<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:32:43.847550+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:34357</id>
    <title>ALSA-2026:34357 — Important: opentelemetry-collector security update</title>
    <updated>2026-10-02T17:32:46.480425+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: opentelemetry-collector</p>
<p>Collector with the supported components for a AlmaLinux build of OpenTelemetry</p>
<p>Security Fix(es):</p>
<p>* github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)
  * github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)
  * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
  * golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
  * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
  * crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:34357"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09275</id>
    <title>bdu:2026-09275</title>
    <updated>2026-10-02T17:32:46.480583+00:00</updated>
    <content>bdu:2026-09275</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-27145</id>
    <title>BELL-CVE-2026-27145</title>
    <updated>2026-10-02T17:32:46.480617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-27145"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2026-27145</id>
    <title>BIT-golang-2026-27145 — Inefficient candidate hostname parsing in crypto/x509</title>
    <updated>2026-10-02T17:32:46.480680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2026-27145"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</id>
    <title>certfr-2026-avi-1249 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T17:32:46.480731+00:00</updated>
    <content>certfr-2026-avi-1249</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ag91746</id>
    <title>Withdrawn: CLEANSTART-2026-AG91746 — Security fixes for CVE-2026-25680, CVE-2026-25681, CVE-2026-26958, CVE-2026-27145, CVE-2026-29181, CVE-2026-32952, CVE-…</title>
    <updated>2026-10-02T17:32:46.480764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: dex</p>
<p>Multiple security vulnerabilities affect the dex package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ag91746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371758</id>
    <title>EUVD-2026-371758</title>
    <updated>2026-10-02T17:32:46.480811+00:00</updated>
    <content>EUVD-2026-371758</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371758"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27145</id>
    <title>fkie_cve-2026-27145</title>
    <updated>2026-10-02T17:32:46.480837+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27145"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4279-q6mj-392r</id>
    <title>GHSA-4279-q6mj-392r</title>
    <updated>2026-10-02T17:32:46.480886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4279-q6mj-392r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-27145</id>
    <title>msrc_CVE-2026-27145 — Inefficient candidate hostname parsing in crypto/x509</title>
    <updated>2026-10-02T17:32:46.480923+00:00</updated>
    <content>msrc_CVE-2026-27145</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-27145"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10959-1</id>
    <title>openSUSE-SU-2026:10959-1 — go1.25-1.25.11-1.1 on GA media</title>
    <updated>2026-10-02T17:32:46.480958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.25-1.25.11-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10959-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:23262</id>
    <title>RHSA-2026:23262 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T17:32:46.480997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame net/mail: golang: Go net/mail: Denial of Service via crafted email inputs golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header net/textproto: golang: Golang net/textproto: Misleading error messages via input injection golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:23262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:29981</id>
    <title>RLSA-2026:29981 — Moderate: golang security, bug fix, and enhancement update</title>
    <updated>2026-10-02T17:32:46.481079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: golang</p>
<p>The golang packages provide the Go programming language compiler.</p>
<p>Security Fix(es):</p>
<p>* net/textproto: golang: Golang net/textproto: Misleading error messages via input injection (CVE-2026-42507)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Update Go to version 1.26.4+1 [rhel-9.8.z] (JIRA:Rocky Linux-183350)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:29981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22154-1</id>
    <title>SUSE-SU-2026:22154-1 — Security update for go1.26</title>
    <updated>2026-10-02T17:32:46.481132+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.26</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22154-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27145</id>
    <title>UBUNTU-CVE-2026-27145</title>
    <updated>2026-10-02T17:32:46.481167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: golang-1.24, Ubuntu:24.04:LTS: golang-1.24, Ubuntu:25.10: golang-1.24, Ubuntu:25.10: golang-1.25, Ubuntu:26.04:LTS: golang-1.24, Ubuntu:26.04:LTS: golang-1.25, Ubuntu:26.04:LTS: golang-1.26</p>
<p>(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27145"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1776</id>
    <title>WID-SEC-W-2026-1776 — Golang Go: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:32:46.481231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, um einen Denial of Service durchzuführen, und um falsche Informationen darzustellen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1776"/>
  </entry>
</feed>
