<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:27:14 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2025-10148</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-10148</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: curl, Alpaquita:25: curl, Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: curl, Alpaquita:25: curl, Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-10148</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0775 — De multiples vulnérabilités ont été découvertes dans Curl. Elles permettent à un attaquant de provoquer un déni de serv…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0775</link>
      <description>certfr-2025-avi-0775</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0775</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: curl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</guid>
    </item>
    <item>
      <title>cnvd-2025-21413</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-21413</link>
      <description>cnvd-2025-21413</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-21413</guid>
    </item>
    <item>
      <title>EUVD-2026-368391</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368391</link>
      <description>EUVD-2026-368391</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368391</guid>
    </item>
    <item>
      <title>fkie_cve-2025-10148</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-10148</link>
      <description>&lt;p&gt;curl&amp;#39;s WebSocket code did not update the 32-bit mask pattern for each new
outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.&lt;/p&gt;
&lt;p&gt;A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl&amp;#39;s WebSocket code did not update the 32-bit mask pattern for each new
outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.&lt;/p&gt;
&lt;p&gt;A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-10148</guid>
    </item>
    <item>
      <title>GHSA-cxvq-c3r3-8gwq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cxvq-c3r3-8gwq</link>
      <description>&lt;p&gt;curl&amp;#39;s websocket code did not update the 32 bit mask pattern for each new
 outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.&lt;/p&gt;
&lt;p&gt;A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl&amp;#39;s websocket code did not update the 32 bit mask pattern for each new
 outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.&lt;/p&gt;
&lt;p&gt;A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cxvq-c3r3-8gwq</guid>
    </item>
    <item>
      <title>ICSA-26-043-03 — Siemens COMOS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-043-03</link>
      <description>&lt;p&gt;When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password. DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3. Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. curl&amp;#39;s websocket code did not update the 32 bit mask pattern for each new
 outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.&lt;/p&gt;
&lt;p&gt;A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy. The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-mid…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password. DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3. Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. curl&amp;#39;s websocket code did not update the 32 bit mask pattern for each new
 outgoing frame as the specification says. Instead it used a fixed mask that
persisted and was used throughout the entire connection.&lt;/p&gt;
&lt;p&gt;A predictable mask pattern allows for a malicious server to induce traffic
between the two communicating parties that could be interpreted by an involved
proxy (configured or transparent) as genuine, real, HTTP traffic with content
and thereby poison its cache. That cached poisoned content could then be
served to all users of that proxy. The IAM client in affected products is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-mid…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-043-03</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-10148 — predictable WebSocket mask</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-10148</link>
      <description>msrc_CVE-2025-10148</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-10148</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15590-1 — curl-8.16.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15590-1</link>
      <description>&lt;p&gt;curl-8.16.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl-8.16.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15590-1</guid>
    </item>
    <item>
      <title>RHSA-2026:6893 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:6893</link>
      <description>&lt;p&gt;curl: libcurl: Curl out of bounds read for cookie path curl: predictable WebSocket mask curl: Curl missing SFTP host verification with wolfSSH backend curl: Public key pinning bypass via QUIC and GnuTLS allows server impersonation curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token curl: libcurl: Improper certificate validation due to cached TLS settings reuse curl: Host verification bypass during SSH transfers curl: libssh key passphrase bypass without agent set curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect curl: curl: Unauthorized access due to improper HTTP proxy connection reuse curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl: libcurl: Curl out of bounds read for cookie path curl: predictable WebSocket mask curl: Curl missing SFTP host verification with wolfSSH backend curl: Public key pinning bypass via QUIC and GnuTLS allows server impersonation curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token curl: libcurl: Improper certificate validation due to cached TLS settings reuse curl: Host verification bypass during SSH transfers curl: libssh key passphrase bypass without agent set curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect curl: curl: Unauthorized access due to improper HTTP proxy connection reuse curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:6893</guid>
    </item>
    <item>
      <title>SSA-089022 — SSA-089022: Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.3</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-089022</link>
      <description>&lt;p&gt;There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns.  This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block.  A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400. An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal. A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. libcurl&amp;#39;s ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `fr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns.  This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block.  A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400. An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal. A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. libcurl&amp;#39;s ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `fr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-089022</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03173-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03173-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03173-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-10148</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-10148</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: curl, Ubuntu:25.10: curl&lt;/p&gt;
&lt;p&gt;curl&amp;#39;s WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: curl, Ubuntu:25.10: curl&lt;/p&gt;
&lt;p&gt;curl&amp;#39;s WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-10148</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2023 — cURL: Mehrere Schwachstellen ermöglichen Manipulation von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2023</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2023</guid>
    </item>
  </channel>
</rss>
