<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:17:38.831932+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:67148</id>
    <title>ALSA-2026:67148 — Important: osbuild-composer security update</title>
    <updated>2026-10-03T06:17:39.209703+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: osbuild-composer, AlmaLinux:8: osbuild-composer-core, AlmaLinux:8: osbuild-composer-worker</p>
<p>A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.</p>
<p>Security Fix(es):</p>
<p>* crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)
  * crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
  * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
  * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
  * github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)
  * github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:67148"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-br58082</id>
    <title>Withdrawn: CLEANSTART-2026-BR58082 — Echo is a Go web framework</title>
    <updated>2026-10-03T06:17:39.209797+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: kube-metrics-adapter</p>
<p>Multiple security vulnerabilities affect the kube-metrics-adapter package. Echo is a Go web framework. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-br58082"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330680</id>
    <title>EUVD-2026-330680</title>
    <updated>2026-10-03T06:17:39.209821+00:00</updated>
    <content>EUVD-2026-330680</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330680"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55677</id>
    <title>fkie_cve-2026-55677</title>
    <updated>2026-10-03T06:17:39.209835+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55677"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vfp3-v2gw-7wfq</id>
    <title>GHSA-vfp3-v2gw-7wfq — Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files</title>
    <updated>2026-10-03T06:17:39.209860+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/labstack/echo/v5, Go: github.com/labstack/echo/v4, Go: github.com/labstack/echo</p>
<p>### Summary</p>
<p>Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving `%2F` as-is), while `StaticDirectoryHandler` unescapes `%2F` to `/` before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization.</p>
<p>### Details</p>
<p>**Root cause 1 — `router.go` lines 798-802:**
The router uses `req.URL.RawPath` for route matching when `useEscapedPathForRouting` is false (the default). This means `/admin%2Fsecret.txt` is treated as a single path segment and does NOT match the `/admin/*` route pattern.</p>
<p>```go
if !r.useEscapedPathForRouting &amp;&amp; req.URL.RawPath != "" {
    path = req.URL.RawPath
}
```</p>
<p>**Root cause 2 — `echo.go` lines 559-568:**
`StaticDirectoryHandler` calls `url.PathUnescape()` on the path parameter before opening files. This converts `%2F` back to `/`, resolving `admin/secret.txt` on disk.</p>
<p>```go
if !disablePathUnescaping {
    tmpPath, err := url.PathUnescape(p)
    p = tmpPath
}
name := filepath.ToSlash(filepath.Clean(strings.TrimPrefix(p, "/")))
```</p>
<p>### PoC (Screenshot)
Sample:
&lt;img width="1291" height="970" alt="image" src="https://github.com/user-attachments/assets/0bc58059-3e6d-4678-ab25-a5c79b006738" /&gt;</p>
<p>403:
&lt;img width="526" height="194" alt="image" src="https://github.com/user-attachments/assets/2f55ffdd-87b2-4a1b-8a13-130ebad0f257" /&gt;</p>
<p>Bypass with encoded slash:
&lt;img width="592" height="203" alt="image" src="https…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vfp3-v2gw-7wfq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:44622</id>
    <title>RHSA-2026:44622 — Red Hat Security Advisory: Multicluster Global Hub 1.6.4 security update</title>
    <updated>2026-10-03T06:17:39.209934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default grafana: Grafana: Privilege escalation via dashboard overwrite net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: Integer Overflow in Avro Decoder github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin github.com/containerd/containerd: containerd: Security bypass via Contain…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:44622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:57541</id>
    <title>RHSA-2026:57541 — Red Hat Security Advisory: osbuild-composer security update</title>
    <updated>2026-10-03T06:17:39.209985+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:57541"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:66432</id>
    <title>RLSA-2026:66432 — Important: osbuild-composer security update</title>
    <updated>2026-10-03T06:17:39.210004+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: osbuild-composer</p>
<p>A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.</p>
<p>Security Fix(es):</p>
<p>* golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)</p>
<p>* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)</p>
<p>* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)</p>
<p>* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502)</p>
<p>* github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)</p>
<p>* github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:66432"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55677</id>
    <title>UBUNTU-CVE-2026-55677</title>
    <updated>2026-10-03T06:17:39.210035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: golang-github-labstack-echo.v2, Ubuntu:20.04:LTS: golang-github-labstack-echo.v3, Ubuntu:22.04:LTS: golang-github-labstack-echo, Ubuntu:22.04:LTS: golang-github-labstack-echo.v2, Ubuntu:22.04:LTS: golang-github-labstack-echo.v3, Ubuntu:24.04:LTS: golang-github-labstack-echo, Ubuntu:25.10: golang-github-labstack-echo, Ubuntu:26.04:LTS: golang-github-labstack-echo</p>
<p>Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55677"/>
  </entry>
</feed>
