<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 02:36:52 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:2562 — Important: golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:2562</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests&lt;/p&gt;
&lt;p&gt;The golang packages provide the Go programming language compiler.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
* golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)
* golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect (CVE-2023-45289)
* golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783)
* golang: net/mail: comments in display names are incorrectly handled (CVE-2024-24784)
* golang: html/template: errors returned from MarshalJSON methods may break template escaping (CVE-2024-24785)
* golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests&lt;/p&gt;
&lt;p&gt;The golang packages provide the Go programming language compiler.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
* golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)
* golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect (CVE-2023-45289)
* golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783)
* golang: net/mail: comments in display names are incorrectly handled (CVE-2024-24784)
* golang: html/template: errors returned from MarshalJSON methods may break template escaping (CVE-2024-24785)
* golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:2562</guid>
    </item>
    <item>
      <title>bdu:2024-03248</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-03248</link>
      <description>bdu:2024-03248</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-03248</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-24785</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-24785</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-24785</guid>
    </item>
    <item>
      <title>BIT-golang-2024-24785 — Errors returned from JSON marshaling may break template escaping in html/template</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2024-24785</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2024-24785</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0646 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</link>
      <description>certfr-2024-avi-0646</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</guid>
    </item>
    <item>
      <title>EUVD-2026-222706</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-222706</link>
      <description>EUVD-2026-222706</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-222706</guid>
    </item>
    <item>
      <title>fkie_cve-2024-24785</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-24785</link>
      <description>&lt;p&gt;If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-24785</guid>
    </item>
    <item>
      <title>GHSA-j6m3-gc37-6r6q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j6m3-gc37-6r6q</link>
      <description>&lt;p&gt;If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j6m3-gc37-6r6q</guid>
    </item>
    <item>
      <title>gsd-2024-24785</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-24785</link>
      <description>gsd-2024-24785</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-24785</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-24785 — Errors returned from JSON marshaling may break template escaping in html/template</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-24785</link>
      <description>msrc_CVE-2024-24785</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-24785</guid>
    </item>
    <item>
      <title>OESA-2024-1306 — golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1306</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: golang, openEuler:20.03-LTS-SP4: golang, openEuler:22.03-LTS: golang, openEuler:22.03-LTS-SP1: golang, openEuler:22.03-LTS-SP2: golang, openEuler:22.03-LTS-SP3: golang&lt;/p&gt;
&lt;p&gt;The Go Programming Language.&#13;
&#13;
Security Fix(es):&#13;
&#13;
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as &amp;amp;quot;Authorization&amp;amp;quot; or &amp;amp;quot;Cookie&amp;amp;quot;. For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.(CVE-2023-45289)&#13;
&#13;
When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.(CVE-2023-45290)&#13;
&#13;
Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.(CVE-2024-24783)&#13;
&#13;
If errors returned from MarshalJSON methods contain us…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: golang, openEuler:20.03-LTS-SP4: golang, openEuler:22.03-LTS: golang, openEuler:22.03-LTS-SP1: golang, openEuler:22.03-LTS-SP2: golang, openEuler:22.03-LTS-SP3: golang&lt;/p&gt;
&lt;p&gt;The Go Programming Language.&#13;
&#13;
Security Fix(es):&#13;
&#13;
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as &amp;amp;quot;Authorization&amp;amp;quot; or &amp;amp;quot;Cookie&amp;amp;quot;. For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.(CVE-2023-45289)&#13;
&#13;
When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.(CVE-2023-45290)&#13;
&#13;
Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.(CVE-2024-24783)&#13;
&#13;
If errors returned from MarshalJSON methods contain us…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1306</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13752-1 — go1.22-1.22.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13752-1</link>
      <description>&lt;p&gt;go1.22-1.22.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go1.22-1.22.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13752-1</guid>
    </item>
    <item>
      <title>RHSA-2024:0041 — Red Hat Security Advisory: OpenShift Container Platform 4.16.0 bug fix and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0041</link>
      <description>&lt;p&gt;helm: shows secrets with --dry-run option in clear text opentelemetry: DoS vulnerability in otelhttp golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics ssh: Prefix truncation attack on Binary Packet Protocol (BPP) go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients coredns: CD bit response is cached and served later quic-go: memory exhaustion attack against QUIC&amp;#39;s connection ID mechanism golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm golang: net/mail: comments in display names are incorrectly handled golang: html/template: errors returned from MarshalJSON methods may break template escaping golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON cloudevents/sdk-go: usage of WithRoundTripper to create a Client leaks credentials jose: resource exhaustion jose-go: improper handling of highly compressed data follow-redirects: Possible credential leak webpack-dev-middleware: lack of URL validation may lead to file leak&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;helm: shows secrets with --dry-run option in clear text opentelemetry: DoS vulnerability in otelhttp golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics ssh: Prefix truncation attack on Binary Packet Protocol (BPP) go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients coredns: CD bit response is cached and served later quic-go: memory exhaustion attack against QUIC&amp;#39;s connection ID mechanism golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm golang: net/mail: comments in display names are incorrectly handled golang: html/template: errors returned from MarshalJSON methods may break template escaping golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON cloudevents/sdk-go: usage of WithRoundTripper to create a Client leaks credentials jose: resource exhaustion jose-go: improper handling of highly compressed data follow-redirects: Possible credential leak webpack-dev-middleware: lack of URL validation may lead to file leak&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0041</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:0800-1 — Security update for go1.21</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:0800-1</link>
      <description>&lt;p&gt;Security update for go1.21&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.21&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:0800-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-24785</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24785</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 10 more&lt;/p&gt;
&lt;p&gt;If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 10 more&lt;/p&gt;
&lt;p&gt;If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24785</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0560 — Golang Go: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0560</link>
      <description>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um beliebigen Code auszuführen oder um Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um beliebigen Code auszuführen oder um Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0560</guid>
    </item>
  </channel>
</rss>
