<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:28:53 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-14810</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14810</link>
      <description>bdu:2025-14810</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14810</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1064 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1064</link>
      <description>certfr-2025-avi-1064</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1064</guid>
    </item>
    <item>
      <title>EUVD-2026-265029</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265029</link>
      <description>EUVD-2026-265029</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265029</guid>
    </item>
    <item>
      <title>fkie_cve-2025-12977</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-12977</link>
      <description>&lt;p&gt;Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid tags. Because tags influence routing and some outputs derive filenames or contents from tags, this can allow newline injection, path traversal, forged record injection, or log misrouting, impacting data integrity and log routing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid tags. Because tags influence routing and some outputs derive filenames or contents from tags, this can allow newline injection, path traversal, forged record injection, or log misrouting, impacting data integrity and log routing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-12977</guid>
    </item>
    <item>
      <title>GHSA-v498-rhc6-28g9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v498-rhc6-28g9</link>
      <description>&lt;p&gt;Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid tags. Because tags influence routing and some outputs derive filenames or contents from tags, this can allow newline injection, path traversal, forged record injection, or log misrouting, impacting data integrity and log routing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into Splunk or Elasticsearch can supply tag_key values containing special characters such as newlines or ../ that are treated as valid tags. Because tags influence routing and some outputs derive filenames or contents from tags, this can allow newline injection, path traversal, forged record injection, or log misrouting, impacting data integrity and log routing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v498-rhc6-28g9</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-12977 — CVE-2025-12977</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-12977</link>
      <description>msrc_CVE-2025-12977</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-12977</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2670 — Fluent Bit: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2670</link>
      <description>&lt;p&gt;Ein entfernter anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Fluent Bit ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu verursachen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Fluent Bit ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu verursachen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2670</guid>
    </item>
  </channel>
</rss>
