<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:21:52.215421+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364131</id>
    <title>EUVD-2026-364131</title>
    <updated>2026-10-03T05:21:52.263560+00:00</updated>
    <content>EUVD-2026-364131</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364131"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66786</id>
    <title>fkie_cve-2026-66786</title>
    <updated>2026-10-03T05:21:52.263598+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-66786"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f6r4-g4jr-h7f2</id>
    <title>GHSA-f6r4-g4jr-h7f2</title>
    <updated>2026-10-03T05:21:52.263634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and ipsec.conf directives. This allows an attacker to inject arbitrary configuration parameters or execute commands through leftupdown hooks, leading to remote code execution as root on the gateway node.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f6r4-g4jr-h7f2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:63016</id>
    <title>RHSA-2026:63016 — Red Hat Security Advisory: Submariner v0.24 security fixes and container updates</title>
    <updated>2026-10-03T05:21:52.263652+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering github.com/coredns/coredns: CoreDNS: Denial of Service via crafted UDP datagram with proxyproto plugin submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity submariner-operator: pprof debug endpoint enabled by default on 0.0.0.0:8082 without authentication submariner-operator: Operator ClusterRole grants cluster-wide create/update on all ConfigMaps submariner-operator: Release workflow consumes same-org composite action via mutable @devel branch ref submariner: IPsec PSK secrets file created with default world-readable permissions submariner: submariner: ipsec.conf stanza injection via remote-supplied CableName and Subnets lighthouse: Go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082 lighthouse: Dockerfile build stages use end-of-life Fedora 40 referenced by mutable tag</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:63016"/>
  </entry>
</feed>
