<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:15:17 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:7502 — Moderate: go-toolset:rhel8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:7502</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: delve, AlmaLinux:8: go-toolset, AlmaLinux:8: golang, AlmaLinux:8: golang-bin, AlmaLinux:8: golang-docs, AlmaLinux:8: golang-misc, AlmaLinux:8: golang-src, AlmaLinux:8: golang-tests&lt;/p&gt;
&lt;p&gt;Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: delve, AlmaLinux:8: go-toolset, AlmaLinux:8: golang, AlmaLinux:8: golang-bin, AlmaLinux:8: golang-docs, AlmaLinux:8: golang-misc, AlmaLinux:8: golang-src, AlmaLinux:8: golang-tests&lt;/p&gt;
&lt;p&gt;Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:7502</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2024-9355 — CVE-2024-9355 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-9355</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-9355</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0021 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0021</link>
      <description>certfr-2025-avi-0021</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0021</guid>
    </item>
    <item>
      <title>EUVD-2026-373055</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-373055</link>
      <description>EUVD-2026-373055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-373055</guid>
    </item>
    <item>
      <title>fkie_cve-2024-9355</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-9355</link>
      <description>&lt;p&gt;A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-9355</guid>
    </item>
    <item>
      <title>GHSA-3h3x-2hwv-hr52 — Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3h3x-2hwv-hr52</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/golang-fips/openssl&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/golang-fips/openssl&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3h3x-2hwv-hr52</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-9355 — Golang-fips: golang fips zeroed buffer</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-9355</link>
      <description>msrc_CVE-2024-9355</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-9355</guid>
    </item>
    <item>
      <title>OESA-2025-1052 — podman security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1052</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.(CVE-2019-9514)&#13;
&#13;
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)&#13;
&#13;
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request&amp;amp;apos;s Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.(CVE-2022-2880)&#13;
&#13;
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: podman&lt;/p&gt;
&lt;p&gt;Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.(CVE-2019-9514)&#13;
&#13;
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)&#13;
&#13;
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request&amp;amp;apos;s Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.(CVE-2022-2880)&#13;
&#13;
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1052</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:0350-1 — Security update for govulncheck-vulndb</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</link>
      <description>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</guid>
    </item>
    <item>
      <title>RHSA-2024:10133 — Red Hat Security Advisory: rhc-worker-script security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:10133</link>
      <description>&lt;p&gt;golang-fips: Golang FIPS zeroed buffer net/http: Denial of service due to improper 100-continue handling in net/http&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang-fips: Golang FIPS zeroed buffer net/http: Denial of service due to improper 100-continue handling in net/http&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:10133</guid>
    </item>
    <item>
      <title>RLSA-2026:66016 — Important: osbuild-composer security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:66016</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355)&lt;/p&gt;
&lt;p&gt;* golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336)&lt;/p&gt;
&lt;p&gt;* net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)&lt;/p&gt;
&lt;p&gt;* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)&lt;/p&gt;
&lt;p&gt;* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)&lt;/p&gt;
&lt;p&gt;* net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)&lt;/p&gt;
&lt;p&gt;* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)&lt;/p&gt;
&lt;p&gt;* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)&lt;/p&gt;
&lt;p&gt;* encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355)&lt;/p&gt;
&lt;p&gt;* golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336)&lt;/p&gt;
&lt;p&gt;* net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)&lt;/p&gt;
&lt;p&gt;* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)&lt;/p&gt;
&lt;p&gt;* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)&lt;/p&gt;
&lt;p&gt;* net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)&lt;/p&gt;
&lt;p&gt;* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)&lt;/p&gt;
&lt;p&gt;* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)&lt;/p&gt;
&lt;p&gt;* encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:66016</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3911-1 — Security update for govulncheck-vulndb</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1</link>
      <description>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3911-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3075 — Golang Go "FIPS OpenSSL": Schwachstelle ermöglicht nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3075</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in der Golang Go Komponente &amp;#34;FIPS OpenSSL&amp;#34; ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in der Golang Go Komponente &amp;#34;FIPS OpenSSL&amp;#34; ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3075</guid>
    </item>
  </channel>
</rss>
