<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T10:19:15.714317+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:47085</id>
    <title>ALSA-2026:47085 — Important: rest security update</title>
    <updated>2026-10-06T10:19:15.954143+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: rest, AlmaLinux:10: rest-devel</p>
<p>The rest packages provide a library for access to the RESTful web services.</p>
<p>Security Fix(es):</p>
<p>* librest: weak random number generation in PKCE implementation (CVE-2026-16615)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:47085"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362657</id>
    <title>EUVD-2026-362657</title>
    <updated>2026-10-06T10:19:15.954204+00:00</updated>
    <content>EUVD-2026-362657</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362657"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-16615</id>
    <title>fkie_cve-2026-16615</title>
    <updated>2026-10-06T10:19:15.954221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-16615"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-223h-642r-2f6v</id>
    <title>GHSA-223h-642r-2f6v</title>
    <updated>2026-10-06T10:19:15.954249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-223h-642r-2f6v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-16615</id>
    <title>msrc_CVE-2026-16615 — Librest: weak random number generation in pkce implementation</title>
    <updated>2026-10-06T10:19:15.954266+00:00</updated>
    <content>msrc_CVE-2026-16615</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-16615"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3974</id>
    <title>OESA-2026-3974 — rest security update</title>
    <updated>2026-10-06T10:19:15.954284+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: rest</p>
<p>This library has been designed to make it easier to access web services that claim to be &amp;amp;quot;RESTful&amp;amp;quot;. It comprises of two parts: the first aims to make it easier to make requests by providing a wrapper around libsoup, the second aids with XML parsing by wrapping libxml2.

Security Fix(es):</p>
<p>A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated &amp;quot;code verifier&amp;quot; lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.(CVE-2026-16615)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3974"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11477-1</id>
    <title>openSUSE-SU-2026:11477-1 — librest-1_0-0-0.10.2-2.1 on GA media</title>
    <updated>2026-10-06T10:19:15.954310+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>librest-1_0-0-0.10.2-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11477-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:62222</id>
    <title>RHSA-2026:62222 — Red Hat Security Advisory: rest security update</title>
    <updated>2026-10-06T10:19:15.954326+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>librest: weak random number generation in PKCE implementation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:62222"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:47085</id>
    <title>RLSA-2026:47085 — Important: rest security update</title>
    <updated>2026-10-06T10:19:15.954341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: rest</p>
<p>The rest packages provide a library for access to the RESTful web services.</p>
<p>Security Fix(es):</p>
<p>* librest: weak random number generation in PKCE implementation (CVE-2026-16615)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:47085"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23564-1</id>
    <title>SUSE-SU-2026:23564-1 — Security update for librest</title>
    <updated>2026-10-06T10:19:15.954362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for librest</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23564-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16615</id>
    <title>UBUNTU-CVE-2026-16615</title>
    <updated>2026-10-06T10:19:15.954377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: librest, Ubuntu:18.04:LTS: librest, Ubuntu:20.04:LTS: librest, Ubuntu:22.04:LTS: librest, Ubuntu:24.04:LTS: librest, Ubuntu:26.04:LTS: librest</p>
<p>A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16615"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2553</id>
    <title>WID-SEC-W-2026-2553 — Red Hat Enterprise Linux (librest, pipewire): Mehrere Schwachstellen</title>
    <updated>2026-10-06T10:19:15.954406+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen und beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2553"/>
  </entry>
</feed>
