:23.341212+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: html/template: errors returned from MarshalJSON methods may break template escaping crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:3428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-65637</id>
    <title>UBUNTU-CVE-2025-65637</title>
    <updated>2026-10-02T21:14:23.341231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: golang-logrus, Ubuntu:18.04:LTS: golang-logrus, Ubuntu:20.04:LTS: golang-logrus, Ubuntu:22.04:LTS: golang-logrus, Ubuntu:24.04:LTS: golang-logrus, Ubuntu:25.10: golang-logrus, Ubuntu:26.04:LTS: golang-logrus</p>
<p>A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and causing application unavailability (DoS). This affects versions &lt; 1.8.3, 1.9.0, and 1.9.2. The issue is fixed in 1.8.3, 1.9.1, and 1.9.3+, where the input is chunked and the writer continues to function even if an error is logged.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-65637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0114</id>
    <title>WID-SEC-W-2026-0114 — Red Hat OpenShift (github.com/sirupsen/logrus): Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T21:14:23.341263+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0114"/>
  </entry>
</feed>
