<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:05:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-189464</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-189464</link>
      <description>EUVD-2026-189464</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-189464</guid>
    </item>
    <item>
      <title>fkie_cve-2024-47182</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47182</link>
      <description>&lt;p&gt;Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches to bcrypt, a more appropriate hash for passwords, in version 8.5.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches to bcrypt, a more appropriate hash for passwords, in version 8.5.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-47182</guid>
    </item>
    <item>
      <title>GHSA-w7qr-q9fh-fj35 — Dozzle uses unsafe hash for passwords</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w7qr-q9fh-fj35</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/amir20/dozzle&lt;/p&gt;
&lt;p&gt;### Summary
The app uses sha-256 as the hash for passwords. The app should switch to bcrypt.&lt;/p&gt;
&lt;p&gt;### Details
SHA-256 is a message digest hash, and not classified as secure for password hashing. Message digest hashes are designed to be fast, while password hashing mechanisms are designed with certain cryptographic properties (e.g. slow) to protect against vulnerabilities. Refer to the links below for more information:
- https://security.stackexchange.com/questions/195563/why-is-sha-256-not-good-for-passwords
- https://stackoverflow.com/questions/11624372/best-practice-for-hashing-passwords-sha256-or-sha512
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pre-hashing-passwords-with-bcrypt&lt;/p&gt;
&lt;p&gt;### PoC
N/A&lt;/p&gt;
&lt;p&gt;### Impact
It leaves users susceptible to rainbow table attacks&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/amir20/dozzle&lt;/p&gt;
&lt;p&gt;### Summary
The app uses sha-256 as the hash for passwords. The app should switch to bcrypt.&lt;/p&gt;
&lt;p&gt;### Details
SHA-256 is a message digest hash, and not classified as secure for password hashing. Message digest hashes are designed to be fast, while password hashing mechanisms are designed with certain cryptographic properties (e.g. slow) to protect against vulnerabilities. Refer to the links below for more information:
- https://security.stackexchange.com/questions/195563/why-is-sha-256-not-good-for-passwords
- https://stackoverflow.com/questions/11624372/best-practice-for-hashing-passwords-sha256-or-sha512
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pre-hashing-passwords-with-bcrypt&lt;/p&gt;
&lt;p&gt;### PoC
N/A&lt;/p&gt;
&lt;p&gt;### Impact
It leaves users susceptible to rainbow table attacks&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w7qr-q9fh-fj35</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:0350-1 — Security update for govulncheck-vulndb</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</link>
      <description>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3911-1 — Security update for govulncheck-vulndb</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1</link>
      <description>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1</guid>
    </item>
  </channel>
</rss>
