<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T08:16:18.851717+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0315</id>
    <title>certfr-2026-avi-0315 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-06T08:16:19.018414+00:00</updated>
    <content>certfr-2026-avi-0315</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0315"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ba61304</id>
    <title>Withdrawn: CLEANSTART-2026-BA61304 — Security fixes in cosign 2.4.3-r0</title>
    <updated>2026-10-06T08:16:19.018475+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cosign</p>
<p>Package cosign version 2.4.3-r0 fixes 82 vulnerabilities: CVE-2025-0913, CVE-2025-15558, CVE-2025-22868, CVE-2025-22869, CVE-2025-22870...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ba61304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266512</id>
    <title>EUVD-2026-266512</title>
    <updated>2026-10-06T08:16:19.018525+00:00</updated>
    <content>EUVD-2026-266512</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266512"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24117</id>
    <title>fkie_cve-2026-24117</title>
    <updated>2026-10-06T08:16:19.018557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. The issue has been fixed in version 1.5.0. To workaround this issue, disable the search endpoint with --enable_retrieve_api=false.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-24117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4c4x-jm2x-pf9j</id>
    <title>GHSA-4c4x-jm2x-pf9j — Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URL</title>
    <updated>2026-10-06T08:16:19.018605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/sigstore/rekor</p>
<p>## Summary</p>
<p>`/api/v1/index/retrieve` supports retrieving a public key via a user-provided URL, allowing attackers to trigger SSRF to arbitrary internal services.</p>
<p>Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through [Blind SSRF](https://portswigger.net/web-security/ssrf/blind).</p>
<p>## Impact</p>
<p>* SSRF to cloud metadata (169.254.169.254)
* SSRF to internal Kubernetes APIs
* SSRF to any service accessible from Fulcio's network</p>
<p>## Patches</p>
<p>Upgrade to v1.5.0. Note that this is a breaking change to the search API and fully disables lookups by URL. If you require this feature, please reach out and we can discuss alternatives.</p>
<p>## Workarounds</p>
<p>Disable the search endpoint with `--enable_retrieve_api=false`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4c4x-jm2x-pf9j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10127-1</id>
    <title>openSUSE-SU-2026:10127-1 — rekor-1.5.0-1.1 on GA media</title>
    <updated>2026-10-06T08:16:19.018671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rekor-1.5.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10127-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:37387</id>
    <title>RHSA-2026:37387 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.0 security, enhancement &amp; bug fix update</title>
    <updated>2026-10-06T08:16:19.018709+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/containerd/containerd: containerd local privilege escalation containerd: containerd has an integer overflow in User ID handling runc: runc can be tricked into creating empty files/directories on host noobaa-core: Excessive permissions of /etc could lead to escalation of privilege in the noobaa-core container go-git: argument injection via the URL field go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects github.com/moby/moby: Moby's Firewalld reload removes bridge network isolation github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation github.com/sigstore/rekor: Rekor denial of service github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:37387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24117</id>
    <title>UBUNTU-CVE-2026-24117</title>
    <updated>2026-10-06T08:16:19.018896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: rekor, Ubuntu:Pro:26.04:LTS: rekor</p>
<p>Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. The issue has been fixed in version 1.5.0. To workaround this issue, disable the search endpoint with --enable_retrieve_api=false.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24117"/>
  </entry>
</feed>
