<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:00:20.145508+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556</id>
    <title>certfr-2026-avi-0556 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T11:00:20.446514+00:00</updated>
    <content>certfr-2026-avi-0556</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ly29111</id>
    <title>CLEANSTART-2026-LY29111 — DataRow</title>
    <updated>2026-10-02T11:00:20.446584+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: grafana-alloy</p>
<p>Security vulnerability affects the grafana-alloy package. The DataRow.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ly29111"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366112</id>
    <title>EUVD-2026-366112</title>
    <updated>2026-10-02T11:00:20.446618+00:00</updated>
    <content>EUVD-2026-366112</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366112"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32286</id>
    <title>fkie_cve-2026-32286</title>
    <updated>2026-10-02T11:00:20.446632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32286"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jqcq-xjh3-6g23</id>
    <title>GHSA-jqcq-xjh3-6g23 — Denial of service in github.com/jackc/pgproto3/v2</title>
    <updated>2026-10-02T11:00:20.446655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/jackc/pgproto3/v2</p>
<p>The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jqcq-xjh3-6g23"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:11070</id>
    <title>RHSA-2026:11070 — Red Hat Security Advisory: RHACS 4.8.11 security and bug fix update</title>
    <updated>2026-10-02T11:00:20.446675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:11070"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:22450</id>
    <title>RHSA-2026:22450 — Red Hat Security Advisory: osbuild-composer security update</title>
    <updated>2026-10-02T11:00:20.446704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:22450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:22450</id>
    <title>RLSA-2026:22450 — Important: osbuild-composer security update</title>
    <updated>2026-10-02T11:00:20.446737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: osbuild-composer</p>
<p>A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.</p>
<p>Security Fix(es):</p>
<p>* golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728)</p>
<p>* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)</p>
<p>* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)</p>
<p>* crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)</p>
<p>* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)</p>
<p>* github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message (CVE-2026-4427,GHSA-jqcq-xjh3-6g23)</p>
<p>* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)</p>
<p>* github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server (CVE-2026-32286)</p>
<p>* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)</p>
<p>* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)</p>
<p>* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:22450"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32286</id>
    <title>UBUNTU-CVE-2026-32286</title>
    <updated>2026-10-02T11:00:20.446777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: golang-github-jackc-pgproto3, Ubuntu:25.10: golang-github-jackc-pgproto3, Ubuntu:26.04:LTS: golang-github-jackc-pgproto3</p>
<p>The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32286"/>
  </entry>
</feed>
