<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:34:33.176861+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264272</id>
    <title>EUVD-2026-264272</title>
    <updated>2026-10-03T10:34:33.336755+00:00</updated>
    <content>EUVD-2026-264272</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264272"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68476</id>
    <title>fkie_cve-2025-68476</title>
    <updated>2026-10-03T10:34:33.336808+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication to configure HashiCorp Vault authentication. The vulnerability stems from an incorrect or insufficient path validation when loading the Service Account Token specified in spec.hashiCorpVault.credential.serviceAccount. An attacker with permissions to create or modify a TriggerAuthentication resource can exfiltrate the content of any file from the node's filesystem (where the KEDA pod resides) by directing the file's content to a server under their control, as part of the Vault authentication request. The potential impact includes the exfiltration of sensitive system information, such as secrets, keys, or the content of files like /etc/passwd. This issue has been patched in versions 2.17.3 and 2.18.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c4p6-qg4m-9jmr</id>
    <title>GHSA-c4p6-qg4m-9jmr — KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential</title>
    <updated>2026-10-03T10:34:33.336849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/kedacore/keda/v2</p>
<p>### Impact
An Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication to configure HashiCorp Vault authentication.</p>
<p>The vulnerability stems from an incorrect or insufficient path validation when loading the Service Account Token specified in spec.hashiCorpVault.credential.serviceAccount.</p>
<p>An attacker with permissions to create or modify a TriggerAuthentication resource can exfiltrate the content of any file from the node's filesystem (where the KEDA pod resides) by directing the file's content to a server under their control, as part of the Vault authentication request.</p>
<p>The potential impact includes the exfiltration of sensitive system information, such as secrets, keys, or the content of files like /etc/passwd.</p>
<p>### Patches
The problem has been patched in v2.17.3 and 2.18.3 as well as in main branch.</p>
<p>### Workarounds
The only effective workaround is the strict restriction of permissions for creating and modifying TriggerAuthentication resources within the Kubernetes cluster.</p>
<p>Only trusted and authorized users should have create or update permissions on the TriggerAuthentication resource.</p>
<p>This limits an attacker's ability to configure a malicious TriggerAuthentication with an arbitrary path.</p>
<p>### Is my project affected?
If it execute s
```bash
kubectl get deploy keda-operator -n keda -o jsonpath="{.spec.template.spec.containers[0].image}"
```
and the version is not 2.17.3, 2.18.3 or &gt;= 2.19.0, t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c4p6-qg4m-9jmr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-68476</id>
    <title>msrc_CVE-2025-68476 — KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential</title>
    <updated>2026-10-03T10:34:33.336896+00:00</updated>
    <content>msrc_CVE-2025-68476</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-68476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:2106</id>
    <title>RHSA-2026:2106 — Red Hat Security Advisory: RHOAI 2.25.2 - Red Hat OpenShift AI</title>
    <updated>2026-10-03T10:34:33.336914+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>llama-stack-k8s-operator: Llama Stack service exposed across namespaces due to missing NetworkPolicy node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects fonttools: fontTools: Arbitrary file write leading to remote code execution via malicious .designspace file urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token github.com/argoproj/argo-workflows: argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links tornado: Tornado Quadratic DoS via Repeated Header Coalescing tornado: Tornado Quadratic DoS via Crafted Multipart Parameters github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation github.com/kedacore/keda: KEDA: Arbitrary file read vulnerability in Vault authentication aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:2106"/>
  </entry>
</feed>
