<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:53:24 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:5258 — Important: container-tools:rhel8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:5258</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
* golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)
* golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783)
* golang: net/mail: comments in display names are incorrectly handled (CVE-2024-24784)
* containers/image: digest type does not guarantee valid type (CVE-2024-3727)
* golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789)
* go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104)
* gorilla/schema: Potential memory exhaustion attack due to sparse slice deserialization (CVE-2024-37298)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
* golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)
* golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783)
* golang: net/mail: comments in display names are incorrectly handled (CVE-2024-24784)
* containers/image: digest type does not guarantee valid type (CVE-2024-3727)
* golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789)
* go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104)
* gorilla/schema: Potential memory exhaustion attack due to sparse slice deserialization (CVE-2024-37298)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:5258</guid>
    </item>
    <item>
      <title>bdu:2024-06681</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-06681</link>
      <description>bdu:2024-06681</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-06681</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</link>
      <description>certfr-2025-avi-0622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-GG94489 — go-retryablehttp prior to 0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-gg94489</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: prometheus&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the prometheus package. go-retryablehttp prior to 0. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: prometheus&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the prometheus package. go-retryablehttp prior to 0. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-gg94489</guid>
    </item>
    <item>
      <title>EUVD-2026-3250</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-3250</link>
      <description>EUVD-2026-3250</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-3250</guid>
    </item>
    <item>
      <title>fkie_cve-2024-6104</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-6104</link>
      <description>&lt;p&gt;go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-6104</guid>
    </item>
    <item>
      <title>GHSA-v6v8-xj6m-xwqh — go-retryablehttp can leak basic auth credentials to log files</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v6v8-xj6m-xwqh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/hashicorp/go-retryablehttp&lt;/p&gt;
&lt;p&gt;go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/hashicorp/go-retryablehttp&lt;/p&gt;
&lt;p&gt;go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v6v8-xj6m-xwqh</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-6104 — go-retryablehttp can leak basic auth credentials to log files</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-6104</link>
      <description>msrc_CVE-2024-6104</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-6104</guid>
    </item>
    <item>
      <title>OESA-2025-1053 — podman security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1053</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.(CVE-2019-9514)&#13;
&#13;
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)&#13;
&#13;
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request&amp;amp;apos;s Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.(CVE-2022-2880)&#13;
&#13;
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.(CVE-2019-9514)&#13;
&#13;
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)&#13;
&#13;
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request&amp;amp;apos;s Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.(CVE-2022-2880)&#13;
&#13;
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1053</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:0226-1 — Security update for gh</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0226-1</link>
      <description>&lt;p&gt;Security update for gh&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for gh&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:0226-1</guid>
    </item>
    <item>
      <title>RHBA-2024:5865 — Red Hat Bug Fix Advisory: Custom Metrics Autoscaler Operator for Red Hat 2.14.1-454 OpenShift Bug Fixes</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2024:5865</link>
      <description>&lt;p&gt;go-retryablehttp: url might write sensitive information to log file&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go-retryablehttp: url might write sensitive information to log file&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2024:5865</guid>
    </item>
    <item>
      <title>SUSE-RU-2025:02092-1 — Recommended update for podman</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2025:02092-1</link>
      <description>&lt;p&gt;Recommended update for podman&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for podman&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2025:02092-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-6104</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6104</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: golang-github-hashicorp-go-retryablehttp, Ubuntu:20.04:LTS: golang-github-hashicorp-go-retryablehttp, Ubuntu:22.04:LTS: golang-github-hashicorp-go-retryablehttp, Ubuntu:24.04:LTS: golang-github-hashicorp-go-retryablehttp, Ubuntu:25.10: golang-github-hashicorp-go-retryablehttp, Ubuntu:26.04:LTS: golang-github-hashicorp-go-retryablehttp&lt;/p&gt;
&lt;p&gt;go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: golang-github-hashicorp-go-retryablehttp, Ubuntu:20.04:LTS: golang-github-hashicorp-go-retryablehttp, Ubuntu:22.04:LTS: golang-github-hashicorp-go-retryablehttp, Ubuntu:24.04:LTS: golang-github-hashicorp-go-retryablehttp, Ubuntu:25.10: golang-github-hashicorp-go-retryablehttp, Ubuntu:26.04:LTS: golang-github-hashicorp-go-retryablehttp&lt;/p&gt;
&lt;p&gt;go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-6104</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1772 — Red Hat OpenShift: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1772</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1772</guid>
    </item>
  </channel>
</rss>
