<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:25:31 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:7466 — Moderate: delve and golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:7466</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: delve, AlmaLinux:10: go-toolset, AlmaLinux:10: golang, AlmaLinux:10: golang-bin, AlmaLinux:10: golang-docs, AlmaLinux:10: golang-misc, AlmaLinux:10: golang-src, AlmaLinux:10: golang-tests&lt;/p&gt;
&lt;p&gt;Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you&amp;#39;re using a debugger, things aren&amp;#39;t going your way. With that in mind, Delve should stay out of your way as much as possible.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints (CVE-2024-45341)
  * golang: net/[http:](http:) net/[http:](http:) sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336)
  * crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: delve, AlmaLinux:10: go-toolset, AlmaLinux:10: golang, AlmaLinux:10: golang-bin, AlmaLinux:10: golang-docs, AlmaLinux:10: golang-misc, AlmaLinux:10: golang-src, AlmaLinux:10: golang-tests&lt;/p&gt;
&lt;p&gt;Delve is a debugger for the Go programming language. The goal of the project is to provide a simple, full featured debugging tool for Go. Delve should be easy to invoke and easy to use. Chances are if you&amp;#39;re using a debugger, things aren&amp;#39;t going your way. With that in mind, Delve should stay out of your way as much as possible.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints (CVE-2024-45341)
  * golang: net/[http:](http:) net/[http:](http:) sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336)
  * crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:7466</guid>
    </item>
    <item>
      <title>bdu:2025-03456</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-03456</link>
      <description>bdu:2025-03456</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-03456</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2025-22866 — CVE-2025-22866 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-22866</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-22866</guid>
    </item>
    <item>
      <title>BIT-golang-2025-22866 — Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2025-22866</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2025-22866</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0256 — De multiples vulnérabilités ont été découvertes dans Broadcom VMware Tanzu Greenplum. Elles permettent à un attaquant d…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0256</link>
      <description>certfr-2025-avi-0256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0256</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CR41732 — net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cr41732</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ingress-nginx-controller&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the ingress-nginx-controller package. The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ingress-nginx-controller&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the ingress-nginx-controller package. The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cr41732</guid>
    </item>
    <item>
      <title>EUVD-2026-218592</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-218592</link>
      <description>EUVD-2026-218592</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-218592</guid>
    </item>
    <item>
      <title>fkie_cve-2025-22866</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22866</link>
      <description>&lt;p&gt;Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-22866</guid>
    </item>
    <item>
      <title>GHSA-3whm-j4xm-rv8x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3whm-j4xm-rv8x</link>
      <description>&lt;p&gt;Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3whm-j4xm-rv8x</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-22866 — Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-22866</link>
      <description>msrc_CVE-2025-22866</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-22866</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14735-1 — go1.24-1.24rc3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14735-1</link>
      <description>&lt;p&gt;go1.24-1.24rc3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go1.24-1.24rc3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14735-1</guid>
    </item>
    <item>
      <title>RHEA-2025:3039 — Red Hat Enhancement Advisory: RHEA: Submariner 0.19.3 - bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhea-2025:3039</link>
      <description>&lt;p&gt;golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhea-2025:3039</guid>
    </item>
    <item>
      <title>RLSA-2026:67148 — Important: osbuild-composer security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:67148</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)&lt;/p&gt;
&lt;p&gt;* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)&lt;/p&gt;
&lt;p&gt;* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)&lt;/p&gt;
&lt;p&gt;* mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)&lt;/p&gt;
&lt;p&gt;* github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)&lt;/p&gt;
&lt;p&gt;* github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)&lt;/p&gt;
&lt;p&gt;* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)&lt;/p&gt;
&lt;p&gt;* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)&lt;/p&gt;
&lt;p&gt;* mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)&lt;/p&gt;
&lt;p&gt;* github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)&lt;/p&gt;
&lt;p&gt;* github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:67148</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0392-1 — Security update for go1.22</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0392-1</link>
      <description>&lt;p&gt;Security update for go1.22&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.22&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0392-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-22866</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22866</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 24 more&lt;/p&gt;
&lt;p&gt;Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 24 more&lt;/p&gt;
&lt;p&gt;Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22866</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0263 — Golang Go: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0263</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Golang Go ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Golang Go ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0263</guid>
    </item>
  </channel>
</rss>
