<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T22:34:30.462319+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967</id>
    <title>certfr-2025-avi-0967 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-09T22:34:30.470710+00:00</updated>
    <content>certfr-2025-avi-0967</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248537</id>
    <title>EUVD-2026-248537</title>
    <updated>2026-10-09T22:34:30.470746+00:00</updated>
    <content>EUVD-2026-248537</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-58266</id>
    <title>fkie_cve-2024-58266</title>
    <updated>2026-10-09T22:34:30.470761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-58266"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r7qv-8r2h-pg27</id>
    <title>GHSA-r7qv-8r2h-pg27 — Multiple issues involving quote API in shlex</title>
    <updated>2026-10-09T22:34:30.470788+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: shlex</p>
<p>## Issue 1: Failure to quote characters</p>
<p>Affected versions of this crate allowed the bytes `{` and `\xa0` to appear unquoted and unescaped in command arguments.</p>
<p>If the output of `quote` or `join` is passed to a shell, then what should be a single command argument could be interpreted as multiple arguments.</p>
<p>This does not *directly* allow arbitrary command execution (you can't inject a command substitution or similar).  But depending on the command you're running, being able to inject multiple arguments where only one is expected could lead to undesired consequences, potentially including arbitrary command execution.</p>
<p>The flaw was corrected in version 1.2.1 by escaping additional characters. Updating to 1.3.0 is recommended, but 1.2.1 offers a more minimal fix if desired.</p>
<p>Workaround: Check for the bytes `{` and `\xa0` in `quote`/`join` input or output.</p>
<p>(Note: `{` is problematic because it is used for glob expansion.  `\xa0` is problematic because it's treated as a word separator in [specific environments][solved-xa0].)</p>
<p>## Issue 2: Dangerous API w.r.t. nul bytes</p>
<p>Version 1.3.0 deprecates the `quote` and `join` APIs in favor of `try_quote` and `try_join`, which behave the same except that they have `Result` return type, returning `Err` if the input contains nul bytes.</p>
<p>Strings containing nul bytes generally cannot be used in Unix command arguments or environment variables, and most shells cannot handle nul bytes even internally.  If you try to pass one anyway, then the resu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r7qv-8r2h-pg27"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-58266</id>
    <title>msrc_CVE-2024-58266 — The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may f…</title>
    <updated>2026-10-09T22:34:30.470835+00:00</updated>
    <content>msrc_CVE-2024-58266</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-58266"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15433-1</id>
    <title>openSUSE-SU-2025:15433-1 — framework-inputmodule-control-0.2.0-3.1 on GA media</title>
    <updated>2026-10-09T22:34:30.470852+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>framework-inputmodule-control-0.2.0-3.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15433-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2024-0006</id>
    <title>RUSTSEC-2024-0006 — Multiple issues involving quote API</title>
    <updated>2026-10-09T22:34:30.470868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: shlex</p>
<p>## Issue 1: Failure to quote characters</p>
<p>Affected versions of this crate allowed the bytes `{` and `\xa0` to appear
unquoted and unescaped in command arguments.</p>
<p>If the output of `quote` or `join` is passed to a shell, then what should be a
single command argument could be interpreted as multiple arguments.</p>
<p>This does not *directly* allow arbitrary command execution (you can't inject a
command substitution or similar).  But depending on the command you're running,
being able to inject multiple arguments where only one is expected could lead
to undesired consequences, potentially including arbitrary command execution.</p>
<p>The flaw was corrected in version 1.2.1 by escaping additional characters.
Updating to 1.3.0 is recommended, but 1.2.1 offers a more minimal fix if
desired.</p>
<p>Workaround: Check for the bytes `{` and `\xa0` in `quote`/`join` input or
output.</p>
<p>(Note: `{` is problematic because it is used for glob expansion.  `\xa0` is
problematic because it's treated as a word separator in [specific
environments][solved-xa0].)</p>
<p>## Issue 2: Dangerous API w.r.t. nul bytes</p>
<p>Version 1.3.0 deprecates the `quote` and `join` APIs in favor of `try_quote`
and `try_join`, which behave the same except that they have `Result` return
type, returning `Err` if the input contains nul bytes.</p>
<p>Strings containing nul bytes generally cannot be used in Unix command arguments
or environment variables, and most shells cannot handle nul bytes even
internally.  If you try to pass one anyway, then the resu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2024-0006"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:20717-1</id>
    <title>SUSE-SU-2025:20717-1 — Security update for rust-keylime</title>
    <updated>2026-10-09T22:34:30.470906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rust-keylime</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:20717-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58266</id>
    <title>UBUNTU-CVE-2024-58266</title>
    <updated>2026-10-09T22:34:30.470921+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: rust-shlex, Ubuntu:22.04:LTS: rust-shlex, Ubuntu:24.04:LTS: rust-shlex, Ubuntu:25.10: rust-shlex, Ubuntu:26.04:LTS: rust-shlex</p>
<p>The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58266"/>
  </entry>
</feed>
