<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:43:05.847470+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:7383</id>
    <title>ALSA-2026:7383 — Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection</title>
    <updated>2026-10-04T01:43:06.067823+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: cockpit-bridge, AlmaLinux:10: cockpit-doc, AlmaLinux:10: cockpit-packagekit, AlmaLinux:10: cockpit-storaged, AlmaLinux:10: cockpit-system</p>
<p>Cockpit enables users to administer GNU/Linux servers using a web browser. It  
offers network configuration, log inspection, diagnostic reports, SELinux  
troubleshooting, interactive command-line sessions, and more.</p>
<p>Security Fix(es):</p>
<p>* cockpit: ws: be more explicit when handling hostnames on cli (CVE-2026-4631)</p>
<p>For more details about the security issue(s), including the impact, a CVSS  
score, acknowledgments, and other related information, refer to the CVE page(s)  
listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:7383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05259</id>
    <title>bdu:2026-05259</title>
    <updated>2026-10-04T01:43:06.067890+00:00</updated>
    <content>bdu:2026-05259</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-344038</id>
    <title>EUVD-2026-344038</title>
    <updated>2026-10-04T01:43:06.067907+00:00</updated>
    <content>EUVD-2026-344038</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-344038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4631</id>
    <title>fkie_cve-2026-4631</title>
    <updated>2026-10-04T01:43:06.067919+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-4631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rq49-h582-83m7</id>
    <title>GHSA-rq49-h582-83m7</title>
    <updated>2026-10-04T01:43:06.067944+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rq49-h582-83m7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10531-1</id>
    <title>openSUSE-SU-2026:10531-1 — cockpit-360-1.1 on GA media</title>
    <updated>2026-10-04T01:43:06.067962+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cockpit-360-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10531-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:7381</id>
    <title>RHSA-2026:7381 — Red Hat Security Advisory: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection</title>
    <updated>2026-10-04T01:43:06.067979+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cockpit: Cockpit: Unauthenticated remote code execution due to SSH command-line argument injection</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:7381"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21106-1</id>
    <title>SUSE-SU-2026:21106-1 — Security update for cockpit</title>
    <updated>2026-10-04T01:43:06.067995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for cockpit</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21106-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4631</id>
    <title>UBUNTU-CVE-2026-4631</title>
    <updated>2026-10-04T01:43:06.068009+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: cockpit, Ubuntu:20.04:LTS: cockpit, Ubuntu:22.04:LTS: cockpit, Ubuntu:24.04:LTS: cockpit, Ubuntu:25.10: cockpit, Ubuntu:26.04:LTS: cockpit</p>
<p>Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1052</id>
    <title>WID-SEC-W-2026-1052 — Red Hat Enterprise Linux (Cockpit): Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-04T01:43:06.068039+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1052"/>
  </entry>
</feed>
