<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:33:10 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-03571</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-03571</link>
      <description>bdu:2026-03571</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-03571</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AA33691 — Security fixes in calico-fips 3.28.5-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: calico-fips&lt;/p&gt;
&lt;p&gt;Package calico-fips version 3.28.5-r4 fixes 5 vulnerabilities: CVE-2026-33186, CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2025-13281&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: calico-fips&lt;/p&gt;
&lt;p&gt;Package calico-fips version 3.28.5-r4 fixes 5 vulnerabilities: CVE-2026-33186, CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2025-13281&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691</guid>
    </item>
    <item>
      <title>EUVD-2026-263520</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-263520</link>
      <description>EUVD-2026-263520</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-263520</guid>
    </item>
    <item>
      <title>fkie_cve-2025-13281</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-13281</link>
      <description>&lt;p&gt;A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-13281</guid>
    </item>
    <item>
      <title>GHSA-r6j8-c6r2-37rr — kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r6j8-c6r2-37rr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: k8s.io/kubernetes&lt;/p&gt;
&lt;p&gt;A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: k8s.io/kubernetes&lt;/p&gt;
&lt;p&gt;A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r6j8-c6r2-37rr</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-13281 — Portworx Half-Blind SSRF in kube-controller-manager</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-13281</link>
      <description>msrc_CVE-2025-13281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-13281</guid>
    </item>
    <item>
      <title>OESA-2025-2815 — kubernetes security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2815</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kubernetes&lt;/p&gt;
&lt;p&gt;Container cluster management.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Kubernetes kube-controller-manager up to versions 1.30.14, 1.31.14, 1.32.9, 1.33.5 and 1.34.1. It has been classified as CWE-918 (Server-Side Request Forgery). The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. This vulnerability impacts confidentiality, integrity, and availability.(CVE-2025-13281)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: kubernetes&lt;/p&gt;
&lt;p&gt;Container cluster management.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in Kubernetes kube-controller-manager up to versions 1.30.14, 1.31.14, 1.32.9, 1.33.5 and 1.34.1. It has been classified as CWE-918 (Server-Side Request Forgery). The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. This vulnerability impacts confidentiality, integrity, and availability.(CVE-2025-13281)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2815</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2705 — Kubernetes: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2705</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2705</guid>
    </item>
  </channel>
</rss>
