<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:08:32.646062+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:37123</id>
    <title>ALSA-2026:37123 — Important: podman security, bug fix, and enhancement update</title>
    <updated>2026-10-02T16:08:34.273879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: podman, AlmaLinux:9: podman-docker, AlmaLinux:9: podman-plugins, AlmaLinux:9: podman-remote, AlmaLinux:9: podman-tests</p>
<p>The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.</p>
<p>Security Fix(es):</p>
<p>* golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)
  * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)
  * golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)
  * golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)
  * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)
  * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
  * podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* podman does not clean up all files and leaves orphaned files consuming disk space [almalinux-9.8.z] (JIRA:AlmaLinux-173988)
  * [FJ9.8 Bug]: [REG]The "podman-remote save" command fails for rootless users. [almalinux-9.8.z] (JIRA:AlmaLinux-192439)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowled…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:37123"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15282</id>
    <title>bdu:2026-15282</title>
    <updated>2026-10-02T16:08:34.274003+00:00</updated>
    <content>bdu:2026-15282</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15282"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-27136</id>
    <title>BELL-CVE-2026-27136</title>
    <updated>2026-10-02T16:08:34.274022+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: buildah, Alpaquita:23: containerd, Alpaquita:23: podman, Alpaquita:23: runc, Alpaquita:23: skopeo, Alpaquita:25: buildah, Alpaquita:25: containerd, Alpaquita:25: docker-cli-buildx, Alpaquita:25: google-guest-agent, Alpaquita:25: osv-scanner and 20 more</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-27136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</id>
    <title>certfr-2026-avi-0788 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T16:08:34.274075+00:00</updated>
    <content>certfr-2026-avi-0788</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad30368</id>
    <title>Withdrawn: CLEANSTART-2026-AD30368 — Security fixes for CVE-2026-2303, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-39827, CVE-2…</title>
    <updated>2026-10-02T16:08:34.274091+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: weaviate-fips</p>
<p>Multiple security vulnerabilities affect the weaviate-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ad30368"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-320135</id>
    <title>EUVD-2026-320135</title>
    <updated>2026-10-02T16:08:34.274114+00:00</updated>
    <content>EUVD-2026-320135</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-320135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27136</id>
    <title>fkie_cve-2026-27136</title>
    <updated>2026-10-02T16:08:34.274126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m9x8-m34x-fj9q</id>
    <title>GHSA-m9x8-m34x-fj9q</title>
    <updated>2026-10-02T16:08:34.274145+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m9x8-m34x-fj9q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-27136</id>
    <title>msrc_CVE-2026-27136 — Invoking  duplicate attributes can cause XSS in golang.org/x/net/html</title>
    <updated>2026-10-02T16:08:34.274159+00:00</updated>
    <content>msrc_CVE-2026-27136</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-27136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10856-1</id>
    <title>openSUSE-SU-2026:10856-1 — rclone-1.74.2-1.1 on GA media</title>
    <updated>2026-10-02T16:08:34.274175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rclone-1.74.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10856-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:36207</id>
    <title>RHSA-2026:36207 — Red Hat Security Advisory: RHACS 4.11.1 security and bug fix update</title>
    <updated>2026-10-02T16:08:34.274204+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>stackrox: stackrox: Unbounded GraphQL query depth allows authenticated denial of service golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate axios: Axios: Prototype pollution allows information disclosure and request manipulation golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:36207"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:37072</id>
    <title>RLSA-2026:37072 — Important: podman security, bug fix, and enhancement update</title>
    <updated>2026-10-02T16:08:34.274242+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: podman</p>
<p>The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.</p>
<p>Security Fix(es):</p>
<p>* golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)</p>
<p>* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)</p>
<p>* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)</p>
<p>* golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)</p>
<p>* golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)</p>
<p>* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)</p>
<p>* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)</p>
<p>* podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* podman does not clean up all files and leaves orphaned files consuming disk space [rhel-10.2.z] (JIRA:Rocky Linux-173842)</p>
<p>* [FJ10.2 Bug]: [REG]The "podman-remote save" command fails for rootless users. [rhel-10.2.z] (JI…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:37072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22065-1</id>
    <title>SUSE-SU-2026:22065-1 — Security update for elemental-toolkit</title>
    <updated>2026-10-02T16:08:34.274292+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for elemental-toolkit</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22065-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27136</id>
    <title>UBUNTU-CVE-2026-27136</title>
    <updated>2026-10-02T16:08:34.274320+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: golang-golang-x-net-dev, Ubuntu:Pro:18.04:LTS: golang-golang-x-net-dev, Ubuntu:Pro:20.04:LTS: golang-golang-x-net-dev</p>
<p>Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1653</id>
    <title>WID-SEC-W-2026-1653 — Golang Go-Module (Net, Image, Crypto: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:08:34.274342+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um erweiterte Privilegien zu erlangen, Cross-Site-Scripting-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1653"/>
  </entry>
</feed>
