<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:35:35.742569+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:46391</id>
    <title>ALSA-2026:46391 — Important: grafana security, bug fix, and enhancement update</title>
    <updated>2026-10-02T11:35:36.197686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: grafana, AlmaLinux:8: grafana-selinux</p>
<p>Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp; OpenTSDB.</p>
<p>Security Fix(es):</p>
<p>* github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [grafana / almalinux-8.10.z] Remove Lua ExclusiveArch macro for Konflux build (JIRA:AlmaLinux-188279)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:46391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-aq65185</id>
    <title>Withdrawn: CLEANSTART-2026-AQ65185 — Security fixes for CVE-2025-47913, CVE-2025-47914, CVE-2025-58181, CVE-2025-61727, CVE-2025-61729, CVE-2026-1229, CVE-2…</title>
    <updated>2026-10-02T11:35:36.197776+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: terragrunt-fips</p>
<p>Multiple security vulnerabilities affect the terragrunt-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-aq65185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-323552</id>
    <title>EUVD-2026-323552</title>
    <updated>2026-10-02T11:35:36.197806+00:00</updated>
    <content>EUVD-2026-323552</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-323552"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44740</id>
    <title>fkie_cve-2026-44740</title>
    <updated>2026-10-02T11:35:36.197821+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44740"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m3xc-h892-ggx6</id>
    <title>GHSA-m3xc-h892-ggx6 — go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion</title>
    <updated>2026-10-02T11:35:36.197845+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/go-git/go-billy/v5, Go: github.com/go-git/go-billy/v6</p>
<p>### Impact
Multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption.</p>
<p>These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures.</p>
<p>### Patches
Users should upgrade to a patched version in order to mitigate this vulnerability. Versions prior to `v5` are likely to be affected, users are recommended to upgrade to a supported `go-billy` version.</p>
<p>### Credits
Thanks to @faran66 for finding and reporting this issue privately to the go-git project. 🙇</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m3xc-h892-ggx6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10856-1</id>
    <title>openSUSE-SU-2026:10856-1 — rclone-1.74.2-1.1 on GA media</title>
    <updated>2026-10-02T11:35:36.197879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rclone-1.74.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10856-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:32963</id>
    <title>RHSA-2026:32963 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T11:35:36.197909+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation github.com/containerd/containerd: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:32963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:46391</id>
    <title>RLSA-2026:46391 — Important: grafana security, bug fix, and enhancement update</title>
    <updated>2026-10-02T11:35:36.197932+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: grafana</p>
<p>Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp; OpenTSDB.</p>
<p>Security Fix(es):</p>
<p>* github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [grafana / rhel-8.10.z] Remove Lua ExclusiveArch macro for Konflux build (JIRA:Rocky Linux-188279)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:46391"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22157-1</id>
    <title>SUSE-SU-2026:22157-1 — Security update for amazon-ssm-agent</title>
    <updated>2026-10-02T11:35:36.197957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for amazon-ssm-agent</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22157-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44740</id>
    <title>UBUNTU-CVE-2026-44740</title>
    <updated>2026-10-02T11:35:36.197980+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: golang-github-go-git-go-billy, Ubuntu:24.04:LTS: golang-github-go-git-go-billy, Ubuntu:25.10: golang-github-go-git-go-billy, Ubuntu:26.04:LTS: golang-github-go-git-go-billy</p>
<p>Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44740"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2520</id>
    <title>WID-SEC-W-2026-2520 — Red Hat Enterprise Linux (go-billy): Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T11:35:36.198006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2520"/>
  </entry>
</feed>
