<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:31:11.496322+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:18913</id>
    <title>ALSA-2026:18913 — Important: containernetworking-plugins security update</title>
    <updated>2026-10-03T12:31:16.342326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: containernetworking-plugins</p>
<p>The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted.</p>
<p>Security Fix(es):</p>
<p>* crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
  * golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)
  * crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinuxRelease Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:18913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03408</id>
    <title>bdu:2026-03408</title>
    <updated>2026-10-03T12:31:16.342451+00:00</updated>
    <content>bdu:2026-03408</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03408"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-68121</id>
    <title>BELL-CVE-2025-68121</title>
    <updated>2026-10-03T12:31:16.342473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-68121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2025-68121</id>
    <title>BIT-golang-2025-68121 — Unexpected session resumption in crypto/tls</title>
    <updated>2026-10-03T12:31:16.342502+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2025-68121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0191</id>
    <title>certfr-2026-avi-0191 — Une vulnérabilité a été découverte dans Traefik. Elle permet à un attaquant de provoquer un contournement de la politiq…</title>
    <updated>2026-10-03T12:31:16.342525+00:00</updated>
    <content>certfr-2026-avi-0191</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0191"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ab85050</id>
    <title>Withdrawn: CLEANSTART-2026-AB85050 — Security fixes in kafka_exporter-fips 1.6.0-r0</title>
    <updated>2026-10-03T12:31:16.342541+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: kafka_exporter-fips</p>
<p>Package kafka_exporter-fips version 1.6.0-r0 fixes 8 vulnerabilities: ghsa-8r3f-844c-mc37, CVE-2025-68121, CVE-2025-61726, CVE-2025-61728, CVE-2025-61730...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ab85050"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-307835</id>
    <title>EUVD-2026-307835</title>
    <updated>2026-10-03T12:31:16.342561+00:00</updated>
    <content>EUVD-2026-307835</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-307835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68121</id>
    <title>fkie_cve-2025-68121</title>
    <updated>2026-10-03T12:31:16.342572+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h355-32pf-p2xm</id>
    <title>GHSA-h355-32pf-p2xm</title>
    <updated>2026-10-03T12:31:16.342595+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h355-32pf-p2xm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-68121</id>
    <title>msrc_CVE-2025-68121 — Unexpected session resumption in crypto/tls</title>
    <updated>2026-10-03T12:31:16.342612+00:00</updated>
    <content>msrc_CVE-2025-68121</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-68121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1698</id>
    <title>OESA-2026-1698 — golang security update</title>
    <updated>2026-10-03T12:31:16.342628+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP2: golang</p>
<p>The Go Programming Language.

Security Fix(es):</p>
<p>The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.(CVE-2025-61726)</p>
<p>archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive.(CVE-2025-61728)</p>
<p>Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The &amp;quot;#cgo pkg-config:&amp;quot; directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a &amp;quot;--log-file&amp;quot; argument to this directive, causing pkg-config to write to an attacker-controlled location.(CVE-2025-61731)</p>
<p>A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.(CVE-2025-61732)</p>
<p>Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10063-1</id>
    <title>openSUSE-SU-2026:10063-1 — go1.24-1.24.12-1.1 on GA media</title>
    <updated>2026-10-03T12:31:16.342680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.24-1.24.12-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10063-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10125</id>
    <title>RHSA-2026:10125 — Red Hat Security Advisory: RHTAS 1.3.4 - Red Hat Trusted Artifact Signer Release</title>
    <updated>2026-10-03T12:31:16.342741+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10125"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:22141</id>
    <title>RLSA-2026:22141 — Moderate: go-fdo-client and go-fdo-server security update</title>
    <updated>2026-10-03T12:31:16.342784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: go-fdo-server, Rocky Linux:10: go-fdo-client</p>
<p>This package provides a server-side implementation of the FIDO Device Onboard (FDO) specification, written in Go. FDO is an open standard for the late binding of device credentials, allowing for automated and secure on-boarding of devices when they are first powered on in their final location.</p>
<p>Security Fix(es):</p>
<p>* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)</p>
<p>* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)</p>
<p>* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)</p>
<p>* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:22141"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:20122-1</id>
    <title>SUSE-SU-2026:20122-1 — Security update for go1.24</title>
    <updated>2026-10-03T12:31:16.342815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.24</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:20122-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68121</id>
    <title>UBUNTU-CVE-2025-68121</title>
    <updated>2026-10-03T12:31:16.342833+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:Pro:20.04:LTS: golang-1.16, Ubuntu:20.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.20, Ubuntu:20.04:LTS: golang-1.21, Ubuntu:20.04:LTS: golang-1.22, Ubuntu:22.04:LTS: golang-1.17, Ubuntu:22.04:LTS: golang-1.18 and 14 more</p>
<p>During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-68121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-064</id>
    <title>VDE-2026-064 — METTLER TOLEDO: LabX Standard Report on External Component Analysis - v21.3</title>
    <updated>2026-10-03T12:31:16.342881+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been discovered in LabX Standard v21.3.22. Most of the vulnerabilities are fixed in LabX Standard v21.4.23. The Vulnerabilities CVE-2025-69419, CVE-2026-0915, CVE-2025-15467 and CVE-2025-58187 are not yet fixed. The fix will be available in the upcoming releases.</p>
<p>Notice: LabX Standard was formerly known as LabX Cloud Local.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0129</id>
    <title>WID-SEC-W-2026-0129 — Golang Go: Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:31:16.342908+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0129"/>
  </entry>
</feed>
