<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T05:53:10.051900+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1169</id>
    <title>certfr-2026-avi-1169 — De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de prov…</title>
    <updated>2026-10-04T05:53:10.164650+00:00</updated>
    <content>certfr-2026-avi-1169</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1169"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366594</id>
    <title>EUVD-2026-366594</title>
    <updated>2026-10-04T05:53:10.164691+00:00</updated>
    <content>EUVD-2026-366594</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366594"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-88030</id>
    <title>fkie_cve-2026-88030</title>
    <updated>2026-10-04T05:53:10.164708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-88030"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4ww7-gqv6-mffc</id>
    <title>GHSA-4ww7-gqv6-mffc</title>
    <updated>2026-10-04T05:53:10.164739+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4ww7-gqv6-mffc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:73519</id>
    <title>RHSA-2026:73519 — Red Hat Security Advisory: ruby:2.5 security update</title>
    <updated>2026-10-04T05:53:10.164757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses rubygem-mongo: MongoDB Ruby Driver: Data disclosure and denial of service via query-operator injection</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:73519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:73519</id>
    <title>RLSA-2026:73519 — Important: ruby:2.5 security update</title>
    <updated>2026-10-04T05:53:10.164779+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: rubygem-abrt, Rocky Linux:8: rubygem-bson, Rocky Linux:8: rubygem-bundler, Rocky Linux:8: rubygem-mysql2, Rocky Linux:8: rubygem-pg, Rocky Linux:8: ruby, Rocky Linux:8: rubygem-mongo</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>Security Fix(es):</p>
<p>* resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses (CVE-2026-80212)</p>
<p>* rubygem-mongo: MongoDB Ruby Driver: Data disclosure and denial of service via query-operator injection (CVE-2026-88030)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:73519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-88030</id>
    <title>UBUNTU-CVE-2026-88030</title>
    <updated>2026-10-04T05:53:10.164816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: ruby-mongo, Ubuntu:18.04:LTS: ruby-mongo, Ubuntu:20.04:LTS: ruby-mongo, Ubuntu:22.04:LTS: ruby-mongo, Ubuntu:24.04:LTS: ruby-mongo, Ubuntu:26.04:LTS: ruby-mongo</p>
<p>Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-88030"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3320</id>
    <title>WID-SEC-W-2026-3320 — MongoDB: Mehrere Schwachstellen</title>
    <updated>2026-10-04T05:53:10.164844+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Abfrage- und Zugriffsbeschränkungen zu umgehen, nicht vorgesehene Datensätze oder Dateien auszulesen, zu verändern oder zu löschen sowie unter bestimmten Voraussetzungen MongoDB-Server oder Anwendungen zum Absturz zu bringen und dadurch einen Denial-of-Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3320"/>
  </entry>
</feed>
