<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:57:36.526165+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-gj00206</id>
    <title>Withdrawn: CLEANSTART-2026-GJ00206 — Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the…</title>
    <updated>2026-10-03T19:57:36.657001+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: gitea</p>
<p>Multiple security vulnerabilities affect the gitea package. Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-gj00206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-349402</id>
    <title>EUVD-2026-349402</title>
    <updated>2026-10-03T19:57:36.657054+00:00</updated>
    <content>EUVD-2026-349402</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-349402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71557</id>
    <title>fkie_cve-2026-71557</title>
    <updated>2026-10-03T19:57:36.657071+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-71557"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qgq7-7hm3-q39j</id>
    <title>GHSA-qgq7-7hm3-q39j — go-git: Malicious reference names may modify files outside the reference storage</title>
    <updated>2026-10-03T19:57:36.657095+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/go-git/go-git/v5, Go: github.com/go-git/go-git/v6</p>
<p>### Impact
A path traversal issue in `go-git` could allow malicious reference names to access files outside the repository's intended reference storage.</p>
<p>Loose references are stored under `.git/&lt;reference-name&gt;`. The reference name was previously used as a path without verifying that the resolved path remained within the reference storage. A name such as `refs/heads/../../config` could therefore resolve to unrelated repository metadata such as `.git/config` or `.git/HEAD`.</p>
<p>A malicious Git server could advertise such a reference name. The name may also survive refspec mapping; for example, it could be mapped to `refs/remotes/origin/../../config` during a clone or fetch operation.</p>
<p>This vulnerability affects filesystem-backed repositories using the `storage/filesystem` package and its `dotgit` reference storage. Users relying exclusively on the in-memory storage implementation, `storage/memory`, are not affected, because reference names are not resolved as filesystem paths.</p>
<p>Exploitation requires an application using `go-git` with filesystem-backed storage to interact with a malicious Git server or otherwise process attacker-controlled reference names.</p>
<p>### Patches
The issue has been addressed by validating reference names at the `dotgit` storage entry points and rejecting names whose resolved paths could escape the reference storage.</p>
<p>Users of filesystem-backed storage should upgrade to a patched version.</p>
<p>### Workarounds
Applications that exclusively use `storage/memory` ar…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qgq7-7hm3-q39j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-71557</id>
    <title>msrc_CVE-2026-71557 — go-git: Malicious reference names may modify files outside the reference storage</title>
    <updated>2026-10-03T19:57:36.657142+00:00</updated>
    <content>msrc_CVE-2026-71557</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-71557"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11803-1</id>
    <title>openSUSE-SU-2026:11803-1 — alloy-1.19.2-1.1 on GA media</title>
    <updated>2026-10-03T19:57:36.657160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>alloy-1.19.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11803-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:66208</id>
    <title>RHSA-2026:66208 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T19:57:36.657183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution github.com/go-git/go-git: github.com/go-git/go-git/v5: go-git: Unauthorized file modification via directory traversal in reference names</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:66208"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:4286-1</id>
    <title>SUSE-SU-2026:4286-1 — Security update for amazon-ssm-agent</title>
    <updated>2026-10-03T19:57:36.657200+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for amazon-ssm-agent</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:4286-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71557</id>
    <title>UBUNTU-CVE-2026-71557</title>
    <updated>2026-10-03T19:57:36.657216+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: golang-github-go-git-go-git, Ubuntu:Pro:24.04:LTS: golang-github-go-git-go-git, Ubuntu:Pro:26.04:LTS: golang-github-go-git-go-git</p>
<p>go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71557"/>
  </entry>
</feed>
