<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:08:46.154572+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337242</id>
    <title>EUVD-2026-337242</title>
    <updated>2026-10-03T10:08:46.307483+00:00</updated>
    <content>EUVD-2026-337242</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42296</id>
    <title>fkie_cve-2026-42296</title>
    <updated>2026-10-03T10:08:46.307526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod security context, add tolerations to schedule on control-plane nodes, or enable SA token mounting. This defeats the stated purpose of the feature. The practical impact depends on what Kubernetes-level controls are in place. Clusters with PodSecurity admission or OPA/Gatekeeper would independently block some of these (like hostNetwork). Clusters that rely on Argo's Strict mode as the primary enforcement layer are fully exposed. This issue has been patched in versions 3.7.14 and 4.0.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42296"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3775-99mw-8rp4</id>
    <title>GHSA-3775-99mw-8rp4 — Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing…</title>
    <updated>2026-10-03T10:08:46.307575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/argoproj/argo-workflows/v3, Go: github.com/argoproj/argo-workflows/v4</p>
<p>The fix for CVE-2026-31892 (commit 534f4ff) blocks `podSpecPatch` when `templateReferencing: Strict` is active, but doesn't restrict other WorkflowSpec fields that flow through the same merge path and get applied to pods. A user can set `hostNetwork: true`, override `serviceAccountName`, or change `securityContext` on their Workflow while referencing a hardened template -- these survive `JoinWorkflowSpec` and get applied at pod creation.</p>
<p>The check in `setExecWorkflow` gates on `HasPodSpecPatch()` only:</p>
<p>```go
if woc.controller.Config.WorkflowRestrictions.MustUseReference() &amp;&amp; woc.wf.Spec.HasPodSpecPatch() {
```</p>
<p>Everything else passes through. `createWorkflowPod` reads `hostNetwork`, `securityContext`, `serviceAccountName`, `tolerations`, and `automountServiceAccountToken` from the merged spec and applies them directly to the pod.</p>
<p>`JoinWorkflowSpec` constructs the merge target from the user's spec and applies the template as a patch -- user fields take priority. When the template doesn't explicitly set a field like `hostNetwork` (most won't -- `false` is the zero value and gets omitted), the user's `true` survives. For fields like `securityContext` and `serviceAccountName`, the template-level value takes precedence IF the template explicitly sets it. The bypass applies when the template relies on defaults.</p>
<p>Both `Strict` and `Secure` modes are affected. `Secure` stores the merged spec on first submission, so user overrides get baked into the stored spec and subsequent `Mus…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3775-99mw-8rp4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:73987</id>
    <title>RHSA-2026:73987 — Red Hat Security Advisory: RHOAI 3.3.7 - Red Hat OpenShift AI</title>
    <updated>2026-10-03T10:08:46.307634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/url: Memory exhaustion in query parameter parsing in net/url urllib3: urllib3 Streaming API improperly handles highly compressed data nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy keras: Keras: Arbitrary file write via path traversal in archive extraction utilities sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:73987"/>
  </entry>
</feed>
