<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T14:39:03.165579+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-av59470</id>
    <title>Withdrawn: CLEANSTART-2026-AV59470 — Security fixes in prometheus-node-exporter 1.12.1-r0</title>
    <updated>2026-10-04T14:39:03.169315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: prometheus-node-exporter</p>
<p>Package prometheus-node-exporter version 1.12.1-r0 fixes 1 vulnerabilities: CVE-2026-28735</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-av59470"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-320131</id>
    <title>EUVD-2026-320131</title>
    <updated>2026-10-04T14:39:03.169364+00:00</updated>
    <content>EUVD-2026-320131</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-320131"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28735</id>
    <title>fkie_cve-2026-28735</title>
    <updated>2026-10-04T14:39:03.169381+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11.x &lt;= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL.. Mattermost Advisory ID: MMSA-2026-00628</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-28735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r5vf-grcx-5vqp</id>
    <title>GHSA-r5vf-grcx-5vqp — Mattermost allows authenticated users to gain access to private repositories</title>
    <updated>2026-10-04T14:39:03.169406+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/mattermost/mattermost-server, Go: github.com/mattermost/mattermost-plugin-github</p>
<p>Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11.x &lt;= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL. Mattermost Advisory ID: MMSA-2026-00628</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r5vf-grcx-5vqp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1173</id>
    <title>WID-SEC-W-2026-1173 — Mattermost: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-04T14:39:03.169430+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Mattermost ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1173"/>
  </entry>
</feed>
