<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T07:50:11.966608+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0986</id>
    <title>certfr-2026-avi-0986 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T07:50:12.352256+00:00</updated>
    <content>certfr-2026-avi-0986</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-aq98798</id>
    <title>Withdrawn: CLEANSTART-2026-AQ98798 — Security fixes for CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-33811, CVE-2026-33814, CVE-2026-39817, CVE-…</title>
    <updated>2026-10-04T07:50:12.352315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: tigera-operator</p>
<p>Multiple security vulnerabilities affect the tigera-operator package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-aq98798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338866</id>
    <title>EUVD-2026-338866</title>
    <updated>2026-10-04T07:50:12.352353+00:00</updated>
    <content>EUVD-2026-338866</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338866"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50151</id>
    <title>fkie_cve-2026-50151</title>
    <updated>2026-10-04T07:50:12.352367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-50151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jxpm-75mh-9fp7</id>
    <title>GHSA-jxpm-75mh-9fp7 — oras-go blob upload vulnerable to credential forwarding via unvalidated Location header</title>
    <updated>2026-10-04T07:50:12.352392+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: oras.land/oras-go/v2</p>
<p>## Summary</p>
<p>oras-go follows a registry-controlled `Location` header during the monolithic blob upload flow and reuses the `Authorization` header from the initial `POST` request for the subsequent `PUT` request. If a malicious registry returns a cross-host `Location`, oras-go can send the caller's credentials to an attacker-controlled endpoint.</p>
<p>## Affected Versions</p>
<p>tested: v2.6.0 (commit 03243809936cce826494b5506f724c6dc11115b1, as-of 2026-01-24)
range: unknown; likely affects earlier v2.x releases that include the same upload flow</p>
<p>## Impact</p>
<p>Credential leak to an attacker-controlled endpoint and client-side ssrf to a cross-host target.</p>
<p>## Affected Component</p>
<p>- `registry/remote/repository.go:878-916` (`blobStore.completePushAfterInitialPost`)</p>
<p>## Reproduction</p>
<p>Attachments include `poc.zip` with a local-only harness (no real registry required). It runs a fake registry server that returns a cross-host `Location` and a second server that records whether it received `Authorization`.</p>
<p>```bash
unzip -q -o poc.zip -d /tmp/poc
cd /tmp/poc/poc-F-ORAS-LOCATION-UPLOAD-001
make canonical
make control
```</p>
<p>## Recommended Fix</p>
<p>- validate `Location` before uploading (scheme + hostname + effective port) against the original request, or require an explicit opt-in allowlist for cross-host upload urls
- never forward `Authorization` when the upload target changes host or scheme</p>
<p>## references</p>
<p>- security policy: https://github.com/oras-project/oras-go/security/policy
- vulnerable code: `reg…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jxpm-75mh-9fp7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11291-1</id>
    <title>openSUSE-SU-2026:11291-1 — helm-4.2.3-2.1 on GA media</title>
    <updated>2026-10-04T07:50:12.352437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>helm-4.2.3-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11291-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:47737</id>
    <title>RHSA-2026:47737 — Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.13.10 security update</title>
    <updated>2026-10-04T07:50:12.352455+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin js-yaml: js-yaml: Denial of Service via crafted YAML documents</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:47737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23456-1</id>
    <title>SUSE-SU-2026:23456-1 — Security update for helm</title>
    <updated>2026-10-04T07:50:12.352494+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for helm</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23456-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50151</id>
    <title>UBUNTU-CVE-2026-50151</title>
    <updated>2026-10-04T07:50:12.352512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: golang-oras-oras-go, Ubuntu:26.04:LTS: golang-oras-oras-go</p>
<p>oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50151"/>
  </entry>
</feed>
