<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 12:07:57 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0112 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0112</link>
      <description>certfr-2026-avi-0112</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0112</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AV17233 — Security fix for CVE-2025-14762 applied in: logstash-fips 9.2.6-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-av17233</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: logstash-fips&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the logstash-fips package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: logstash-fips&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the logstash-fips package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-av17233</guid>
    </item>
    <item>
      <title>EUVD-2026-263924</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-263924</link>
      <description>EUVD-2026-263924</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-263924</guid>
    </item>
    <item>
      <title>fkie_cve-2025-14762</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14762</link>
      <description>&lt;p&gt;Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an &amp;#34;instruction file&amp;#34; instead of S3&amp;#39;s metadata record.&lt;/p&gt;
&lt;p&gt;To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an &amp;#34;instruction file&amp;#34; instead of S3&amp;#39;s metadata record.&lt;/p&gt;
&lt;p&gt;To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-14762</guid>
    </item>
    <item>
      <title>GHSA-2xgq-q749-89fq — AWS SDK for Ruby's S3 Encryption Client has a Key Commitment Issue</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2xgq-q749-89fq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: aws-sdk-s3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;S3 Encryption Client for Ruby is an open-source client-side encryption library used to facilitate writing and reading encrypted records to S3.&lt;/p&gt;
&lt;p&gt;When the encrypted data key (EDK) is stored in an &amp;#34;Instruction File&amp;#34; instead of S3&amp;#39;s metadata record, the EDK is exposed to an &amp;#34;Invisible Salamanders&amp;#34; attack  (https://eprint.iacr.org/2019/016), which could allow the EDK to be replaced with a new key.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;### Background - Key Commitment&lt;/p&gt;
&lt;p&gt;There is a cryptographic property whereby under certain conditions, a single ciphertext can be decrypted into 2 different plaintexts by using different encryption keys. To address this issue, strong encryption schemes use what is known as &amp;#34;key commitment&amp;#34;, a process by which an encrypted message can only be decrypted by one key; the key used to originally encrypt the message.&lt;/p&gt;
&lt;p&gt;In older versions of S3EC, when customers are also using a feature called &amp;#34;Instruction File&amp;#34; to store EDKs, key commitment is not implemented because multiple EDKs could be associated to an underlying encrypted message object.  For such customers an attack that leverages the lack of key commitment is possible.  A bad actor would need two things to leverage this issue: (i) the ability to create a separate, rogue, EDK that will also decrypt the underlying object to produce desired plaintext, and (ii) permission to upload a new instruction file to the S3 bucket to replace the existing instruction file placed there by the user using the S3C.  Any future at…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: aws-sdk-s3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;S3 Encryption Client for Ruby is an open-source client-side encryption library used to facilitate writing and reading encrypted records to S3.&lt;/p&gt;
&lt;p&gt;When the encrypted data key (EDK) is stored in an &amp;#34;Instruction File&amp;#34; instead of S3&amp;#39;s metadata record, the EDK is exposed to an &amp;#34;Invisible Salamanders&amp;#34; attack  (https://eprint.iacr.org/2019/016), which could allow the EDK to be replaced with a new key.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;### Background - Key Commitment&lt;/p&gt;
&lt;p&gt;There is a cryptographic property whereby under certain conditions, a single ciphertext can be decrypted into 2 different plaintexts by using different encryption keys. To address this issue, strong encryption schemes use what is known as &amp;#34;key commitment&amp;#34;, a process by which an encrypted message can only be decrypted by one key; the key used to originally encrypt the message.&lt;/p&gt;
&lt;p&gt;In older versions of S3EC, when customers are also using a feature called &amp;#34;Instruction File&amp;#34; to store EDKs, key commitment is not implemented because multiple EDKs could be associated to an underlying encrypted message object.  For such customers an attack that leverages the lack of key commitment is possible.  A bad actor would need two things to leverage this issue: (i) the ability to create a separate, rogue, EDK that will also decrypt the underlying object to produce desired plaintext, and (ii) permission to upload a new instruction file to the S3 bucket to replace the existing instruction file placed there by the user using the S3C.  Any future at…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2xgq-q749-89fq</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-14762</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14762</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-aws-sdk, Ubuntu:18.04:LTS: ruby-aws-sdk, Ubuntu:20.04:LTS: ruby-aws-sdk, Ubuntu:22.04:LTS: ruby-aws-sdk, Ubuntu:24.04:LTS: ruby-aws-sdk, Ubuntu:25.10: ruby-aws-sdk, Ubuntu:26.04:LTS: ruby-aws-sdk&lt;/p&gt;
&lt;p&gt;Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an &amp;#34;instruction file&amp;#34; instead of S3&amp;#39;s metadata record. To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-aws-sdk, Ubuntu:18.04:LTS: ruby-aws-sdk, Ubuntu:20.04:LTS: ruby-aws-sdk, Ubuntu:22.04:LTS: ruby-aws-sdk, Ubuntu:24.04:LTS: ruby-aws-sdk, Ubuntu:25.10: ruby-aws-sdk, Ubuntu:26.04:LTS: ruby-aws-sdk&lt;/p&gt;
&lt;p&gt;Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an &amp;#34;instruction file&amp;#34; instead of S3&amp;#39;s metadata record. To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-14762</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0552 — Fluentd: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0552</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Fluentd ausnutzen, um Dateien und Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Fluentd ausnutzen, um Dateien und Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0552</guid>
    </item>
  </channel>
</rss>
