<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:47:53.244703+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-39883</id>
    <title>CVE-2026-39883 — OpenTelemetry-Go has an incomplete fix for CVE-2026-24051: BSD kenv command not using absolute path enables PATH hijack…</title>
    <updated>2026-10-03T21:47:53.278978+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> open-telemetry opentelemetry-go, Red Hat Cert Manager support for Red Hat OpenShift release 1.19, Red Hat multicluster engine for Kubernetes 2.8, Red Hat Openshift Data Foundation 4.22, Red Hat OpenShift Workload Availability 0.3, Red Hat OpenShift Workload Availability 0.8</p>
<p>OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-39883"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gcjh-h69q-9w9g</id>
    <title>GHSA-gcjh-h69q-9w9g — cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag</title>
    <updated>2026-10-03T21:47:53.279064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/google/cel-go</p>
<p>The function `ext.NativeTypes(ParseStructTag("json"))` does not honour the `encoding/json` skip directive `json:"-"`. Fields tagged `json:"-"` are registered in the CEL type system under the literal name `"-"` and are readable from any user-submitted CEL expression via `dyn(obj)["-"]`.</p>
<p>Additionally, `newNativeTypes` silently registers every nested struct reachable from the type passed to `NativeTypes`, including types from third-party dependencies the developer never examined.</p>
<p>## Root cause</p>
<p>In `fieldNameByTag`, the helper used by `ParseStructTag("json")` to translate Go struct tags into CEL field names.</p>
<p>See at `ext/native.go:146`:</p>
<p>```go
func fieldNameByTag(structTagToParse string) func(field reflect.StructField) string {
    return func(field reflect.StructField) string {
        tag, found := field.Tag.Lookup(structTagToParse)
        if found {
            splits := strings.Split(tag, ",")
            if len(splits) &gt; 0 {
                // We make the assumption that the leftmost entry in the tag is the name.
                // This seems to be true for most tags that have the concept of a name/key, such as:
                // https://pkg.go.dev/encoding/xml#Marshal
                // https://pkg.go.dev/encoding/json#Marshal
                // https://pkg.go.dev/go.mongodb.org/mongo-driver/bson#hdr-Structs
                // https://pkg.go.dev/go.yaml.in/yaml/v3#Marshal
                name := splits[0]
                return name
            }
        }</p>
<p>re…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gcjh-h69q-9w9g"/>
  </entry>
</feed>
