<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T06:38:25.130789+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-24786</id>
    <title>CVE-2024-24786 — Infinite loop in JSON unmarshaling in google.golang.org/protobuf</title>
    <updated>2026-10-07T06:38:25.132992+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> google.golang.org/protobuf/encoding/protojson, google.golang.org/protobuf/internal/encoding/json</p>
<p>The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-24786"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6wxm-mpqj-6jpf</id>
    <title>GHSA-6wxm-mpqj-6jpf — Insecure Temporary File usage in github.com/golang/glog</title>
    <updated>2026-10-07T06:38:25.133048+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/golang/glog</p>
<p>When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6wxm-mpqj-6jpf"/>
  </entry>
</feed>
