<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:15:55.617430+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08699</id>
    <title>bdu:2026-08699</title>
    <updated>2026-10-03T09:15:55.827323+00:00</updated>
    <content>bdu:2026-08699</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08699"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-11564</id>
    <title>BELL-CVE-2026-11564</title>
    <updated>2026-10-03T09:15:55.827361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: curl, Alpaquita:25: curl, Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-11564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0797</id>
    <title>certfr-2026-avi-0797 — De multiples vulnérabilités ont été découvertes dans cURL et libcurl. Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-03T09:15:55.827398+00:00</updated>
    <content>certfr-2026-avi-0797</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368402</id>
    <title>EUVD-2026-368402</title>
    <updated>2026-10-03T09:15:55.827416+00:00</updated>
    <content>EUVD-2026-368402</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-11564</id>
    <title>fkie_cve-2026-11564</title>
    <updated>2026-10-03T09:15:55.827428+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup.</p>
<p>An easy handle that first uses default native CA trust can continue trusting
the native platform store after the application switches that same handle to
custom CA material for a later transfer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-11564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hf82-6jff-f22v</id>
    <title>GHSA-hf82-6jff-f22v</title>
    <updated>2026-10-03T09:15:55.827454+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>libcurl keeps previously used connections in a connection pool for subsequent
transfers to reuse if one of them matches the setup.</p>
<p>An easy handle that first uses default native CA trust can continue trusting
the native platform store after the application switches that same handle to
custom CA material for a later transfer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hf82-6jff-f22v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-11564</id>
    <title>msrc_CVE-2026-11564 — Native CA trust persist</title>
    <updated>2026-10-03T09:15:55.827470+00:00</updated>
    <content>msrc_CVE-2026-11564</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-11564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11230-1</id>
    <title>openSUSE-SU-2026:11230-1 — curl-8.21.0-1.1 on GA media</title>
    <updated>2026-10-03T09:15:55.827487+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl-8.21.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11230-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:29017</id>
    <title>RHSA-2026:29017 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T09:15:55.827514+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl: curl: Insecure connection establishment due to TLS configuration mismatch curl: libcurl: Unauthorized connection reuse due to a logical error curl: curl: Cookie injection via malicious HTTP server using super cookies curl: curl: Double-free vulnerability in SASL authentication curl: curl: Information disclosure via incorrect .netrc password lookup curl: Information disclosure due to uncleared proxy authentication state libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback libcurl: libcurl: Information disclosure due to persistent Referer header curl: curl: Man-in-the-middle attack via SSH host key bypass curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse curl: curl: Denial of Service via WebSocket PING flood curl: curl: Information disclosure via incorrect Digest authentication header reuse curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:29017"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-11564</id>
    <title>UBUNTU-CVE-2026-11564</title>
    <updated>2026-10-03T09:15:55.827556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:26.04:LTS: curl</p>
<p>libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-11564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2052</id>
    <title>WID-SEC-W-2026-2052 — cURL: Mehrere Schwachstellen</title>
    <updated>2026-10-03T09:15:55.827577+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand oder eine Speicherbeschädigung zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2052"/>
  </entry>
</feed>
