<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T18:09:25.096796+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335237</id>
    <title>EUVD-2026-335237</title>
    <updated>2026-10-06T18:09:25.151376+00:00</updated>
    <content>EUVD-2026-335237</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335237"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54778</id>
    <title>fkie_cve-2026-54778</title>
    <updated>2026-10-06T18:09:25.151419+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid calls, allowing concurrent connections to attribute one connection's identity to another or crash the host process under contention. This issue is fixed in versions 1.8.1 and 1.9.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q6v9-43v5-jv9q</id>
    <title>GHSA-q6v9-43v5-jv9q — CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution</title>
    <updated>2026-10-06T18:09:25.151458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: CoreWCF.UnixDomainSocket</p>
<p>### Impact
Race condition in POSIX peer identity resolution may attribute one connection’s identity to another (getpwuid/getgrgid non-reentrant) and may crash the host process under contention.</p>
<p>### Patches
Fixed in CoreWCF v1.8.1 and v1.9.1</p>
<p>### Workarounds
Restrict UDS filesystem permissions so that only trusted local users can connect to the socket path. The race still exists but the attacker pool is constrained.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q6v9-43v5-jv9q"/>
  </entry>
</feed>
