<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:16:08.425779+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07253</id>
    <title>bdu:2026-07253</title>
    <updated>2026-10-02T21:16:08.879380+00:00</updated>
    <content>bdu:2026-07253</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07253"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-32289</id>
    <title>BELL-CVE-2026-32289</title>
    <updated>2026-10-02T21:16:08.879436+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-32289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2026-32289</id>
    <title>BIT-golang-2026-32289 — JsBraceDepth Context Tracking Bugs (XSS) in html/template</title>
    <updated>2026-10-02T21:16:08.879501+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2026-32289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0498</id>
    <title>certfr-2026-avi-0498 — De multiples vulnérabilités ont été découvertes dans Zabbix Agent2. Elles permettent à un attaquant de provoquer un pro…</title>
    <updated>2026-10-02T21:16:08.879530+00:00</updated>
    <content>certfr-2026-avi-0498</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ac01087</id>
    <title>Withdrawn: CLEANSTART-2026-AC01087 — During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cer…</title>
    <updated>2026-10-02T21:16:08.879547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: gitness</p>
<p>Multiple security vulnerabilities affect the gitness package. During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ac01087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290980</id>
    <title>EUVD-2026-290980</title>
    <updated>2026-10-02T21:16:08.879570+00:00</updated>
    <content>EUVD-2026-290980</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290980"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32289</id>
    <title>fkie_cve-2026-32289</title>
    <updated>2026-10-02T21:16:08.879582+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7mr4-xjxg-34g6</id>
    <title>GHSA-7mr4-xjxg-34g6</title>
    <updated>2026-10-02T21:16:08.879605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7mr4-xjxg-34g6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-32289</id>
    <title>msrc_CVE-2026-32289 — JsBraceDepth Context Tracking Bugs (XSS) in html/template</title>
    <updated>2026-10-02T21:16:08.879620+00:00</updated>
    <content>msrc_CVE-2026-32289</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-32289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10514-1</id>
    <title>openSUSE-SU-2026:10514-1 — go1.25-1.25.9-1.1 on GA media</title>
    <updated>2026-10-02T21:16:08.879637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.25-1.25.9-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10514-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:7291</id>
    <title>RHSA-2026:7291 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T21:16:08.879657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>os: os: Information disclosure via path traversal using specially crafted filenames net/http: CrossOriginProtection bypass in net/http golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html net/url: Insufficient validation of bracketed IPv6 hostnames in net/url golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication golang: archive/tar: Unbounded allocation when parsing GNU sparse map encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 golang.org/net/http: Lack of limit when parsing cookies can cause memory exhaustion in net/http crypto/x509: Quadratic complexity when checking name constraints in crypto/x509 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information golang.org/x/net/html: Infinite parsing loop in golang.org/x/net encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem net/textproto: Excessive CPU consumption in Reader.ReadResponse in net/textproto net/mail: Excessive CPU consumption in ParseAddress in net/mail golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs golang: archive/zip: Excessive CPU co…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:7291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21355-1</id>
    <title>SUSE-SU-2026:21355-1 — Security update for go1.25</title>
    <updated>2026-10-02T21:16:08.879735+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.25</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21355-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32289</id>
    <title>UBUNTU-CVE-2026-32289</title>
    <updated>2026-10-02T21:16:08.879755+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 26 more</p>
<p>Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32289"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1006</id>
    <title>WID-SEC-W-2026-1006 — Golang Go: Mehrere Schwachstellen</title>
    <updated>2026-10-02T21:16:08.879818+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um Speicherbeschädigungen zu verursachen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand auszulösen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1006"/>
  </entry>
</feed>
