<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T05:13:40.086692+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-61732</id>
    <title>CVE-2025-61732 — Potential code smuggling via doc comments in cmd/cgo</title>
    <updated>2026-10-05T05:13:40.153794+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go toolchain cmd/cgo, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions and 23 more</p>
<p>A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-61732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-77fj-vx54-gvh7</id>
    <title>GHSA-77fj-vx54-gvh7 — Go Markdown has an Out-of-bounds Read in SmartypantsRenderer</title>
    <updated>2026-10-05T05:13:40.155787+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gomarkdown/markdown</p>
<p>### Summary</p>
<p>Processing a malformed input containing a `&lt;` character that is not followed by a `&gt;` character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic.</p>
<p>### Details</p>
<p>The `smartLeftAngle()` function in `html/smartypants.go:367-376` performs an out-of-bounds slice operation when processing a `&lt;` character that is not followed by a `&gt;` character anywhere in the remaining text.
https://github.com/gomarkdown/markdown/blob/37c66b85d6ab025ba67a73ba03b7f3ef55859cca/html/smartypants.go#L367-L376
If the length of the slice is lower than its capacity, this leads to an extra byte of data read. If the length equals the capacity, this leads to a panic.</p>
<p>### PoC
```golang
package main</p>
<p>import (
	"bytes"
	"fmt"</p>
<p>"github.com/gomarkdown/markdown/html"
)</p>
<p>func main() {
	src := []byte("&lt;a")</p>
<p>fmt.Printf("Input: %q  (len=%d, cap=%d)\n", src, len(src), cap(src))</p>
<p>var buf bytes.Buffer
	sp := html.NewSmartypantsRenderer(html.Smartypants)
	sp.Process(&amp;buf, src) // panics: slice bounds out of range</p>
<p>fmt.Printf("Output: %q\n", buf.String())
}
```</p>
<p>### Impact
This vulnerability will lead to a Denial of Service / panic on the processing service.</p>
<p>-- The Datadog Security Team</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-77fj-vx54-gvh7"/>
  </entry>
</feed>
