<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:07:48.793410+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:23664</id>
    <title>ALSA-2025:23664 — Important: opentelemetry-collector security update</title>
    <updated>2026-10-04T01:07:49.324343+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: opentelemetry-collector</p>
<p>Collector with the supported components for a AlmaLinux build of OpenTelemetry</p>
<p>Security Fix(es):</p>
<p>* github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation (CVE-2025-68156)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:23664"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05696</id>
    <title>bdu:2026-05696</title>
    <updated>2026-10-04T01:07:49.324434+00:00</updated>
    <content>bdu:2026-05696</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0627</id>
    <title>certfr-2026-avi-0627 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-04T01:07:49.324453+00:00</updated>
    <content>certfr-2026-avi-0627</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0627"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cf63541</id>
    <title>Withdrawn: CLEANSTART-2026-CF63541 — Security fixes in eks-distro-coredns-fips 1.35.7-r0</title>
    <updated>2026-10-04T01:07:49.324470+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: eks-distro-coredns-fips</p>
<p>Package eks-distro-coredns-fips version 1.35.7-r0 fixes 6 vulnerabilities: ghsa-cfpf-hrx2-8rv6, ghsa-p77j-4mvh-x3m3, ghsa-9h8m-3fm2-qjrq, CVE-2025-68156, CVE-2026-24051...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cf63541"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-263789</id>
    <title>EUVD-2026-263789</title>
    <updated>2026-10-04T01:07:49.324492+00:00</updated>
    <content>EUVD-2026-263789</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-263789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68156</id>
    <title>fkie_cve-2025-68156</title>
    <updated>2026-10-04T01:07:49.324503+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the evaluation environment contains deeply nested or cyclic data structures, these functions may recurse indefinitely until exceed the Go runtime stack limit. This results in a stack overflow panic, causing the host application to crash. While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the
evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness. Instead of returning a recoverable evaluation error, the process may terminate unexpectedly. In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently validated data structures can lead to a process-level crash due to stack exhaustion. This issue is most relevant in scenarios where Expr is used to evaluate expressions against externally supplied or dynamically constructed environments; cyclic references (directly or indirectly) can be introduced into arrays, maps, or structs; and there are no application-level safeguards preventing deeply nested input data. In typical use cases with controlled, acyclic data, the issue may not manifest. However, when present, th…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cfpf-hrx2-8rv6</id>
    <title>GHSA-cfpf-hrx2-8rv6 — Expr has Denial of Service via Unbounded Recursion in Builtin Functions</title>
    <updated>2026-10-04T01:07:49.324543+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/expr-lang/expr</p>
<p>Several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform
recursive traversal over user-provided data structures without enforcing a maximum recursion depth.</p>
<p>If the evaluation environment contains **deeply nested** or **cyclic** data structures, these functions may recurse
indefinitely until exceed the Go runtime stack limit. This results in a **stack overflow panic**, causing the host
application to crash.</p>
<p>While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the
evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness.
Instead of returning a recoverable evaluation error, the process may terminate unexpectedly.</p>
<p>### Impact</p>
<p>In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently
validated data structures can lead to a **process-level crash** due to stack exhaustion.</p>
<p>This issue is most relevant in scenarios where:</p>
<p>* Expr is used to evaluate expressions against externally supplied or dynamically constructed environments.
* Cyclic references (directly or indirectly) can be introduced into arrays, maps, or structs.
* There are no application-level safeguards preventing deeply nested input data.</p>
<p>In typical use cases with controlled, acyclic data, the issue may not manifest. However, when present, the resulting
panic can be used to reliably crash the a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cfpf-hrx2-8rv6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-68156</id>
    <title>msrc_CVE-2025-68156 — Expr has Denial of Service via Unbounded Recursion in Builtin Functions</title>
    <updated>2026-10-04T01:07:49.324585+00:00</updated>
    <content>msrc_CVE-2025-68156</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-68156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15825-1</id>
    <title>openSUSE-SU-2025:15825-1 — coredns-for-k8s1.33-1.12.0-2.1 on GA media</title>
    <updated>2026-10-04T01:07:49.324603+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>coredns-for-k8s1.33-1.12.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15825-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:23664</id>
    <title>RHSA-2025:23664 — Red Hat Security Advisory: opentelemetry-collector security update</title>
    <updated>2026-10-04T01:07:49.324619+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:23664"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0628-1</id>
    <title>SUSE-SU-2026:0628-1 — Security update 5.1.2 for Multi-Linux Manager Client Tools</title>
    <updated>2026-10-04T01:07:49.324635+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update 5.1.2 for Multi-Linux Manager Client Tools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0628-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2886</id>
    <title>WID-SEC-W-2025-2886 — Red Hat Enterprise Linux (git-lfs, opentelemetry-collector): Mehrere Schwachstellen</title>
    <updated>2026-10-04T01:07:49.324650+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Dateien zu manipulieren und einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2886"/>
  </entry>
</feed>
