<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:22:30 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:3318 — Important: go-toolset and golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:3318</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-race, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests&lt;/p&gt;
&lt;p&gt;Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.&lt;/p&gt;
&lt;p&gt;The golang packages provide the Go programming language compiler.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-race, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests&lt;/p&gt;
&lt;p&gt;Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.&lt;/p&gt;
&lt;p&gt;The golang packages provide the Go programming language compiler.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:3318</guid>
    </item>
    <item>
      <title>bdu:2023-03471</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03471</link>
      <description>bdu:2023-03471</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03471</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-24540 — CVE-2023-24540 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-24540</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-24540</guid>
    </item>
    <item>
      <title>BIT-golang-2023-24540 — Improper handling of JavaScript whitespace in html/template</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2023-24540</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set &amp;#34;\t\n\f\r\u0020\u2028\u2029&amp;#34; in JavaScript contexts that also contain actions may not be properly sanitized during execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set &amp;#34;\t\n\f\r\u0020\u2028\u2029&amp;#34; in JavaScript contexts that also contain actions may not be properly sanitized during execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2023-24540</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0500 — De multiples vulnérabilités ont été découvertes dans MongoDB. Elles
permettent à un attaquant de provoquer une exécutio…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0500</link>
      <description>certfr-2023-avi-0500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0500</guid>
    </item>
    <item>
      <title>EUVD-2026-211748</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-211748</link>
      <description>EUVD-2026-211748</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-211748</guid>
    </item>
    <item>
      <title>fkie_cve-2023-24540</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-24540</link>
      <description>&lt;p&gt;Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set &amp;#34;\t\n\f\r\u0020\u2028\u2029&amp;#34; in JavaScript contexts that also contain actions may not be properly sanitized during execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set &amp;#34;\t\n\f\r\u0020\u2028\u2029&amp;#34; in JavaScript contexts that also contain actions may not be properly sanitized during execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-24540</guid>
    </item>
    <item>
      <title>GHSA-7qhm-5mxq-x7vp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7qhm-5mxq-x7vp</link>
      <description>&lt;p&gt;Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set &amp;#34;\t\n\f\r\u0020\u2028\u2029&amp;#34; in JavaScript contexts that also contain actions may not be properly sanitized during execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set &amp;#34;\t\n\f\r\u0020\u2028\u2029&amp;#34; in JavaScript contexts that also contain actions may not be properly sanitized during execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7qhm-5mxq-x7vp</guid>
    </item>
    <item>
      <title>gsd-2023-24540</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-24540</link>
      <description>gsd-2023-24540</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-24540</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-24540 — Improper handling of JavaScript whitespace in html/template</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-24540</link>
      <description>msrc_CVE-2023-24540</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-24540</guid>
    </item>
    <item>
      <title>OESA-2023-1294 — golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1294</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: golang, openEuler:20.03-LTS-SP3: golang, openEuler:22.03-LTS: golang, openEuler:22.03-LTS-SP1: golang&lt;/p&gt;
&lt;p&gt;The Go Programming Language.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Templates containing actions in unquoted HTML attributes (e.g. &amp;amp;quot;attr={{.}}&amp;amp;quot;) executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.(CVE-2023-29400)&#13;
&#13;
Angle brackets (&amp;amp;lt;&amp;amp;gt;) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a &amp;amp;apos;/&amp;amp;apos; character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.(CVE-2023-24539)&#13;
&#13;
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set &amp;amp;quot;\t\n\f\r\u0020\u2028\u2029&amp;amp;quot; in JavaScript contexts that also contain actions may not be properly sanitized during execution.(CVE-2023-24540)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: golang, openEuler:20.03-LTS-SP3: golang, openEuler:22.03-LTS: golang, openEuler:22.03-LTS-SP1: golang&lt;/p&gt;
&lt;p&gt;The Go Programming Language.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Templates containing actions in unquoted HTML attributes (e.g. &amp;amp;quot;attr={{.}}&amp;amp;quot;) executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.(CVE-2023-29400)&#13;
&#13;
Angle brackets (&amp;amp;lt;&amp;amp;gt;) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a &amp;amp;apos;/&amp;amp;apos; character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.(CVE-2023-24539)&#13;
&#13;
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set &amp;amp;quot;\t\n\f\r\u0020\u2028\u2029&amp;amp;quot; in JavaScript contexts that also contain actions may not be properly sanitized during execution.(CVE-2023-24540)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1294</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12907-1 — go1.19-1.19.9-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12907-1</link>
      <description>&lt;p&gt;go1.19-1.19.9-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go1.19-1.19.9-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12907-1</guid>
    </item>
    <item>
      <title>RHBA-2023:4275 — Red Hat Bug Fix Advisory: Red Hat Quay v3.8.11 bug fix release</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2023:4275</link>
      <description>&lt;p&gt;golang: net/http: handle server errors after sending GOAWAY golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags golang: net/url: JoinPath does not strip relative path components in all circumstances golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values golang: html/template: improper handling of JavaScript whitespace golang: html/template: improper handling of empty HTML attributes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net/http: handle server errors after sending GOAWAY golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags golang: net/url: JoinPath does not strip relative path components in all circumstances golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values golang: html/template: improper handling of JavaScript whitespace golang: html/template: improper handling of empty HTML attributes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2023:4275</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:2105-2 — Security update for go1.20</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:2105-2</link>
      <description>&lt;p&gt;Security update for go1.20&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.20&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:2105-2</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2023-24540</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-24540</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: golang-1.20, Ubuntu:22.04:LTS: golang-1.20&lt;/p&gt;
&lt;p&gt;Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set &amp;#34;\t\n\f\r\u0020\u2028\u2029&amp;#34; in JavaScript contexts that also contain actions may not be properly sanitized during execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: golang-1.20, Ubuntu:22.04:LTS: golang-1.20&lt;/p&gt;
&lt;p&gt;Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set &amp;#34;\t\n\f\r\u0020\u2028\u2029&amp;#34; in JavaScript contexts that also contain actions may not be properly sanitized during execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-24540</guid>
    </item>
    <item>
      <title>VDE-2023-062 — Phoenix Contact: WIBU-SYSTEMS CodeMeter Runtime vulnerabilities in multiple products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2023-062</link>
      <description>&lt;p&gt;A heap-based buffer overflow caused by libcurl and wrong whitespace character interpretationin Javascript, both used in CodeMeter Runtime affecting multiple products by PHOENIX CONTACT.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-based buffer overflow caused by libcurl and wrong whitespace character interpretationin Javascript, both used in CodeMeter Runtime affecting multiple products by PHOENIX CONTACT.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2023-062</guid>
    </item>
    <item>
      <title>VDE-2024-001 — TRUMPF: Multiple products contain WIBU CodeMeter vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-001</link>
      <description>&lt;p&gt;The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60d) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes these vulnerabilities is available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60d) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes these vulnerabilities is available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-001</guid>
    </item>
    <item>
      <title>VDE-2024-007 — WAGO: WIBU-SYSTEMS CodeMeter Runtime vulnerabilities in multiple products</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-007</link>
      <description>&lt;p&gt;A heap-based buffer overflow caused by libcurl and wrong whitespace character interpretation in Javascript, both used in CodeMeter Runtime affecting multiple products by WAGO. WIBU-SYSTEMS Codemeter is installed by default during e!COCKPIT and WAGO-I/O-Pro (CODESYS 2.3) installations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A heap-based buffer overflow caused by libcurl and wrong whitespace character interpretation in Javascript, both used in CodeMeter Runtime affecting multiple products by WAGO. WIBU-SYSTEMS Codemeter is installed by default during e!COCKPIT and WAGO-I/O-Pro (CODESYS 2.3) installations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-007</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1167 — Gitea: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1167</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Gitea ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1167</guid>
    </item>
  </channel>
</rss>
