<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:38:19.496140+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07210</id>
    <title>bdu:2026-07210</title>
    <updated>2026-10-02T13:38:19.645069+00:00</updated>
    <content>bdu:2026-07210</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07210"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-33748</id>
    <title>BELL-CVE-2026-33748</title>
    <updated>2026-10-02T13:38:19.645126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: docker</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-33748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci85082</id>
    <title>CLEANSTART-2026-CI85082 — Security fix for CVE-2026-33748 applied in: docker 29.3.0-r1, docker-compose 5.1.0-r0</title>
    <updated>2026-10-02T13:38:19.645158+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: docker, CleanStart: docker-compose</p>
<p>CVE-2026-33748 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ci85082"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277879</id>
    <title>EUVD-2026-277879</title>
    <updated>2026-10-02T13:38:19.645186+00:00</updated>
    <content>EUVD-2026-277879</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33748</id>
    <title>fkie_cve-2026-33748</title>
    <updated>2026-10-02T13:38:19.645199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4vrq-3vrq-g6gg</id>
    <title>GHSA-4vrq-3vrq-g6gg — BuildKit Git URL subdir component can cause access to restricted files</title>
    <updated>2026-10-02T13:38:19.645224+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/moby/buildkit</p>
<p>### Impact
Insufficient validation of Git URL fragment subdir components (`&lt;url&gt;#&lt;ref&gt;:&lt;subdir&gt;`, [docs](https://docs.docker.com/build/concepts/context/#url-fragments)) may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem.</p>
<p>### Patches
The issue has been fixed in version v0.28.1</p>
<p>### Workarounds
The issue affects only builds that use Git URLs with a subpath component. Avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4vrq-3vrq-g6gg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10651-1</id>
    <title>openSUSE-SU-2026:10651-1 — trivy-0.70.0-1.1 on GA media</title>
    <updated>2026-10-02T13:38:19.645251+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>trivy-0.70.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10651-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10125</id>
    <title>RHSA-2026:10125 — Red Hat Security Advisory: RHTAS 1.3.4 - Red Hat Trusted Artifact Signer Release</title>
    <updated>2026-10-02T13:38:19.645272+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10125"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21851-1</id>
    <title>SUSE-SU-2026:21851-1 — Security update for docker-stable</title>
    <updated>2026-10-02T13:38:19.645307+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for docker-stable</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21851-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33748</id>
    <title>UBUNTU-CVE-2026-33748</title>
    <updated>2026-10-02T13:38:19.645323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:Pro:18.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io-app, Ubuntu:22.04:LTS: docker.io-app, Ubuntu:Pro:22.04:LTS: docker.io, Ubuntu:24.04:LTS: docker.io-app, Ubuntu:Pro:24.04:LTS: docker.io, Ubuntu:25.10: docker.io, Ubuntu:25.10: docker.io-app and 2 more</p>
<p>BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0873</id>
    <title>WID-SEC-W-2026-0873 — docker: Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:38:19.645362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in docker ausnutzen, um Sicherheitsvorkehrungen zu umgehen und Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0873"/>
  </entry>
</feed>
