<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T18:31:14.044170+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0010</id>
    <title>certfr-2026-avi-0010 — De multiples vulnérabilités ont été découvertes dans Curl. Elles permettent à un attaquant de provoquer une atteinte à…</title>
    <updated>2026-10-06T18:31:14.155801+00:00</updated>
    <content>certfr-2026-avi-0010</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368393</id>
    <title>EUVD-2026-368393</title>
    <updated>2026-10-06T18:31:14.155849+00:00</updated>
    <content>EUVD-2026-368393</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-13034</id>
    <title>fkie_cve-2025-13034</title>
    <updated>2026-10-06T18:31:14.155865+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`
with the curl tool, curl should check the public key of the server certificate
to verify the peer.</p>
<p>This check was skipped in a certain condition that would then make curl allow
the connection without performing the proper check, thus not noticing a
possible impostor. To skip this check, the connection had to be done with QUIC
with ngtcp2 built to use GnuTLS and the user had to explicitly disable the
standard certificate verification.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-13034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9r76-qj98-jfhc</id>
    <title>GHSA-9r76-qj98-jfhc</title>
    <updated>2026-10-06T18:31:14.155900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`
with the curl tool,curl should check the public key of the server certificate
to verify the peer.</p>
<p>This check was skipped in a certain condition that would then make curl allow
the connection without performing the proper check, thus not noticing a
possible impostor. To skip this check, the connection had to be done with QUIC
with ngtcp2 built to use GnuTLS and the user had to explicitly disable the
standard certificate verification.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9r76-qj98-jfhc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-13034</id>
    <title>msrc_CVE-2025-13034 — No QUIC certificate pinning with GnuTLS</title>
    <updated>2026-10-06T18:31:14.155920+00:00</updated>
    <content>msrc_CVE-2025-13034</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-13034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:6893</id>
    <title>RHSA-2026:6893 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-06T18:31:14.155939+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl: libcurl: Curl out of bounds read for cookie path curl: predictable WebSocket mask curl: Curl missing SFTP host verification with wolfSSH backend curl: Public key pinning bypass via QUIC and GnuTLS allows server impersonation curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token curl: libcurl: Improper certificate validation due to cached TLS settings reuse curl: Host verification bypass during SSH transfers curl: libssh key passphrase bypass without agent set curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect curl: curl: Unauthorized access due to improper HTTP proxy connection reuse curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:6893"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-13034</id>
    <title>UBUNTU-CVE-2025-13034</title>
    <updated>2026-10-06T18:31:14.155979+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: curl</p>
<p>When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool, curl should check the public key of the server certificate to verify the peer. This check was skipped in a certain condition that would then make curl allow the connection without performing the proper check, thus not noticing a possible impostor. To skip this check, the connection had to be done with QUIC with ngtcp2 built to use GnuTLS and the user had to explicitly disable the standard certificate verification.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-13034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0030</id>
    <title>WID-SEC-W-2026-0030 — cURL: Mehrere Schwachstellen</title>
    <updated>2026-10-06T18:31:14.156004+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0030"/>
  </entry>
</feed>
