<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:05:23.339736+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-gitlab-2026-4398</id>
    <title>BIT-gitlab-2026-4398 — Authorization Bypass Through User-Controlled Key in GitLab</title>
    <updated>2026-10-02T22:05:23.393197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: gitlab</p>
<p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-gitlab-2026-4398"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1086</id>
    <title>certfr-2026-avi-1086 — De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provo…</title>
    <updated>2026-10-02T22:05:23.393253+00:00</updated>
    <content>certfr-2026-avi-1086</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-361127</id>
    <title>EUVD-2026-361127</title>
    <updated>2026-10-02T22:05:23.393274+00:00</updated>
    <content>EUVD-2026-361127</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-361127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4398</id>
    <title>fkie_cve-2026-4398</title>
    <updated>2026-10-02T22:05:23.393286+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-4398"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hpxp-rx7c-457j</id>
    <title>GHSA-hpxp-rx7c-457j</title>
    <updated>2026-10-02T22:05:23.393309+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hpxp-rx7c-457j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3029</id>
    <title>WID-SEC-W-2026-3029 — GitLab: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:05:23.393324+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Daten zu manipulieren und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3029"/>
  </entry>
</feed>
