<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:32:26.091671+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-378283</id>
    <title>EUVD-2026-378283</title>
    <updated>2026-10-03T10:32:26.273726+00:00</updated>
    <content>EUVD-2026-378283</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-378283"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73268</id>
    <title>fkie_cve-2026-73268</title>
    <updated>2026-10-03T10:32:26.273845+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6c6p-j4gf-mj2c</id>
    <title>GHSA-6c6p-j4gf-mj2c</title>
    <updated>2026-10-03T10:32:26.273920+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6c6p-j4gf-mj2c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:59556</id>
    <title>RHSA-2026:59556 — Red Hat Security Advisory: multicluster engine for Kubernetes v2.11.6 security update</title>
    <updated>2026-10-03T10:32:26.273956+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token form-data: form-data: Form field override via CRLF injection provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls net/textproto: golang: Golang net/textproto: Misleading error messages via input injection cluster-proxy-addon: cluster-proxy-addon: unauthenticated SSRF to arbitrary managed-cluster services via public Route managedcluster-import-controller: CSR auto-approver does not validate certificate Subject or signerName (spoke→hub cluster-admin) clusterclaims-controller: Confused deputy: tenant-controlled ClusterClaim labels propagated to ManagedCluster, enabling cross-tenant ManagedClusterSet join clusterclaims-controller: ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no local ownership check cluster-curator-controller: cluster-curator-controller: spec.instal…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:59556"/>
  </entry>
</feed>
