<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:28:44.474723+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0540</id>
    <title>certfr-2026-avi-0540 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu Gemfire. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T23:28:45.071568+00:00</updated>
    <content>certfr-2026-avi-0540</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad69953</id>
    <title>Withdrawn: CLEANSTART-2026-AD69953 — Security fixes in argo-cd-fips 3.1.14-r0</title>
    <updated>2026-10-02T23:28:45.071638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: argo-cd-fips</p>
<p>Package argo-cd-fips version 3.1.14-r0 fixes 14 vulnerabilities: ghsa-mh2q-q3fh-2475, ghsa-p77j-4mvh-x3m3, ghsa-pc3f-x583-g7j2, ghsa-78h2-9frx-2jm8, ghsa-hfvc-g4fc-pqhx...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ad69953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-365483</id>
    <title>EUVD-2026-365483</title>
    <updated>2026-10-02T23:28:45.071675+00:00</updated>
    <content>EUVD-2026-365483</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-365483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39883</id>
    <title>fkie_cve-2026-39883</title>
    <updated>2026-10-02T23:28:45.071689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hfvc-g4fc-pqhx</id>
    <title>GHSA-hfvc-g4fc-pqhx — opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking</title>
    <updated>2026-10-02T23:28:45.071713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: go.opentelemetry.io/otel/sdk</p>
<p>## Summary</p>
<p>The fix for GHSA-9h8m-3fm2-qjrq (CVE-2026-24051) changed the Darwin `ioreg` command to use an absolute path but left the BSD `kenv` command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms.</p>
<p>## Root Cause</p>
<p>`sdk/resource/host_id.go` line 42:</p>
<p>if result, err := r.execCommand("kenv", "-q", "smbios.system.uuid"); err == nil {</p>
<p>Compare with the fixed Darwin path at line 58:</p>
<p>result, err := r.execCommand("/usr/sbin/ioreg", "-rd1", "-c", "IOPlatformExpertDevice")</p>
<p>The `execCommand` helper at `sdk/resource/host_id_exec.go` uses `exec.Command(name, arg...)` which searches `$PATH` when the command name contains no path separator.</p>
<p>Affected platforms (per build tag in `host_id_bsd.go:4`): DragonFly BSD, FreeBSD, NetBSD, OpenBSD, Solaris.</p>
<p>The `kenv` path is reached when `/etc/hostid` does not exist (line 38-40), which is common on FreeBSD systems.</p>
<p>## Attack</p>
<p>1. Attacker has local access to a system running a Go application that imports `go.opentelemetry.io/otel/sdk`
2. Attacker places a malicious `kenv` binary earlier in `$PATH`
3. Application initializes OpenTelemetry resource detection at startup
4. `hostIDReaderBSD.read()` calls `exec.Command("kenv", ...)` which resolves to the malicious binary
5. Arbitrary code executes in the context of the application</p>
<p>Same attack vector and impact as CVE-2026-24051.</p>
<p>## Suggested Fix</p>
<p>Use the absolute path:</p>
<p>if result, err := r.execCommand("/bin/kenv", "-q", "smbios.system.uuid"); e…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hfvc-g4fc-pqhx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11173-1</id>
    <title>openSUSE-SU-2026:11173-1 — etcd-3.6.13-1.1 on GA media</title>
    <updated>2026-10-02T23:28:45.071761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>etcd-3.6.13-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11173-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:26254</id>
    <title>RHSA-2026:26254 — Red Hat Security Advisory: Assisted Installer RHEL 9 components for Multicluster Engine for Kubernetes 2.8.8</title>
    <updated>2026-10-02T23:28:45.071780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:26254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39883</id>
    <title>UBUNTU-CVE-2026-39883</title>
    <updated>2026-10-02T23:28:45.071799+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: golang-opentelemetry-otel, Ubuntu:24.04:LTS: golang-opentelemetry-otel, Ubuntu:25.10: golang-opentelemetry-otel, Ubuntu:26.04:LTS: golang-opentelemetry-otel</p>
<p>OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2929</id>
    <title>WID-SEC-W-2026-2929 — Splunk Splunk Enterprise: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:28:45.071831+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise ausnutzen, um beliebigen Code auszuführen, Berechtigungen zu erweitern, Sicherheitsmaßnahmen zu umgehen, SQL-Injection-, serverseitige Request-Forgery- und Cross-Site-Scripting-Angriffe durchzuführen, sensible Informationen offenzulegen oder zu manipulieren, Denial-of-Service-Zustände auszulösen oder andere, nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2929"/>
  </entry>
</feed>
