<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:34:15.121054+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:1902</id>
    <title>ALSA-2026:1902 — Important: python-wheel security update</title>
    <updated>2026-10-02T17:34:16.374016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: python3-wheel, AlmaLinux:10: python3-wheel-wheel</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking (CVE-2026-24049)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:1902"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03593</id>
    <title>bdu:2026-03593</title>
    <updated>2026-10-02T17:34:16.374100+00:00</updated>
    <content>bdu:2026-03593</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03593"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-24049</id>
    <title>BELL-CVE-2026-24049</title>
    <updated>2026-10-02T17:34:16.374118+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: py3-wheel, Alpaquita:stream: py3-wheel, BellSoft Hardened Containers:25: py3-wheel, BellSoft Hardened Containers:stream: py3-wheel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-24049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2026-24049</id>
    <title>BREW-aws-sam-cli-CVE-2026-24049 — Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack</title>
    <updated>2026-10-02T17:34:16.374142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aws-sam-cli</p>
<p>### Summary
 - **Vulnerability Type:** Path Traversal (CWE-22) leading to Arbitrary File Permission Modification.  
 - **Root Cause Component:** wheel.cli.unpack.unpack function.  
 - **Affected Packages:**  
   1. wheel (Upstream source)  
   2. setuptools (Downstream, vendors wheel)  
 - **Severity:** High (Allows modifying system file permissions).</p>
<p>### Details  
The vulnerability exists in how the unpack function handles file permissions after extraction. The code blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path.  
```
# Vulnerable Code Snippet (present in both wheel and setuptools/_vendor/wheel)
for zinfo in wf.filelist:
    wf.extract(zinfo, destination)  # (1) Extraction is handled safely by zipfile</p>
<p># (2) VULNERABILITY:
    # The 'permissions' are applied to a path constructed using the UNSANITIZED 'zinfo.filename'.
    # If zinfo.filename contains "../", this targets files outside the destination.
    permissions = zinfo.external_attr &gt;&gt; 16 &amp; 0o777
    destination.joinpath(zinfo.filename).chmod(permissions)
```</p>
<p>### PoC  
I have confirmed this exploit works against the unpack function imported from setuptools._vendor.wheel.cli.unpack.</p>
<p>**Prerequisites:** pip install setuptools</p>
<p>**Step 1: Generate the Malicious Wheel (gen_poc.py)**  
This script creates a wheel that passes internal hash validation but contains a directory traversal payload in the file list.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2026-24049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0326</id>
    <title>certfr-2026-avi-0326 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T17:34:16.374200+00:00</updated>
    <content>certfr-2026-avi-0326</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0326"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ks43633</id>
    <title>Withdrawn: CLEANSTART-2026-KS43633 — Security fixes in airflow-3 3.0.6-r1</title>
    <updated>2026-10-02T17:34:16.374216+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: airflow-3</p>
<p>Package airflow-3 version 3.0.6-r1 fixes 29 vulnerabilities: CVE-2026-25604, CVE-2026-42526, CVE-2026-27173, CVE-2026-41018, CVE-2026-46745...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ks43633"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-369275</id>
    <title>EUVD-2026-369275</title>
    <updated>2026-10-02T17:34:16.374237+00:00</updated>
    <content>EUVD-2026-369275</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-369275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24049</id>
    <title>fkie_cve-2026-24049</title>
    <updated>2026-10-02T17:34:16.374249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-24049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8rrh-rw8j-w5fx</id>
    <title>GHSA-8rrh-rw8j-w5fx — Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack</title>
    <updated>2026-10-02T17:34:16.374272+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: wheel</p>
<p>### Summary
 - **Vulnerability Type:** Path Traversal (CWE-22) leading to Arbitrary File Permission Modification.  
 - **Root Cause Component:** wheel.cli.unpack.unpack function.  
 - **Affected Packages:**  
   1. wheel (Upstream source)  
   2. setuptools (Downstream, vendors wheel)  
 - **Severity:** High (Allows modifying system file permissions).</p>
<p>### Details  
The vulnerability exists in how the unpack function handles file permissions after extraction. The code blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path.  
```
# Vulnerable Code Snippet (present in both wheel and setuptools/_vendor/wheel)
for zinfo in wf.filelist:
    wf.extract(zinfo, destination)  # (1) Extraction is handled safely by zipfile</p>
<p># (2) VULNERABILITY:
    # The 'permissions' are applied to a path constructed using the UNSANITIZED 'zinfo.filename'.
    # If zinfo.filename contains "../", this targets files outside the destination.
    permissions = zinfo.external_attr &gt;&gt; 16 &amp; 0o777
    destination.joinpath(zinfo.filename).chmod(permissions)
```</p>
<p>### PoC  
I have confirmed this exploit works against the unpack function imported from setuptools._vendor.wheel.cli.unpack.</p>
<p>**Prerequisites:** pip install setuptools</p>
<p>**Step 1: Generate the Malicious Wheel (gen_poc.py)**  
This script creates a wheel that passes internal hash validation but contains a directory traversal payload in the file list.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8rrh-rw8j-w5fx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1279</id>
    <title>OESA-2026-1279 — python-wheel security update</title>
    <updated>2026-10-02T17:34:16.374326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: python-wheel</p>
<p>A built-package format for Python. A wheel is a ZIP-format archive with a specially formatted filename and the .whl extension. It is designed to contain all the files for a PEP 376 compatible install in a way that is very close to the on-disk format.

Security Fix(es):</p>
<p>wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.(CVE-2026-24049)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10151-1</id>
    <title>openSUSE-SU-2026:10151-1 — python311-wheel-0.46.3-1.1 on GA media</title>
    <updated>2026-10-02T17:34:16.374351+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-wheel-0.46.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10151-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2047</id>
    <title>PYSEC-2026-2047 — Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack</title>
    <updated>2026-10-02T17:34:16.374369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: wheel</p>
<p>### Summary
 - **Vulnerability Type:** Path Traversal (CWE-22) leading to Arbitrary File Permission Modification.  
 - **Root Cause Component:** wheel.cli.unpack.unpack function.  
 - **Affected Packages:**  
   1. wheel (Upstream source)  
   2. setuptools (Downstream, vendors wheel)  
 - **Severity:** High (Allows modifying system file permissions).</p>
<p>### Details  
The vulnerability exists in how the unpack function handles file permissions after extraction. The code blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path.  
```
# Vulnerable Code Snippet (present in both wheel and setuptools/_vendor/wheel)
for zinfo in wf.filelist:
    wf.extract(zinfo, destination)  # (1) Extraction is handled safely by zipfile</p>
<p># (2) VULNERABILITY:
    # The 'permissions' are applied to a path constructed using the UNSANITIZED 'zinfo.filename'.
    # If zinfo.filename contains "../", this targets files outside the destination.
    permissions = zinfo.external_attr &gt;&gt; 16 &amp; 0o777
    destination.joinpath(zinfo.filename).chmod(permissions)
```</p>
<p>### PoC  
I have confirmed this exploit works against the unpack function imported from setuptools._vendor.wheel.cli.unpack.</p>
<p>**Prerequisites:** pip install setuptools</p>
<p>**Step 1: Generate the Malicious Wheel (gen_poc.py)**  
This script creates a wheel that passes internal hash validation but contains a directory traversal payload in the file list.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2047"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10184</id>
    <title>RHSA-2026:10184 — Red Hat Security Advisory: RHOAI 2.25.5 - Red Hat OpenShift AI</title>
    <updated>2026-10-02T17:34:16.374420+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vllm: Server Side request forgery (SSRF) in MediaConnector feast: Feast: Remote Code Execution via insecure YAML deserialization openshift-ai: Trusty AI Grants All Authenticated users to list pods in any namespace nltk: Zip Slip Vulnerability in nltk Leading to Code Execution golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data cbor2: cbor2: Information Disclosure via shared memory in CBORDecoder reuse aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb aiohttp: aiohttp: Denial of Service via specially crafted POST request aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request python-markdown: denial of service via malformed HTML-like sequences nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function nltk: NLTK: Arbitrary file read via path traversal vulnerability io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files google-cloud-aiplatform: google-cloud-aiplatform: Arbitrary code execution via Stored Cross-Site Scripting (XSS) tensorflow: TensorFlow: Local privilege escalation via…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:20217-1</id>
    <title>SUSE-SU-2026:20217-1 — Security update for python-wheel</title>
    <updated>2026-10-02T17:34:16.374516+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-wheel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:20217-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24049</id>
    <title>UBUNTU-CVE-2026-24049</title>
    <updated>2026-10-02T17:34:16.374533+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:18.04:LTS: python-pip, Ubuntu:Pro:20.04:LTS: python-pip, Ubuntu:Pro:24.04:LTS: wheel, Ubuntu:25.10: python-pip, Ubuntu:25.10: wheel</p>
<p>wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0302</id>
    <title>WID-SEC-W-2026-0302 — Red Hat Enterprise Linux (python-wheel): Schwachstelle ermöglicht Privilegieneskalation und Codeausführung</title>
    <updated>2026-10-02T17:34:16.374565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen oder beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0302"/>
  </entry>
</feed>
