<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:39:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-04789</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04789</link>
      <description>bdu:2024-04789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04789</guid>
    </item>
    <item>
      <title>BREW-dstack-CVE-2024-35255 — Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/brew-dstack-cve-2024-35255</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: dstack&lt;/p&gt;
&lt;p&gt;Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: dstack&lt;/p&gt;
&lt;p&gt;Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-dstack-cve-2024-35255</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0487 — De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Elles permettent à un attaquant de provoquer une é…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0487</link>
      <description>certfr-2024-avi-0487</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0487</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BJ92729 — Security fixes for CVE-2024-24786, CVE-2024-35255, CVE-2025-22868, CVE-2025-30204, CVE-2025-61726, CVE-2025-61728, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bj92729</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: prometheus-operator&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the prometheus-operator package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: prometheus-operator&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the prometheus-operator package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bj92729</guid>
    </item>
    <item>
      <title>EUVD-2026-350245</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-350245</link>
      <description>EUVD-2026-350245</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-350245</guid>
    </item>
    <item>
      <title>fkie_cve-2024-35255</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-35255</link>
      <description>&lt;p&gt;Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-35255</guid>
    </item>
    <item>
      <title>GHSA-m5vv-6r4h-3vj9 — Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m5vv-6r4h-3vj9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: azure-identity, npm: @azure/identity, Maven: com.azure:azure-identity, npm: @azure/msal-node, NuGet: Microsoft.Identity.Client, Go: github.com/Azure/azure-sdk-for-go/sdk/azidentity, Maven: com.microsoft.azure:msal4j, NuGet: Azure.Identity&lt;/p&gt;
&lt;p&gt;Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: azure-identity, npm: @azure/identity, Maven: com.azure:azure-identity, npm: @azure/msal-node, NuGet: Microsoft.Identity.Client, Go: github.com/Azure/azure-sdk-for-go/sdk/azidentity, Maven: com.microsoft.azure:msal4j, NuGet: Azure.Identity&lt;/p&gt;
&lt;p&gt;Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m5vv-6r4h-3vj9</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-35255 — Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-35255</link>
      <description>msrc_CVE-2024-35255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-35255</guid>
    </item>
    <item>
      <title>OESA-2025-2066 — restic security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2066</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: restic&lt;/p&gt;
&lt;p&gt;restic is a backup program. It supports verification, encryption, snapshots and deduplication.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Microsoft Azure Identity Library and Microsoft Authentication Library (Cloud Software) (the affected version unknown). It has been rated as problematic.Using CWE to declare the problem leads to CWE-362. The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.Impacted is confidentiality.Applying a patch is able to eliminate this problem. A possible mitigation has been published immediately after the disclosure of the vulnerability.(CVE-2024-35255)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: restic&lt;/p&gt;
&lt;p&gt;restic is a backup program. It supports verification, encryption, snapshots and deduplication.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Microsoft Azure Identity Library and Microsoft Authentication Library (Cloud Software) (the affected version unknown). It has been rated as problematic.Using CWE to declare the problem leads to CWE-362. The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.Impacted is confidentiality.Applying a patch is able to eliminate this problem. A possible mitigation has been published immediately after the disclosure of the vulnerability.(CVE-2024-35255)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2066</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14048-1 — teleport-15.4.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14048-1</link>
      <description>&lt;p&gt;teleport-15.4.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;teleport-15.4.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14048-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1209 — Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1209</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: azure-identity&lt;/p&gt;
&lt;p&gt;Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: azure-identity&lt;/p&gt;
&lt;p&gt;Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1209</guid>
    </item>
    <item>
      <title>RHBA-2024:7523 — Red Hat Bug Fix Advisory: Red Hat Developer Hub 1.3.0 release</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2024:7523</link>
      <description>&lt;p&gt;micromatch: vulnerable to Regular Expression Denial of Service braces: fails to limit the number of characters it can handle dset: Prototype Pollution golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses net/http: Denial of service due to improper 100-continue handling in net/http azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity urllib3: proxy-authorization request header is not stripped during cross-origin redirects fast-loops: prototype pollution via objectMergeDeep nodejs-async: Regular expression denial of service while parsing function in autoinject express: Improper Input Handling in Express Redirects serve-static: Improper Sanitization in serve-static&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;micromatch: vulnerable to Regular Expression Denial of Service braces: fails to limit the number of characters it can handle dset: Prototype Pollution golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses net/http: Denial of service due to improper 100-continue handling in net/http azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity urllib3: proxy-authorization request header is not stripped during cross-origin redirects fast-loops: prototype pollution via objectMergeDeep nodejs-async: Regular expression denial of service while parsing function in autoinject express: Improper Input Handling in Express Redirects serve-static: Improper Sanitization in serve-static&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2024:7523</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1339 — Microsoft Azure: Mehrere Schwachstellen ermöglichen Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1339</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure ausnutzen, um seine Privilegien zu erhöhen und um einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure ausnutzen, um seine Privilegien zu erhöhen und um einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1339</guid>
    </item>
  </channel>
</rss>
