<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T02:06:06.579714+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-363369</id>
    <title>EUVD-2026-363369</title>
    <updated>2026-10-04T02:06:06.652743+00:00</updated>
    <content>EUVD-2026-363369</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-363369"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66785</id>
    <title>fkie_cve-2026-66785</title>
    <updated>2026-10-04T02:06:06.652780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided by the malicious cluster, enabling it to declare arbitrary network ranges. Consequently, all network traffic intended for these arbitrary ranges from peer clusters will be rerouted through the attacker's tunnel, potentially leading to unauthorized information disclosure or network disruption.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-66785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-37mq-728j-5q43</id>
    <title>GHSA-37mq-728j-5q43</title>
    <updated>2026-10-04T02:06:06.652814+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided by the malicious cluster, enabling it to declare arbitrary network ranges. Consequently, all network traffic intended for these arbitrary ranges from peer clusters will be rerouted through the attacker's tunnel, potentially leading to unauthorized information disclosure or network disruption.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-37mq-728j-5q43"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:63016</id>
    <title>RHSA-2026:63016 — Red Hat Security Advisory: Submariner v0.24 security fixes and container updates</title>
    <updated>2026-10-04T02:06:06.652834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering github.com/coredns/coredns: CoreDNS: Denial of Service via crafted UDP datagram with proxyproto plugin submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity submariner-operator: pprof debug endpoint enabled by default on 0.0.0.0:8082 without authentication submariner-operator: Operator ClusterRole grants cluster-wide create/update on all ConfigMaps submariner-operator: Release workflow consumes same-org composite action via mutable @devel branch ref submariner: IPsec PSK secrets file created with default world-readable permissions submariner: submariner: ipsec.conf stanza injection via remote-supplied CableName and Subnets lighthouse: Go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082 lighthouse: Dockerfile build stages use end-of-life Fedora 40 referenced by mutable tag</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:63016"/>
  </entry>
</feed>
