<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:40:16.671849+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-45571</id>
    <title>BELL-CVE-2026-45571</title>
    <updated>2026-10-03T08:40:16.817748+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: grype, Alpaquita:stream: osv-scanner</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-45571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ba39475</id>
    <title>Withdrawn: CLEANSTART-2026-BA39475 — Security fixes in external-secrets-fips 0.17.0-r2</title>
    <updated>2026-10-03T08:40:16.817814+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: external-secrets-fips</p>
<p>Package external-secrets-fips version 0.17.0-r2 fixes 75 vulnerabilities: CVE-2026-39820, CVE-2026-25679, CVE-2025-61726, CVE-2026-27143, CVE-2025-68121...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ba39475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322128</id>
    <title>EUVD-2026-322128</title>
    <updated>2026-10-03T08:40:16.817853+00:00</updated>
    <content>EUVD-2026-322128</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45571</id>
    <title>fkie_cve-2026-45571</title>
    <updated>2026-10-03T08:40:16.817881+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-crhj-59gh-8x96</id>
    <title>GHSA-crhj-59gh-8x96 — go-git: Crafted repositories may modify main and submodule .git directories</title>
    <updated>2026-10-03T08:40:16.817908+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/go-git/go-git/v5, Go: github.com/go-git/go-git/v6, Go: github.com/go-git/go-git</p>
<p>### Impact
A path validation issue in `go-git` could allow crafted repository data to affect files outside the intended checkout target, including the repository's `.git` directory.</p>
<p>These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. Some attack vectors were platform-specific: certain payloads affected only Windows users, others affected only macOS users, and some applied across all supported platforms.</p>
<p>Using non-descendant `go-billy` filesystem instances, or different filesystem types, for the `Storer` and `Worktree` may provide some isolation against `.git` directory manipulation. For example, users that store the `.git` directory through `memfs` while using `osfs` for the worktree are not affected by this vulnerability in the main repository, because repository metadata is not materialized inside the worktree filesystem.</p>
<p>However, this isolation does not necessarily apply when the repository contains submodules, since submodule dotgit directories may still be represented or materialized within the worktree context.</p>
<p>It is important to note that exploitation requires a maliciously crafted repository payload. Users should always exercise caution when interacting with repositories or Git servers they do not trust.</p>
<p>### Patches
Users should upgrade to a patched version in order to mitigate this vulnerability. Versions prior to `v5` are likely to be affected, users are recommended to upgrade to a sup…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-crhj-59gh-8x96"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-45571</id>
    <title>msrc_CVE-2026-45571 — go-git: Crafted repositories may modify main and submodule .git directories</title>
    <updated>2026-10-03T08:40:16.817953+00:00</updated>
    <content>msrc_CVE-2026-45571</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-45571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10831-1</id>
    <title>openSUSE-SU-2026:10831-1 — flux2-cli-2.8.8-1.1 on GA media</title>
    <updated>2026-10-03T08:40:16.817972+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>flux2-cli-2.8.8-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10831-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:37387</id>
    <title>RHSA-2026:37387 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.0 security, enhancement &amp; bug fix update</title>
    <updated>2026-10-03T08:40:16.817988+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/containerd/containerd: containerd local privilege escalation containerd: containerd has an integer overflow in User ID handling runc: runc can be tricked into creating empty files/directories on host noobaa-core: Excessive permissions of /etc could lead to escalation of privilege in the noobaa-core container go-git: argument injection via the URL field go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects github.com/moby/moby: Moby's Firewalld reload removes bridge network isolation github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation github.com/sigstore/rekor: Rekor denial of service github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:37387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45571</id>
    <title>UBUNTU-CVE-2026-45571</title>
    <updated>2026-10-03T08:40:16.818080+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: golang-github-go-git-go-git, Ubuntu:Pro:24.04:LTS: golang-github-go-git-go-git, Ubuntu:25.10: golang-github-go-git-go-git, Ubuntu:Pro:26.04:LTS: golang-github-go-git-go-git</p>
<p>go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-45571"/>
  </entry>
</feed>
