<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:32:22.802712+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15024</id>
    <title>bdu:2026-15024</title>
    <updated>2026-10-02T23:32:22.884048+00:00</updated>
    <content>bdu:2026-15024</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15024"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-370517</id>
    <title>EUVD-2026-370517</title>
    <updated>2026-10-02T23:32:22.884087+00:00</updated>
    <content>EUVD-2026-370517</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-370517"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92960</id>
    <title>fkie_cve-2026-92960</title>
    <updated>2026-10-02T23:32:22.884101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host process DNS resolver globally, redirecting all subsequent host DNS queries through an attacker-controlled resolver.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-92960"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qj2x-7x9q-qgm7</id>
    <title>GHSA-qj2x-7x9q-qgm7</title>
    <updated>2026-10-02T23:32:22.884132+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host process DNS resolver globally, redirecting all subsequent host DNS queries through an attacker-controlled resolver.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qj2x-7x9q-qgm7"/>
  </entry>
</feed>
