<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:59:18.834593+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-374454</id>
    <title>EUVD-2026-374454</title>
    <updated>2026-10-02T16:59:18.917556+00:00</updated>
    <content>EUVD-2026-374454</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-374454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84470</id>
    <title>fkie_cve-2026-84470</title>
    <updated>2026-10-02T16:59:18.917602+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Ansible Automation Platform's automation-controller (AWX).
The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the
requested instance_groups with only a read-level permission check, whereas the
standard single-job launch path requires use-level permission on the same
field. A principal that holds read (but not use) permission on an instance
group -- for example the built-in read-only System Auditor role -- together
with execute permission on a job template can launch bulk jobs onto instance
groups they are not authorized to use, bypassing execution-placement
isolation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-84470"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xrhp-vf4q-84h8</id>
    <title>GHSA-xrhp-vf4q-84h8</title>
    <updated>2026-10-02T16:59:18.917642+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Ansible Automation Platform's automation-controller (AWX).
The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the
requested instance_groups with only a read-level permission check, whereas the
standard single-job launch path requires use-level permission on the same
field. A principal that holds read (but not use) permission on an instance
group -- for example the built-in read-only System Auditor role -- together
with execute permission on a job template can launch bulk jobs onto instance
groups they are not authorized to use, bypassing execution-placement
isolation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xrhp-vf4q-84h8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71113</id>
    <title>RHSA-2026:71113 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update</title>
    <updated>2026-10-02T16:59:18.917662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Automation-Controller: automation-controller: Kubernetes service account token exfiltration via HashiCorp Vault credential SSRF encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages js-yaml: js-yaml: Denial of Service via crafted YAML documents sqlparse: sqlparse: Denial of Service via inefficient SQL parsing nanoid: nanoid: Denial of Service via negative size input in non-secure module functions gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options gitpython: GitPython: Command Injection via Git option prefix abbreviation postcss: PostCSS: Information disclosure via crafted sourceMappingURL automation-controller: automation-controller-container: automation-controller: Named-URL 404 body oracle enable…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</id>
    <title>WID-SEC-W-2026-3555 — Red Hat Ansible Automation Platform (automation-controller): Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:59:18.917799+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555"/>
  </entry>
</feed>
