<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:45:52 +0000</lastBuildDate>
    <item>
      <title>bdu:2021-04872</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-04872</link>
      <description>bdu:2021-04872</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-04872</guid>
    </item>
    <item>
      <title>EUVD-2026-28035</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-28035</link>
      <description>EUVD-2026-28035</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-28035</guid>
    </item>
    <item>
      <title>fkie_cve-2021-32635</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-32635</link>
      <description>&lt;p&gt;Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint. An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container. Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint. The vulnerability is patched in Singularity version 3.7.4. Two possible workarounds exist: Users can only interact with the default remote endpoint, or an installation can have an execution control list configured to restrict execution to containers signed with specific secure keys.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint. An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container. Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint. The vulnerability is patched in Singularity version 3.7.4. Two possible workarounds exist: Users can only interact with the default remote endpoint, or an installation can have an execution control list configured to restrict execution to containers signed with specific secure keys.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-32635</guid>
    </item>
    <item>
      <title>GHSA-5mv9-q7fq-9394 — Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5mv9-q7fq-9394</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/sylabs/singularity&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Due to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint.&lt;/p&gt;
&lt;p&gt;An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container.&lt;/p&gt;
&lt;p&gt;Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;All users should upgrade to Singularity 3.7.4 or later.&lt;/p&gt;
&lt;p&gt;A patch was applied at: https://github.com/sylabs/singularity/commit/d52ae9d13979733c5e987a566fae59ed6f1bf796&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users who only interact with the default remote endpoint are not affected.&lt;/p&gt;
&lt;p&gt;Installations with an execution control list configured to restrict execution to containers signed with specific secure keys are not affected.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;General questions about the impact of the advisory can be asked in the:&lt;/p&gt;
&lt;p&gt;- [SingularityCE Slack Channel](https://singularityce.slack.com)
- [SingularityCE Mailing List](https://groups.google.com/g/singularity-ce)&lt;/p&gt;
&lt;p&gt;Any sensitive security concerns should be directed to: security@sylabs.io&lt;/p&gt;
&lt;p&gt;See our Security Policy here: https://sylabs.io/security-policy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/sylabs/singularity&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Due to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint.&lt;/p&gt;
&lt;p&gt;An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container.&lt;/p&gt;
&lt;p&gt;Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;All users should upgrade to Singularity 3.7.4 or later.&lt;/p&gt;
&lt;p&gt;A patch was applied at: https://github.com/sylabs/singularity/commit/d52ae9d13979733c5e987a566fae59ed6f1bf796&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Users who only interact with the default remote endpoint are not affected.&lt;/p&gt;
&lt;p&gt;Installations with an execution control list configured to restrict execution to containers signed with specific secure keys are not affected.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;General questions about the impact of the advisory can be asked in the:&lt;/p&gt;
&lt;p&gt;- [SingularityCE Slack Channel](https://singularityce.slack.com)
- [SingularityCE Mailing List](https://groups.google.com/g/singularity-ce)&lt;/p&gt;
&lt;p&gt;Any sensitive security concerns should be directed to: security@sylabs.io&lt;/p&gt;
&lt;p&gt;See our Security Policy here: https://sylabs.io/security-policy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5mv9-q7fq-9394</guid>
    </item>
    <item>
      <title>gsd-2021-32635</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-32635</link>
      <description>gsd-2021-32635</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-32635</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11384-1 — singularity-3.8.3-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11384-1</link>
      <description>&lt;p&gt;singularity-3.8.3-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;singularity-3.8.3-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11384-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-32635</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-32635</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: singularity-container, Ubuntu:Pro:24.04:LTS: singularity-container, Ubuntu:25.10: singularity-container, Ubuntu:26.04:LTS: singularity-container&lt;/p&gt;
&lt;p&gt;Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint. An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container. Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint. The vulnerability is patched in Singularity version 3.7.4. Two possible workarounds exist: Users can only interact with the default remote endpoint, or an installation can have an execution control list configured to restrict execution to containers signed with specific secure keys.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: singularity-container, Ubuntu:Pro:24.04:LTS: singularity-container, Ubuntu:25.10: singularity-container, Ubuntu:26.04:LTS: singularity-container&lt;/p&gt;
&lt;p&gt;Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint. An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container. Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint. The vulnerability is patched in Singularity version 3.7.4. Two possible workarounds exist: Users can only interact with the default remote endpoint, or an installation can have an execution control list configured to restrict execution to containers signed with specific secure keys.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-32635</guid>
    </item>
  </channel>
</rss>
