<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:55:06.206048+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-44173</id>
    <title>BELL-CVE-2026-44173</title>
    <updated>2026-10-03T19:55:06.310376+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: mariadb, Alpaquita:25: mariadb, Alpaquita:stream: mariadb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-44173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-mariadb-2026-44173</id>
    <title>BIT-mariadb-2026-44173 — MariaDB: FILE privilege was not checked for subqueries in the FROM clause</title>
    <updated>2026-10-03T19:55:06.310442+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: mariadb</p>
<p>MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-mariadb-2026-44173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343637</id>
    <title>EUVD-2026-343637</title>
    <updated>2026-10-03T19:55:06.310471+00:00</updated>
    <content>EUVD-2026-343637</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44173</id>
    <title>fkie_cve-2026-44173</title>
    <updated>2026-10-03T19:55:06.310484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10897-1</id>
    <title>openSUSE-SU-2026:10897-1 — libmariadbd-devel-11.8.7-1.1 on GA media</title>
    <updated>2026-10-03T19:55:06.310508+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libmariadbd-devel-11.8.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10897-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:25143</id>
    <title>RHSA-2026:25143 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T19:55:06.310530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check mariadb: Arbitrary shell command execution via improper sanitization in CONNECT engine mariadb: mbstream: Unauthorized file creation via path traversal mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries urllib3: urllib3: Denial of Service due to excessive HTTP response decompression mariadb: Arbitrary code execution via improper parameter validation during SST mariadb: Arbitrary code execution via global system variable manipulation by a high-privileged user mariadb: MariaDB Server: Arbitrary code execution via wsrep_notify_cmd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:25143"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:33093</id>
    <title>RLSA-2026:33093 — Important: mariadb10.11 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T19:55:06.310558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: mariadb10.11</p>
<p>MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities.</p>
<p>Security Fix(es):</p>
<p>* mariadb: MariaDB Server: Arbitrary code execution via wsrep_notify_cmd (CVE-2026-49261)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Rebase MariaDB 10.11 to 10.11.18 in Rocky Linux10 (JIRA:Rocky Linux-183086)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:33093"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22095-1</id>
    <title>SUSE-SU-2026:22095-1 — Security update for mariadb</title>
    <updated>2026-10-03T19:55:06.310584+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for mariadb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22095-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44173</id>
    <title>UBUNTU-CVE-2026-44173</title>
    <updated>2026-10-03T19:55:06.310605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: mariadb-10.0, Ubuntu:18.04:LTS: mariadb-10.1, Ubuntu:20.04:LTS: mariadb-10.3, Ubuntu:22.04:LTS: mariadb-10.6, Ubuntu:24.04:LTS: mariadb, Ubuntu:25.10: mariadb, Ubuntu:26.04:LTS: mariadb</p>
<p>MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause contained only subqueries. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44173"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1597</id>
    <title>WID-SEC-W-2026-1597 — MariaDB: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T19:55:06.310634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in MariaDB ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1597"/>
  </entry>
</feed>
