<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:52:27 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05122</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05122</link>
      <description>bdu:2026-05122</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05122</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-14017</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-14017</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-14017</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0010 — De multiples vulnérabilités ont été découvertes dans Curl. Elles permettent à un attaquant de provoquer une atteinte à…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0010</link>
      <description>certfr-2026-avi-0010</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0010</guid>
    </item>
    <item>
      <title>EUVD-2026-368394</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368394</link>
      <description>EUVD-2026-368394</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368394</guid>
    </item>
    <item>
      <title>fkie_cve-2025-14017</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14017</link>
      <description>&lt;p&gt;When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,
changing TLS options in one thread would inadvertently change them globally
and therefore possibly also affect other concurrently setup transfers.&lt;/p&gt;
&lt;p&gt;Disabling certificate verification for a specific transfer could
unintentionally disable the feature for other threads as well.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,
changing TLS options in one thread would inadvertently change them globally
and therefore possibly also affect other concurrently setup transfers.&lt;/p&gt;
&lt;p&gt;Disabling certificate verification for a specific transfer could
unintentionally disable the feature for other threads as well.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-14017</guid>
    </item>
    <item>
      <title>GHSA-jh4h-2cg6-889h</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jh4h-2cg6-889h</link>
      <description>&lt;p&gt;When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,
changing TLS options in one thread would inadvertently change them globally
and therefore possibly also affect other concurrently setup transfers.&lt;/p&gt;
&lt;p&gt;Disabling certificate verification for a specific transfer could
unintentionally disable the feature for other threads as well.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,
changing TLS options in one thread would inadvertently change them globally
and therefore possibly also affect other concurrently setup transfers.&lt;/p&gt;
&lt;p&gt;Disabling certificate verification for a specific transfer could
unintentionally disable the feature for other threads as well.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jh4h-2cg6-889h</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-14017 — broken TLS options for threaded LDAPS</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-14017</link>
      <description>msrc_CVE-2025-14017</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-14017</guid>
    </item>
    <item>
      <title>NCSC-2026-0127 — Kwetsbaarheden verholpen in Oracle PeopleSoft</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0127</link>
      <description>NCSC-2026-0127</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0127</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10017-1 — curl-8.18.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10017-1</link>
      <description>&lt;p&gt;curl-8.18.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl-8.18.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10017-1</guid>
    </item>
    <item>
      <title>RHSA-2026:6893 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:6893</link>
      <description>&lt;p&gt;curl: libcurl: Curl out of bounds read for cookie path curl: predictable WebSocket mask curl: Curl missing SFTP host verification with wolfSSH backend curl: Public key pinning bypass via QUIC and GnuTLS allows server impersonation curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token curl: libcurl: Improper certificate validation due to cached TLS settings reuse curl: Host verification bypass during SSH transfers curl: libssh key passphrase bypass without agent set curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect curl: curl: Unauthorized access due to improper HTTP proxy connection reuse curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl: libcurl: Curl out of bounds read for cookie path curl: predictable WebSocket mask curl: Curl missing SFTP host verification with wolfSSH backend curl: Public key pinning bypass via QUIC and GnuTLS allows server impersonation curl: curl: Security bypass due to global TLS option changes in multi-threaded LDAPS transfers curl: Information disclosure via cross-protocol redirect with OAuth2 bearer token curl: libcurl: Improper certificate validation due to cached TLS settings reuse curl: Host verification bypass during SSH transfers curl: libssh key passphrase bypass without agent set curl: curl: Authentication bypass due to incorrect connection reuse with Negotiate authentication curl: curl: Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect curl: curl: Unauthorized access due to improper HTTP proxy connection reuse curl: curl: Arbitrary code execution or Denial of Service via use-after-free in SMB request handling&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:6893</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0077-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0077-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0077-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-14017</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14017</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: curl, Ubuntu:Pro:16.04:LTS: curl, Ubuntu:Pro:18.04:LTS: curl, Ubuntu:Pro:20.04:LTS: curl, Ubuntu:22.04:LTS: curl, Ubuntu:24.04:LTS: curl, Ubuntu:25.10: curl&lt;/p&gt;
&lt;p&gt;When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: curl, Ubuntu:Pro:16.04:LTS: curl, Ubuntu:Pro:18.04:LTS: curl, Ubuntu:Pro:20.04:LTS: curl, Ubuntu:22.04:LTS: curl, Ubuntu:24.04:LTS: curl, Ubuntu:25.10: curl&lt;/p&gt;
&lt;p&gt;When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14017</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0030 — cURL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0030</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0030</guid>
    </item>
  </channel>
</rss>
