<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:43:58 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:0401 — Important: grafana security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:0401</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: grafana, AlmaLinux:8: grafana-selinux&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* go-git: argument injection via the URL field (CVE-2025-21613)
  * go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies (CVE-2025-21614)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: grafana, AlmaLinux:8: grafana-selinux&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* go-git: argument injection via the URL field (CVE-2025-21613)
  * go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies (CVE-2025-21614)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:0401</guid>
    </item>
    <item>
      <title>bdu:2025-00210</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-00210</link>
      <description>bdu:2025-00210</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-00210</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0337 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0337</link>
      <description>certfr-2025-avi-0337</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0337</guid>
    </item>
    <item>
      <title>EUVD-2026-209116</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-209116</link>
      <description>EUVD-2026-209116</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-209116</guid>
    </item>
    <item>
      <title>fkie_cve-2025-21613</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21613</link>
      <description>&lt;p&gt;go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-21613</guid>
    </item>
    <item>
      <title>GHSA-v725-9546-7q7m — go-git has an Argument Injection via the URL field</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v725-9546-7q7m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gopkg.in/src-d/go-git.v4, Go: github.com/go-git/go-git/v5&lt;/p&gt;
&lt;p&gt;### Impact
An argument injection vulnerability was discovered in `go-git` versions prior to `v5.13`.&lt;/p&gt;
&lt;p&gt;Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to [git-upload-pack flags](https://git-scm.com/docs/git-upload-pack). This only happens when the `file` transport protocol is being used, as that is the only protocol that shells out to `git` binaries.&lt;/p&gt;
&lt;p&gt;### Affected versions
Users running versions of `go-git` from `v4` and above are recommended to upgrade to `v5.13` in order to mitigate this vulnerability.&lt;/p&gt;
&lt;p&gt;### Workarounds
In cases where a bump to the latest version of `go-git` is not possible, we recommend users to enforce restrict validation rules for values passed in the URL field.&lt;/p&gt;
&lt;p&gt;## Credit
Thanks to @vin01 for responsibly disclosing this vulnerability to us.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: gopkg.in/src-d/go-git.v4, Go: github.com/go-git/go-git/v5&lt;/p&gt;
&lt;p&gt;### Impact
An argument injection vulnerability was discovered in `go-git` versions prior to `v5.13`.&lt;/p&gt;
&lt;p&gt;Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to [git-upload-pack flags](https://git-scm.com/docs/git-upload-pack). This only happens when the `file` transport protocol is being used, as that is the only protocol that shells out to `git` binaries.&lt;/p&gt;
&lt;p&gt;### Affected versions
Users running versions of `go-git` from `v4` and above are recommended to upgrade to `v5.13` in order to mitigate this vulnerability.&lt;/p&gt;
&lt;p&gt;### Workarounds
In cases where a bump to the latest version of `go-git` is not possible, we recommend users to enforce restrict validation rules for values passed in the URL field.&lt;/p&gt;
&lt;p&gt;## Credit
Thanks to @vin01 for responsibly disclosing this vulnerability to us.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v725-9546-7q7m</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-21613 — go-git has an Argument Injection via the URL field</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21613</link>
      <description>msrc_CVE-2025-21613</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-21613</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:0056-1 — Security update for trivy</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:0056-1</link>
      <description>&lt;p&gt;Security update for trivy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for trivy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:0056-1</guid>
    </item>
    <item>
      <title>RHSA-2024:6121 — Red Hat Security Advisory: OpenShift Container Platform 4.18.1 security and extras update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:6121</link>
      <description>&lt;p&gt;helm: shows secrets with --dry-run option in clear text PostCSS: Improper input validation in PostCSS cross-spawn: regular expression denial of service golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html body-parser: Denial of Service Vulnerability in body-parser dompurify: DOMPurify vulnerable to tampering by prototype pollution path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x nanoid: nanoid mishandles non-integer values jinja2: Jinja has a sandbox breakout through malicious filenames jinja2: Jinja has a sandbox breakout through indirect reference to format method go-git: argument injection via the URL field go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;helm: shows secrets with --dry-run option in clear text PostCSS: Improper input validation in PostCSS cross-spawn: regular expression denial of service golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html body-parser: Denial of Service Vulnerability in body-parser dompurify: DOMPurify vulnerable to tampering by prototype pollution path-to-regexp: path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x nanoid: nanoid mishandles non-integer values jinja2: Jinja has a sandbox breakout through malicious filenames jinja2: Jinja has a sandbox breakout through indirect reference to format method go-git: argument injection via the URL field go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:6121</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0060-1 — Security update for govulncheck-vulndb</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0060-1</link>
      <description>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for govulncheck-vulndb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0060-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-21613</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21613</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: golang-github-go-git-go-git, Ubuntu:Pro:24.04:LTS: golang-github-go-git-go-git&lt;/p&gt;
&lt;p&gt;go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: golang-github-go-git-go-git, Ubuntu:Pro:24.04:LTS: golang-github-go-git-go-git&lt;/p&gt;
&lt;p&gt;go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21613</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0123 — Red Hat Enterprise Linux und and OpenShift (go-git): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0123</link>
      <description>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in der Grafana Komponente ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen preiszugeben und einen Denial-of-Service-Zustand zu erzeugen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in der Grafana Komponente ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen preiszugeben und einen Denial-of-Service-Zustand zu erzeugen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0123</guid>
    </item>
  </channel>
</rss>
