<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:13:22.175021+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-7246</id>
    <title>BELL-CVE-2026-7246</title>
    <updated>2026-10-03T03:13:25.887569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: py3-click</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-7246"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-acronym-cve-2026-7246</id>
    <title>BREW-acronym-CVE-2026-7246</title>
    <updated>2026-10-03T03:13:25.887630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: acronym</p>
<p>Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-acronym-cve-2026-7246"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0834</id>
    <title>certfr-2026-avi-0834 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T03:13:25.887656+00:00</updated>
    <content>certfr-2026-avi-0834</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0834"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-du27033</id>
    <title>Withdrawn: CLEANSTART-2026-DU27033 — Security fixes in apache-superset 5.0.0-r8</title>
    <updated>2026-10-03T03:13:25.887675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-superset</p>
<p>Package apache-superset version 5.0.0-r8 fixes 6 vulnerabilities: ghsa-537c-gmf6-5ccf, CVE-2026-34180, ghsa-6v7p-g79w-8964, CVE-2026-57585, CVE-2026-44405...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-du27033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-355255</id>
    <title>EUVD-2026-355255</title>
    <updated>2026-10-03T03:13:25.887697+00:00</updated>
    <content>EUVD-2026-355255</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-355255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-7246</id>
    <title>fkie_cve-2026-7246</title>
    <updated>2026-10-03T03:13:25.887709+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE record description is preserved below:</p>
<p>Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-7246"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-7246</id>
    <title>msrc_CVE-2026-7246 — Pallets Click contains a command injection via Unsanitized Filename "click.edit()"</title>
    <updated>2026-10-03T03:13:25.887739+00:00</updated>
    <content>msrc_CVE-2026-7246</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-7246"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2302</id>
    <title>OESA-2026-2302 — python-click security update</title>
    <updated>2026-10-03T03:13:25.887756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-click</p>
<p>Click is a Python package for creating beautiful command line interfaces in a composable way with as little code as necessary. It&amp;amp;apos;s the &amp;amp;quot;Command Line Interface Creation Kit&amp;amp;quot;. It&amp;amp;apos;s highly configurable but comes with sensible defaults out of the box.

Security Fix(es):</p>
<p>Pallets Click, versions 8.3.2 and below, contains a command injection vulnerability in the click.edit() function. The vulnerability allows attackers to inject arbitrary OS commands through unsanitized filename parameters in the click.edit() function. Attackers can exploit this vulnerability to execute malicious commands from an unprivileged account, potentially leading to complete system compromise.(CVE-2026-7246)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2302"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10760-1</id>
    <title>openSUSE-SU-2026:10760-1 — python311-click-8.3.3-2.1 on GA media</title>
    <updated>2026-10-03T03:13:25.887781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-click-8.3.3-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10760-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2132</id>
    <title>PYSEC-2026-2132</title>
    <updated>2026-10-03T03:13:25.887798+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: click</p>
<p>Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:24761</id>
    <title>RHSA-2026:24761 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update</title>
    <updated>2026-10-03T03:13:25.887815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions github.com/pallets/click: Pallets Click: Arbitrary command execution via command injection in click.edit() minimatch: minimatch: Denial of Service via specially crafted glob patterns minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() node-forge: Forge: Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification node-forge: Forge: Authentication bypass via forged Ed25519 cryptographic signatures node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance Vite: Vite: Information disclosure via WebSocket connection bypasses access control cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:24761"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22254-1</id>
    <title>SUSE-SU-2026:22254-1 — Security update for python-click</title>
    <updated>2026-10-03T03:13:25.887861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-click</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22254-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-7246</id>
    <title>Withdrawn: UBUNTU-CVE-2026-7246</title>
    <updated>2026-10-03T03:13:25.887876+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:16.04:LTS: python-click, Ubuntu:18.04:LTS: python-click, Ubuntu:20.04:LTS: python-click, Ubuntu:22.04:LTS: python-click, Ubuntu:24.04:LTS: python-click, Ubuntu:25.10: python-click, Ubuntu:26.04: python-click</p>
<p>(Pallets Click, versions 8.3.2 and below, contain a command injection v ...)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-7246"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</id>
    <title>WID-SEC-W-2026-3046 — IBM Concert: Mehrere Schwachstellen</title>
    <updated>2026-10-03T03:13:25.887903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046"/>
  </entry>
</feed>
