<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:43:59.570192+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:11412</id>
    <title>ALSA-2026:11412 — Important: yggdrasil-worker-package-manager security update</title>
    <updated>2026-10-03T07:44:04.603150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: yggdrasil-worker-package-manager</p>
<p>yggdrasil-worker-package-manager is a simple package manager yggd worker. It knows how to install and remove packages, add, remove, enable and disable repositories, and does rudimentary detection of the host it is running on to guess the package manager to use. It only installs packages that match one of the provided allow-pattern regular expressions.</p>
<p>Security Fix(es):</p>
<p>* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:11412"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04127</id>
    <title>bdu:2026-04127</title>
    <updated>2026-10-03T07:44:04.603278+00:00</updated>
    <content>bdu:2026-04127</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-25679</id>
    <title>BELL-CVE-2026-25679</title>
    <updated>2026-10-03T07:44:04.603298+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-25679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2026-25679</id>
    <title>BIT-golang-2026-25679 — Incorrect parsing of IPv6 host literals in net/url</title>
    <updated>2026-10-03T07:44:04.603327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2026-25679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0315</id>
    <title>certfr-2026-avi-0315 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T07:44:04.603348+00:00</updated>
    <content>certfr-2026-avi-0315</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0315"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691</id>
    <title>Withdrawn: CLEANSTART-2026-AA33691 — Security fixes in calico-fips 3.28.5-r4</title>
    <updated>2026-10-03T07:44:04.603364+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: calico-fips</p>
<p>Package calico-fips version 3.28.5-r4 fixes 5 vulnerabilities: CVE-2026-33186, CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2025-13281</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371781</id>
    <title>EUVD-2026-371781</title>
    <updated>2026-10-03T07:44:04.603385+00:00</updated>
    <content>EUVD-2026-371781</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25679</id>
    <title>fkie_cve-2026-25679</title>
    <updated>2026-10-03T07:44:04.603396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j3gx-2473-5fp8</id>
    <title>GHSA-j3gx-2473-5fp8</title>
    <updated>2026-10-03T07:44:04.603416+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j3gx-2473-5fp8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-25679</id>
    <title>msrc_CVE-2026-25679 — Incorrect parsing of IPv6 host literals in net/url</title>
    <updated>2026-10-03T07:44:04.603429+00:00</updated>
    <content>msrc_CVE-2026-25679</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-25679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1792</id>
    <title>OESA-2026-1792 — golang security update</title>
    <updated>2026-10-03T07:44:04.603444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: golang</p>
<p>.

Security Fix(es):</p>
<p>url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.(CVE-2026-25679)</p>
<p>On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.(CVE-2026-27139)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1792"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10299-1</id>
    <title>openSUSE-SU-2026:10299-1 — go1.26-1.26.1-1.1 on GA media</title>
    <updated>2026-10-03T07:44:04.603466+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.26-1.26.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10299-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10065</id>
    <title>RHSA-2026:10065 — Red Hat Security Advisory: Red Hat Update Infrastructure 5.1 security update</title>
    <updated>2026-10-03T07:44:04.603483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libxslt: Processing web content may disclose sensitive information nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing python: Python: Command-line option injection in webbrowser.open() via crafted URLs libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing net/url: Incorrect parsing of IPv6 host literals in net/url vim: Vim: Arbitrary code execution via 'helpfile' option processing nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module NGINX: NGINX: Denial of Service due to memory corruption via crafted MP4 file vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin vim: Vim: Denial of service and information disclosure via crafted swap file nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files vim: Vim: Arbitrary code execution via command injection in glob() function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10065"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19128</id>
    <title>RLSA-2026:19128 — Important: yggdrasil-worker-package-manager security update</title>
    <updated>2026-10-03T07:44:04.603531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: yggdrasil-worker-package-manager</p>
<p>yggdrasil-worker-package-manager is a simple package manager yggd worker. It knows how to install and remove packages, add, remove, enable and disable repositories, and does rudimentary detection of the host it is running on to guess the package manager to use. It only installs packages that match one of the provided allow-pattern regular expressions.</p>
<p>Security Fix(es):</p>
<p>* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21195-1</id>
    <title>SUSE-SU-2026:21195-1 — Security update for go1.26-openssl</title>
    <updated>2026-10-03T07:44:04.603556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.26-openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21195-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25679</id>
    <title>UBUNTU-CVE-2026-25679</title>
    <updated>2026-10-03T07:44:04.603573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: golang-1.24, Ubuntu:24.04:LTS: golang-1.24, Ubuntu:25.10: golang-1.24, Ubuntu:25.10: golang-1.25, Ubuntu:26.04:LTS: golang-1.24, Ubuntu:26.04:LTS: golang-1.25, Ubuntu:26.04:LTS: golang-1.26</p>
<p>url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25679"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-088</id>
    <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
    <updated>2026-10-03T07:44:04.603605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.</p>
<p>The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25</p>
<p>All other vulnerabilities are to be fixed in the upcoming releases.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0548</id>
    <title>WID-SEC-W-2026-0548 — Golang Go: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T07:44:04.603646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0548"/>
  </entry>
</feed>
