<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T21:39:52.337229+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00136</id>
    <title>bdu:2026-00136</title>
    <updated>2026-10-09T21:39:52.421772+00:00</updated>
    <content>bdu:2026-00136</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-260736</id>
    <title>EUVD-2026-260736</title>
    <updated>2026-10-09T21:39:52.421827+00:00</updated>
    <content>EUVD-2026-260736</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-260736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49521</id>
    <title>fkie_cve-2025-49521</title>
    <updated>2026-10-09T21:39:52.421854+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In OpenShift, it can lead to service account token theft.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-49521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g6ph-9xfv-87c2</id>
    <title>GHSA-g6ph-9xfv-87c2</title>
    <updated>2026-10-09T21:39:52.421909+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In OpenShift, it can lead to service account token theft.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g6ph-9xfv-87c2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:9986</id>
    <title>RHSA-2025:9986 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update</title>
    <updated>2026-10-09T21:39:52.421941+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/http: Request smuggling due to acceptance of invalid chunked data in net/http event-driven-ansible: Authenticated Argument Injection in Git URL in EDA Project Creation event-driven-ansible: Template Injection via Git Branch and Refspec in EDA Projects</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:9986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1437</id>
    <title>WID-SEC-W-2025-1437 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-09T21:39:52.421982+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um beliebige Befehle auszuführen, Informationen offenzulegen oder um einen Request-Smuggling Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1437"/>
  </entry>
</feed>
