<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:28:21.301497+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02407</id>
    <title>bdu:2024-02407</title>
    <updated>2026-10-03T17:28:21.516747+00:00</updated>
    <content>bdu:2024-02407</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02407"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-241906</id>
    <title>EUVD-2026-241906</title>
    <updated>2026-10-03T17:28:21.516789+00:00</updated>
    <content>EUVD-2026-241906</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-241906"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2995</id>
    <title>fkie_cve-2022-2995</title>
    <updated>2026-10-03T17:28:21.516804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-2995"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-phjr-8j92-w5v7</id>
    <title>GHSA-phjr-8j92-w5v7 — CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure</title>
    <updated>2026-10-03T17:28:21.516836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/cri-o/cri-o</p>
<p>Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-phjr-8j92-w5v7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-2995</id>
    <title>gsd-2022-2995</title>
    <updated>2026-10-03T17:28:21.516862+00:00</updated>
    <content>gsd-2022-2995</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-2995"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-2995</id>
    <title>msrc_CVE-2022-2995 — Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclo…</title>
    <updated>2026-10-03T17:28:21.516874+00:00</updated>
    <content>msrc_CVE-2022-2995</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-2995"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1251</id>
    <title>OESA-2024-1251 — cri-o security update</title>
    <updated>2026-10-03T17:28:21.516893+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: cri-o</p>
<p>Open Container Initiative-based implementation of Kubernetes Container Runtime Interface.

Security Fix(es):

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.(CVE-2022-2995)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1251"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7398</id>
    <title>RHSA-2022:7398 — Red Hat Security Advisory: OpenShift Container Platform 4.12.0 packages and security update</title>
    <updated>2026-10-03T17:28:21.516914+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go-yaml: Denial of Service in go-yaml golang: net/http: improper sanitization of Transfer-Encoding header golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters cri-o: incorrect handling of the supplementary groups python-scciclient: missing server certificate verification kubernetes: Unauthorized read of Custom Resources kube-apiserver: Aggregated API server can cause clients to be redirected (SSRF) OpenShift: Missing HTTP Strict Transport Security cri-o: Security regression of CVE-2022-27652 golang: net/http: handle server errors after sending GOAWAY golang: compress/gzip: stack exhaustion in Reader.Read golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service golang: net/url: JoinPath does not strip relative path components in all circumstances golang: regexp/syntax: limit memory used by parsing regexps</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7398"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0111</id>
    <title>WID-SEC-W-2023-0111 — Red Hat OpenShift: Mehrere Schwachstellen</title>
    <updated>2026-10-03T17:28:21.516956+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen und Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0111"/>
  </entry>
</feed>
