<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:13:47.259601+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-43617</id>
    <title>BELL-CVE-2026-43617</title>
    <updated>2026-10-03T14:13:47.510524+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: rsync, Alpaquita:25: rsync, Alpaquita:stream: rsync</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-43617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336806</id>
    <title>EUVD-2026-336806</title>
    <updated>2026-10-03T14:13:47.510586+00:00</updated>
    <content>EUVD-2026-336806</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336806"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43617</id>
    <title>fkie_cve-2026-43617</title>
    <updated>2026-10-03T14:13:47.510601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-43617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4j4q-473w-9q2r</id>
    <title>GHSA-4j4q-473w-9q2r</title>
    <updated>2026-10-03T14:13:47.510662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4j4q-473w-9q2r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43617</id>
    <title>msrc_CVE-2026-43617 — Rsync &lt; 3.4.3 Authorization Bypass via Hostname Resolution</title>
    <updated>2026-10-03T14:13:47.510693+00:00</updated>
    <content>msrc_CVE-2026-43617</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-43617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10857-1</id>
    <title>openSUSE-SU-2026:10857-1 — rsync-3.4.3-1.1 on GA media</title>
    <updated>2026-10-03T14:13:47.510711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rsync-3.4.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10857-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:2048-1</id>
    <title>SUSE-SU-2026:2048-1 — Security update for rsync</title>
    <updated>2026-10-03T14:13:47.510731+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rsync</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:2048-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43617</id>
    <title>UBUNTU-CVE-2026-43617</title>
    <updated>2026-10-03T14:13:47.510753+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: rsync, Ubuntu:Pro:16.04:LTS: rsync, Ubuntu:Pro:18.04:LTS: rsync, Ubuntu:Pro:20.04:LTS: rsync, Ubuntu:22.04:LTS: rsync, Ubuntu:24.04:LTS: rsync, Ubuntu:25.10: rsync, Ubuntu:26.04:LTS: rsync</p>
<p>Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1611</id>
    <title>WID-SEC-W-2026-1611 — Rsync: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:13:47.510784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um seine Privilegien zu erhöhen, um Informationen offenzulegen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1611"/>
  </entry>
</feed>
