<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:11:15.979646+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T14:11:16.282966+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-pw57640</id>
    <title>Withdrawn: CLEANSTART-2026-PW57640 — Security fixes for CVE-2025-61726, CVE-2025-61728, CVE-2025-61730, CVE-2025-61732, CVE-2025-68119, CVE-2025-68121, CVE-…</title>
    <updated>2026-10-03T14:11:16.283025+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: grafana-alloy-fips</p>
<p>Multiple security vulnerabilities affect the grafana-alloy-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-pw57640"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4427</id>
    <title>fkie_cve-2026-4427</title>
    <updated>2026-10-03T14:11:16.283076+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rejected reason: Duplicate of CVE-2026-32286</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-4427"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x6gf-mpr2-68h6</id>
    <title>Withdrawn: GHSA-x6gf-mpr2-68h6 — Duplicate Advisory: pgproto3: Negative field length panics in DataRow.Decode</title>
    <updated>2026-10-03T14:11:16.283100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Go: github.com/jackc/pgproto3/v2</p>
<p>## Duplicate Advisory</p>
<p>This advisory has been withdrawn because it is a duplicate of GHSA-jqcq-xjh3-6g23. This link is maintained to preserve external references.</p>
<p>## Original Description
A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x6gf-mpr2-68h6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10669-1</id>
    <title>openSUSE-SU-2026:10669-1 — alloy-1.16.0-2.1 on GA media</title>
    <updated>2026-10-03T14:11:16.283126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>alloy-1.16.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10669-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10126</id>
    <title>RHSA-2026:10126 — Red Hat Security Advisory: RHTAS 1.3.4 - Red Hat Trusted Artifact Signer Release</title>
    <updated>2026-10-03T14:11:16.283143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10126"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:22450</id>
    <title>RLSA-2026:22450 — Important: osbuild-composer security update</title>
    <updated>2026-10-03T14:11:16.283160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: osbuild-composer</p>
<p>A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.</p>
<p>Security Fix(es):</p>
<p>* golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728)</p>
<p>* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)</p>
<p>* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)</p>
<p>* crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)</p>
<p>* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)</p>
<p>* github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message (CVE-2026-4427,GHSA-jqcq-xjh3-6g23)</p>
<p>* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)</p>
<p>* github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server (CVE-2026-32286)</p>
<p>* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)</p>
<p>* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)</p>
<p>* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:22450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21793-1</id>
    <title>SUSE-SU-2026:21793-1 — Security update for alloy</title>
    <updated>2026-10-03T14:11:16.283200+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for alloy</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21793-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4427</id>
    <title>Withdrawn: UBUNTU-CVE-2026-4427</title>
    <updated>2026-10-03T14:11:16.283218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:24.04:LTS: golang-github-jackc-pgproto3, Ubuntu:25.10: golang-github-jackc-pgproto3</p>
<p>A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4427"/>
  </entry>
</feed>
