<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:47:37.770314+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:1762</id>
    <title>ALSA-2022:1762 — Important: container-tools:rhel8 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T10:47:38.018942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more</p>
<p>The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.
Security Fix(es):
* psgo: Privilege escalation in 'podman top' (CVE-2022-1227)
* prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)
* podman: Default inheritable capabilities for linux container should be empty (CVE-2022-27649)
* crun: Default inheritable capabilities for linux container should be empty (CVE-2022-27650)
* buildah: Default inheritable capabilities for linux container should be empty (CVE-2022-27651)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:1762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05475</id>
    <title>bdu:2022-05475</title>
    <updated>2026-10-02T10:47:38.019114+00:00</updated>
    <content>bdu:2022-05475</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0562</id>
    <title>certfr-2025-avi-0562 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T10:47:38.019133+00:00</updated>
    <content>certfr-2025-avi-0562</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0562"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ep15881</id>
    <title>Withdrawn: CLEANSTART-2026-EP15881 — Security fixes in cert-manager-webhook-pdns-fips 2.3.0-r0</title>
    <updated>2026-10-02T10:47:38.019149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cert-manager-webhook-pdns-fips</p>
<p>Package cert-manager-webhook-pdns-fips version 2.3.0-r0 fixes 17 vulnerabilities: CVE-2022-1996, CVE-2023-45142, CVE-2023-25151, CVE-2022-21698, CVE-2022-30636...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ep15881"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234449</id>
    <title>EUVD-2026-234449</title>
    <updated>2026-10-02T10:47:38.019172+00:00</updated>
    <content>EUVD-2026-234449</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234449"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21698</id>
    <title>fkie_cve-2022-21698</title>
    <updated>2026-10-02T10:47:38.019183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods. In order to be affected, an instrumented software must use any of `promhttp.InstrumentHandler*` middleware except `RequestsInFlight`; not filter any specific methods (e.g GET) before middleware; pass metric with `method` label name to our middleware; and not have any firewall/LB/proxy that filters away requests with unknown `method`. client_golang version 1.11.1 contains a patch for this issue. Several workarounds are available, including removing the `method` label name from counter/gauge used in the InstrumentHandler; turning off affected promhttp handlers; adding custom middleware before promhttp handler that will sanitize the request method given by Go http.Request; and using a reverse proxy or web application firewall, configured to only allow a limited set of methods.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-21698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cg3q-j54f-5p7p</id>
    <title>GHSA-cg3q-j54f-5p7p — Uncontrolled Resource Consumption in promhttp</title>
    <updated>2026-10-02T10:47:38.019209+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/prometheus/client_golang</p>
<p>This is the Go client library for Prometheus. It has two separate parts, one for instrumenting application code, and one for creating clients that talk to the Prometheus HTTP API. client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients.</p>
<p>### Impact</p>
<p>HTTP server susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods.</p>
<p>###  Affected Configuration</p>
<p>In order to be affected, an instrumented software must</p>
<p>* Use any of `promhttp.InstrumentHandler*` middleware except `RequestsInFlight`.
* Do not filter any specific methods (e.g GET) before middleware.
* Pass metric with `method` label name to our middleware.
* Not have any firewall/LB/proxy that filters away requests with unknown `method`.</p>
<p>### Patches</p>
<p>* https://github.com/prometheus/client_golang/pull/962
* https://github.com/prometheus/client_golang/pull/987</p>
<p>### Workarounds</p>
<p>If you cannot upgrade to [v1.11.1 or above](https://github.com/prometheus/client_golang/releases/tag/v1.11.1), in order to stop being affected you can:</p>
<p>* Remove `method` label name from counter/gauge you use in the InstrumentHandler.
* Turn off affected promhttp handlers.
* Add custom middleware before promhttp handler that will sanitize the request method given by Go http.Request.
* Use a reverse proxy or web application firewall, configured to o…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cg3q-j54f-5p7p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-21698</id>
    <title>gsd-2022-21698</title>
    <updated>2026-10-02T10:47:38.019263+00:00</updated>
    <content>gsd-2022-21698</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-21698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-21698</id>
    <title>msrc_CVE-2022-21698 — Uncontrolled Resource Consumption in promhttp</title>
    <updated>2026-10-02T10:47:38.019277+00:00</updated>
    <content>msrc_CVE-2022-21698</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-21698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11965-1</id>
    <title>openSUSE-SU-2024:11965-1 — kubeseal-0.17.4-1.1 on GA media</title>
    <updated>2026-10-02T10:47:38.019293+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kubeseal-0.17.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11965-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2022:5876</id>
    <title>RHBA-2022:5876 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.10.26 extras update</title>
    <updated>2026-10-02T10:47:38.019310+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>prometheus/client_golang: Denial of service using InstrumentHandlerCounter</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2022:5876"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2026-2254</id>
    <title>SUSE-EL-9-CLIENT-TOOLS-2026-2254 — Security update 5.0.8 for Multi-Linux Manager Client Tools</title>
    <updated>2026-10-02T10:47:38.019326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update 5.0.8 for Multi-Linux Manager Client Tools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2026-2254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21698</id>
    <title>UBUNTU-CVE-2022-21698</title>
    <updated>2026-10-02T10:47:38.019342+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: golang-github-prometheus-client-golang, Ubuntu:20.04:LTS: golang-github-prometheus-client-golang, Ubuntu:22.04:LTS: golang-github-prometheus-client-golang, Ubuntu:24.04:LTS: golang-github-prometheus-client-golang, Ubuntu:25.10: golang-github-prometheus-client-golang, Ubuntu:26.04:LTS: golang-github-prometheus-client-golang</p>
<p>client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods. In order to be affected, an instrumented software must use any of `promhttp.InstrumentHandler*` middleware except `RequestsInFlight`; not filter any specific methods (e.g GET) before middleware; pass metric with `method` label name to our middleware; and not have any firewall/LB/proxy that filters away requests with unknown `method`. client_golang version 1.11.1 contains a patch for this issue. Several workarounds are available, including removing the `method` label name from counter/gauge used in the InstrumentHandler; turning off affected promhttp handlers; adding custom middleware before promhttp handler that will sanitize the request method given by Go http.Request; and using a reverse proxy or web application firewall, configured to only allow a limited set of methods.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0069</id>
    <title>WID-SEC-W-2022-0069 — Red Hat OpenShift Logging Subsystem: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:47:38.019375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Logging Subsystem ausnutzen, um Sicherheitsmechanismen zu umgehen und um einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0069"/>
  </entry>
</feed>
