<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:04:48.003844+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:22112</id>
    <title>ALSA-2026:22112 — Important: go-toolset:rhel8 security update</title>
    <updated>2026-10-02T11:04:48.454147+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: delve, AlmaLinux:8: go-toolset, AlmaLinux:8: golang, AlmaLinux:8: golang-bin, AlmaLinux:8: golang-docs, AlmaLinux:8: golang-misc, AlmaLinux:8: golang-race, AlmaLinux:8: golang-src, AlmaLinux:8: golang-tests</p>
<p>Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.</p>
<p>Security Fix(es):</p>
<p>* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
  * cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)
  * html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823)
  * cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819)
  * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814)
  * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
  * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
  * net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2026-39825)
  * cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817)
  * html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826)
  * net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836)</p>
<p>For more details about the security issue(s), including t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:22112"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08060</id>
    <title>bdu:2026-08060</title>
    <updated>2026-10-02T11:04:48.454325+00:00</updated>
    <content>bdu:2026-08060</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08060"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-39825</id>
    <title>BELL-CVE-2026-39825</title>
    <updated>2026-10-02T11:04:48.454347+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-39825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2026-39825</id>
    <title>BIT-golang-2026-39825 — ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil</title>
    <updated>2026-10-02T11:04:48.454375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query "a1=x&amp;a2=x&amp;...&amp;a10000=x&amp;hidden=y" can forward the parameter "hidden=y" while hiding it from the proxy's Rewrite function.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2026-39825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ab44357</id>
    <title>Withdrawn: CLEANSTART-2026-AB44357 — Security fixes in opentofu-fips 1.9.4-r6</title>
    <updated>2026-10-02T11:04:48.454401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: opentofu-fips</p>
<p>Package opentofu-fips version 1.9.4-r6 fixes 13 vulnerabilities: CVE-2026-39820, CVE-2026-42499, CVE-2026-33814, CVE-2026-33811, CVE-2026-39836...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ab44357"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-309269</id>
    <title>EUVD-2026-309269</title>
    <updated>2026-10-02T11:04:48.454422+00:00</updated>
    <content>EUVD-2026-309269</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-309269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39825</id>
    <title>fkie_cve-2026-39825</title>
    <updated>2026-10-02T11:04:48.454433+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query "a1=x&amp;a2=x&amp;...&amp;a10000=x&amp;hidden=y" can forward the parameter "hidden=y" while hiding it from the proxy's Rewrite function.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-39825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h74g-238j-357m</id>
    <title>GHSA-h74g-238j-357m</title>
    <updated>2026-10-02T11:04:48.454459+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query "a1=x&amp;a2=x&amp;...&amp;a10000=x&amp;hidden=y" can forward the parameter "hidden=y" while hiding it from the proxy's Rewrite function.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h74g-238j-357m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-39825</id>
    <title>msrc_CVE-2026-39825 — ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil</title>
    <updated>2026-10-02T11:04:48.454477+00:00</updated>
    <content>msrc_CVE-2026-39825</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-39825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10723-1</id>
    <title>openSUSE-SU-2026:10723-1 — go1.25-1.25.10-1.1 on GA media</title>
    <updated>2026-10-02T11:04:48.454494+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.25-1.25.10-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10723-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:23262</id>
    <title>RHSA-2026:23262 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T11:04:48.454516+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame net/mail: golang: Go net/mail: Denial of Service via crafted email inputs golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header net/textproto: golang: Golang net/textproto: Misleading error messages via input injection golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:23262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:22112</id>
    <title>RLSA-2026:22112 — Important: go-toolset:rhel8 security update</title>
    <updated>2026-10-02T11:04:48.454557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: delve, Rocky Linux:8: golang</p>
<p>Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.</p>
<p>Security Fix(es):</p>
<p>* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)</p>
<p>* cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)</p>
<p>* html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823)</p>
<p>* cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819)</p>
<p>* net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814)</p>
<p>* net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)</p>
<p>* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)</p>
<p>* net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2026-39825)</p>
<p>* cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817)</p>
<p>* html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826)</p>
<p>* net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows (CVE-2026-39836)</p>
<p>For more details about the security issue(s), including the impact, a CVSS…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:22112"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21804-1</id>
    <title>SUSE-SU-2026:21804-1 — Security update for go1.26</title>
    <updated>2026-10-02T11:04:48.454600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.26</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21804-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39825</id>
    <title>UBUNTU-CVE-2026-39825</title>
    <updated>2026-10-02T11:04:48.454621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 26 more</p>
<p>ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query "a1=x&amp;a2=x&amp;...&amp;a10000=x&amp;hidden=y" can forward the parameter "hidden=y" while hiding it from the proxy's Rewrite function.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1437</id>
    <title>WID-SEC-W-2026-1437 — Golang Go: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:04:48.454689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1437"/>
  </entry>
</feed>
