<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T09:36:33.768956+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-flux-2022-24878</id>
    <title>BIT-flux-2022-24878 — Improper path handling in Kustomization files allows for denial of service</title>
    <updated>2026-10-06T09:36:33.773071+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: flux</p>
<p>Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to cause a Denial of Service at the controller level. Workarounds include automated tooling in the user's CI/CD pipeline to validate `kustomization.yaml` files conform with specific policies. This vulnerability is fixed in kustomize-controller v0.24.0 and included in flux2 v0.29.0. Users are recommended to upgrade.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-flux-2022-24878"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234163</id>
    <title>EUVD-2026-234163</title>
    <updated>2026-10-06T09:36:33.773123+00:00</updated>
    <content>EUVD-2026-234163</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234163"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-24878</id>
    <title>fkie_cve-2022-24878</title>
    <updated>2026-10-06T09:36:33.773139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to cause a Denial of Service at the controller level. Workarounds include automated tooling in the user's CI/CD pipeline to validate `kustomization.yaml` files conform with specific policies. This vulnerability is fixed in kustomize-controller v0.24.0 and included in flux2 v0.29.0. Users are recommended to upgrade.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-24878"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7pwf-jg34-hxwp</id>
    <title>GHSA-7pwf-jg34-hxwp — Improper path handling in Kustomization files allows for denial of service</title>
    <updated>2026-10-06T09:36:33.773163+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/fluxcd/kustomize-controller, Go: github.com/fluxcd/flux2</p>
<p>The kustomize-controller enables the use of Kustomize’s functionality when applying Kubernetes declarative state onto a cluster. A malicious user can use a specially crafted `kustomization.yaml` to cause Denial of Service at controller level.</p>
<p>In multi-tenancy deployments this can lead to multiple tenants not being able to apply their Kustomizations until the malicious `kustomization.yaml` is removed and the controller restarted.</p>
<p>### Impact</p>
<p>Within the affected versions, users with write access to a Flux source are able to craft a malicious `kustomization.yaml` file which causes the controller to enter an endless loop.</p>
<p>### Patches</p>
<p>This vulnerability was fixed in kustomize-controller v0.24.0 and included in flux2 v0.29.0 released on 2022-04-20. The changes introduce better handling of Kustomization files blocking references that could lead to endless loops.</p>
<p>### Credits</p>
<p>The Flux engineering team found and patched this vulnerability.</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory please open an issue in the [flux2 repository](http://github.com/fluxcd/flux2).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7pwf-jg34-hxwp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-24878</id>
    <title>gsd-2022-24878</title>
    <updated>2026-10-06T09:36:33.773201+00:00</updated>
    <content>gsd-2022-24878</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-24878"/>
  </entry>
</feed>
