<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:24:08.576744+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:10135</id>
    <title>ALSA-2026:10135 — Important: buildah security update</title>
    <updated>2026-10-02T14:24:10.144999+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: buildah, AlmaLinux:9: buildah-tests</p>
<p>The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.</p>
<p>Security Fix(es):</p>
<p>* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:10135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556</id>
    <title>certfr-2026-avi-0556 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T14:24:10.145107+00:00</updated>
    <content>certfr-2026-avi-0556</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-aa71310</id>
    <title>Withdrawn: CLEANSTART-2026-AA71310 — Security fixes in spire-server-fips 1.14.5-r0</title>
    <updated>2026-10-02T14:24:10.145130+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: spire-server-fips</p>
<p>Package spire-server-fips version 1.14.5-r0 fixes 3 vulnerabilities: CVE-2026-33816, ghsa-xmrv-pmrh-hhx2, CVE-2026-34986</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-aa71310"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371755</id>
    <title>EUVD-2026-371755</title>
    <updated>2026-10-02T14:24:10.145153+00:00</updated>
    <content>EUVD-2026-371755</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371755"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34986</id>
    <title>fkie_cve-2026-34986</title>
    <updated>2026-10-02T14:24:10.145166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-78h2-9frx-2jm8</id>
    <title>GHSA-78h2-9frx-2jm8 — Go JOSE Panics in JWE decryption</title>
    <updated>2026-10-02T14:24:10.145194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/go-jose/go-jose/v4, Go: github.com/go-jose/go-jose/v3, Go: github.com/go-jose/go-jose</p>
<p>### Impact</p>
<p>Decrypting a JSON Web Encryption (JWE) object will panic if the `alg` field indicates a key wrapping algorithm ([one ending in `KW`](https://pkg.go.dev/github.com/go-jose/go-jose/v4#pkg-constants), with the exception of `A128GCMKW`, `A192GCMKW`, and `A256GCMKW`) and the `encrypted_key` field is empty. The panic happens when `cipher.KeyUnwrap()` in `key_wrap.go` attempts to allocate a slice with a zero or negative length based on the length of the `encrypted_key`.</p>
<p>This code path is reachable from `ParseEncrypted()` / `ParseEncryptedJSON()` / `ParseEncryptedCompact()` followed by `Decrypt()` on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected.</p>
<p>This panic is also reachable by calling `cipher.KeyUnwrap()` directly with any `ciphertext` parameter less than 16 bytes long, but calling this function directly is less common.</p>
<p>Panics can lead to denial of service.</p>
<p>### Fixed In</p>
<p>4.1.4 and v3.0.5</p>
<p>### Workarounds</p>
<p>If the list of `keyAlgorithms` passed to `ParseEncrypted()` / `ParseEncryptedJSON()` / `ParseEncryptedCompact()` does not include key wrapping algorithms (those ending in `KW`), your application is unaffected.</p>
<p>If your application uses key wrapping, you can prevalidate to the JWE objects to ensure the `encrypted_key` field is nonempty. If your application accepts JWE Compact Serialization,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-78h2-9frx-2jm8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3173</id>
    <title>OESA-2026-3173 — buildah security update</title>
    <updated>2026-10-02T14:24:10.145240+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: buildah</p>
<p>The  package provides a command line tool which can be used to * create a working container from scratch or * create a working container from an image as a starting point * mount/umount a working container&amp;amp;apos;s root file system for manipulation * save container&amp;amp;apos;s root file system layer to create a new image * delete a working container or an image

Security Fix(es):</p>
<p>A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.(CVE-2024-9676)</p>
<p>Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10529-1</id>
    <title>openSUSE-SU-2026:10529-1 — tekton-cli-0.44.1-1.1 on GA media</title>
    <updated>2026-10-02T14:24:10.145276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tekton-cli-0.44.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10529-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10125</id>
    <title>RHSA-2026:10125 — Red Hat Security Advisory: RHTAS 1.3.4 - Red Hat Trusted Artifact Signer Release</title>
    <updated>2026-10-02T14:24:10.145296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10125"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19135</id>
    <title>RLSA-2026:19135 — Important: opentelemetry-collector security update</title>
    <updated>2026-10-02T14:24:10.145324+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: opentelemetry-collector</p>
<p>Collector with the supported components for a Rocky Enterprise Software Foundation build of OpenTelemetry</p>
<p>Security Fix(es):</p>
<p>* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)</p>
<p>* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)</p>
<p>* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)</p>
<p>* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)</p>
<p>* crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)</p>
<p>* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)</p>
<p>* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)</p>
<p>* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:1935-1</id>
    <title>SUSE-SU-2026:1935-1 — Security update for google-cloud-sap-agent</title>
    <updated>2026-10-02T14:24:10.145355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for google-cloud-sap-agent</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:1935-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34986</id>
    <title>UBUNTU-CVE-2026-34986</title>
    <updated>2026-10-02T14:24:10.145423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: golang-gopkg-square-go-jose.v2, Ubuntu:22.04:LTS: golang-gopkg-square-go-jose.v2, Ubuntu:24.04:LTS: golang-github-go-jose-go-jose, Ubuntu:24.04:LTS: golang-gopkg-square-go-jose.v2, Ubuntu:25.10: golang-github-go-jose-go-jose, Ubuntu:25.10: golang-github-go-jose-go-jose.v3, Ubuntu:25.10: golang-gopkg-square-go-jose.v2, Ubuntu:26.04:LTS: golang-github-go-jose-go-jose.v3, Ubuntu:26.04:LTS: golang-gopkg-square-go-jose.v2, Ubuntu:Pro:26.04:LTS: golang-github-go-jose-go-jose</p>
<p>Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1268</id>
    <title>WID-SEC-W-2026-1268 — Red Hat Enterprise Linux (go-jose): Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T14:24:10.145477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1268"/>
  </entry>
</feed>
