<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:24:35.879797+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:30851</id>
    <title>ALSA-2026:30851 — Important: perl:5.32 security update</title>
    <updated>2026-10-03T00:24:36.104985+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: perl, AlmaLinux:8: perl-Algorithm-Diff, AlmaLinux:8: perl-Archive-Tar, AlmaLinux:8: perl-Archive-Zip, AlmaLinux:8: perl-Attribute-Handlers, AlmaLinux:8: perl-AutoLoader, AlmaLinux:8: perl-AutoSplit, AlmaLinux:8: perl-B, AlmaLinux:8: perl-Benchmark, AlmaLinux:8: perl-CPAN and 212 more</p>
<p>Perl is a high-level programming language that is commonly used for system administration utilities and web programming.</p>
<p>Security Fix(es):</p>
<p>* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)
  * perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:30851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-42496</id>
    <title>BELL-CVE-2026-42496</title>
    <updated>2026-10-03T00:24:36.105276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: perl, Alpaquita:25: perl, Alpaquita:stream: perl, BellSoft Hardened Containers:23: perl, BellSoft Hardened Containers:25: perl, BellSoft Hardened Containers:stream: perl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-42496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</id>
    <title>certfr-2026-avi-0731 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T00:24:36.105310+00:00</updated>
    <content>certfr-2026-avi-0731</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337240</id>
    <title>EUVD-2026-337240</title>
    <updated>2026-10-03T00:24:36.105329+00:00</updated>
    <content>EUVD-2026-337240</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42496</id>
    <title>fkie_cve-2026-42496</title>
    <updated>2026-10-03T00:24:36.105341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.</p>
<p>_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.</p>
<p>A subsequent open through the extracted name reads or writes the attacker chosen path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8p37-q9qq-hgx8</id>
    <title>GHSA-8p37-q9qq-hgx8</title>
    <updated>2026-10-03T00:24:36.105367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.</p>
<p>_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.</p>
<p>A subsequent open through the extracted name reads or writes the attacker chosen path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8p37-q9qq-hgx8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42496</id>
    <title>msrc_CVE-2026-42496 — Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction dir…</title>
    <updated>2026-10-03T00:24:36.105385+00:00</updated>
    <content>msrc_CVE-2026-42496</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-42496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2678</id>
    <title>OESA-2026-2678 — perl-Archive-Tar security update</title>
    <updated>2026-10-03T00:24:36.105403+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: perl-Archive-Tar, openEuler:24.03-LTS-SP3: perl-Archive-Tar, openEuler:20.03-LTS-SP4: perl-Archive-Tar, openEuler:22.03-LTS-SP4: perl-Archive-Tar</p>
<p>archive::Tar provides an object oriented mechanism for handling tar files. It provides class methods for quick and easy files handling while also allowing for the creation of tar file objects for custom manipulation. If you have the IO::Zlib module installed, Archive::Tar will also support compressed or gzipped tar files.

Security Fix(es):</p>
<p>Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.</p>
<p>_make_special_file() passes the tar header&amp;apos;s linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.</p>
<p>A subsequent open through the extracted name reads or writes the attacker chosen path.(CVE-2026-42496)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:30851</id>
    <title>RHSA-2026:30851 — Red Hat Security Advisory: perl:5.32 security update</title>
    <updated>2026-10-03T00:24:36.105435+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:30851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:30851</id>
    <title>RLSA-2026:30851 — Important: perl:5.32 security update</title>
    <updated>2026-10-03T00:24:36.105457+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: perl, Rocky Linux:8: perl-Algorithm-Diff, Rocky Linux:8: perl-Archive-Zip, Rocky Linux:8: perl-autodie, Rocky Linux:8: perl-bignum, Rocky Linux:8: perl-Carp, Rocky Linux:8: perl-Compress-Bzip2, Rocky Linux:8: perl-Compress-Raw-Bzip2, Rocky Linux:8: perl-Compress-Raw-Lzma, Rocky Linux:8: perl-Compress-Raw-Zlib and 101 more</p>
<p>Perl is a high-level programming language that is commonly used for system administration utilities and web programming.</p>
<p>Security Fix(es):</p>
<p>* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)</p>
<p>* perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:30851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42496</id>
    <title>UBUNTU-CVE-2026-42496</title>
    <updated>2026-10-03T00:24:36.105771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: perl, Ubuntu:Pro:18.04:LTS: perl, Ubuntu:Pro:20.04:LTS: perl, Ubuntu:22.04:LTS: perl, Ubuntu:24.04:LTS: perl, Ubuntu:25.10: perl, Ubuntu:26.04:LTS: perl</p>
<p>Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-088</id>
    <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
    <updated>2026-10-03T00:24:36.105806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.</p>
<p>The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25</p>
<p>All other vulnerabilities are to be fixed in the upcoming releases.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2666</id>
    <title>WID-SEC-W-2026-2666 — cPanel cPanel/WHM (Archive-Tar): Mehrere Schwachstellen ermöglichen Manipulation von Dateien</title>
    <updated>2026-10-03T00:24:36.105857+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in cPanel cPanel/WHM ausnutzen, um vertrauliche Informationen preiszugeben oder Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2666"/>
  </entry>
</feed>
