<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:54:00.654601+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:60304</id>
    <title>ALSA-2026:60304 — Important: golang security, bug fix, and enhancement update</title>
    <updated>2026-10-02T10:54:02.175175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-race, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests</p>
<p>The golang packages provide the Go programming language compiler.</p>
<p>Security Fix(es):</p>
<p>* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
  * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
  * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
  * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
  * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
  * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Go 1.26 -- maxThreads limit hit in CGO threads blocked on RAND_bytes in FIPS mode (JIRA:AlmaLinux-215845)
  * Update Go to version 1.26.7+1 [almalinux-9.8.z] (JIRA:AlmaLinux-246425)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:60304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-56860</id>
    <title>BELL-CVE-2026-56860</title>
    <updated>2026-10-02T10:54:02.175298+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-56860"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2026-56860</id>
    <title>BIT-golang-2026-56860 — Avoid quadratic complexity in resolvePath in net/url</title>
    <updated>2026-10-02T10:54:02.175330+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2026-56860"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125</id>
    <title>certfr-2026-avi-1125 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T10:54:02.175354+00:00</updated>
    <content>certfr-2026-avi-1125</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1125"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ab16903</id>
    <title>Withdrawn: CLEANSTART-2026-AB16903 — Security fixes in fluent-operator-fips 3.10.0-r2</title>
    <updated>2026-10-02T10:54:02.175372+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: fluent-operator-fips</p>
<p>Package fluent-operator-fips version 3.10.0-r2 fixes 10 vulnerabilities: CVE-2026-56860, CVE-2026-56858, CVE-2026-33818, CVE-2026-46600, CVE-2026-56853...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ab16903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352496</id>
    <title>EUVD-2026-352496</title>
    <updated>2026-10-02T10:54:02.175393+00:00</updated>
    <content>EUVD-2026-352496</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56860</id>
    <title>fkie_cve-2026-56860</title>
    <updated>2026-10-02T10:54:02.175405+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-56860"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-25mv-j2qr-v5jq</id>
    <title>GHSA-25mv-j2qr-v5jq</title>
    <updated>2026-10-02T10:54:02.175426+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-25mv-j2qr-v5jq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-56860</id>
    <title>msrc_CVE-2026-56860 — Avoid quadratic complexity in resolvePath in net/url</title>
    <updated>2026-10-02T10:54:02.175441+00:00</updated>
    <content>msrc_CVE-2026-56860</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-56860"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3716</id>
    <title>OESA-2026-3716 — golang security update</title>
    <updated>2026-10-02T10:54:02.175457+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: golang</p>
<p>.

Security Fix(es):</p>
<p>Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.(CVE-2026-33818)</p>
<p>When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.(CVE-2026-56853)</p>
<p>Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.(CVE-2026-56859)</p>
<p>Previously, resolving relative paths containing parent directory (&amp;apos;..&amp;apos;) segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for &amp;apos;..&amp;apos; segments, eliminating the quadratic time complexity and significantly reducing memory allocations.(CVE-2026-56860)</p>
<p>Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.(CVE-2026-56862)</p>
<p>A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content tha…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3716"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11516-1</id>
    <title>openSUSE-SU-2026:11516-1 — go1.25-1.25.13-1.1 on GA media</title>
    <updated>2026-10-02T10:54:02.175496+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.25-1.25.13-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11516-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:54835</id>
    <title>RHSA-2026:54835 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T10:54:02.175517+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:54835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:60304</id>
    <title>RLSA-2026:60304 — Important: golang security, bug fix, and enhancement update</title>
    <updated>2026-10-02T10:54:02.175543+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: golang</p>
<p>The golang packages provide the Go programming language compiler.</p>
<p>Security Fix(es):</p>
<p>* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)</p>
<p>* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)</p>
<p>* net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)</p>
<p>* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)</p>
<p>* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)</p>
<p>* encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Go 1.26 -- maxThreads limit hit in CGO threads blocked on RAND_bytes in FIPS mode (JIRA:Rocky Linux-215845)</p>
<p>* Update Go to version 1.26.7+1 [rhel-9.8.z] (JIRA:Rocky Linux-246425)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:60304"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23300-1</id>
    <title>SUSE-SU-2026:23300-1 — Security update for go1.25</title>
    <updated>2026-10-02T10:54:02.175573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.25</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23300-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56860</id>
    <title>UBUNTU-CVE-2026-56860</title>
    <updated>2026-10-02T10:54:02.175590+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 23 more</p>
<p>Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-56860"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2850</id>
    <title>WID-SEC-W-2026-2850 — Golang Go: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:54:02.175642+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Denial of Service zu verursachen, ein Cross Site Scripting durchzuführen, Sicherheitsmaßnahmen zu umgehen oder Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2850"/>
  </entry>
</feed>
