<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:38:47 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-10918</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10918</link>
      <description>bdu:2025-10918</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10918</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-40918</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-40918</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl-authen-sasl, Alpaquita:25: perl-authen-sasl, Alpaquita:stream: perl-authen-sasl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl-authen-sasl, Alpaquita:25: perl-authen-sasl, Alpaquita:stream: perl-authen-sasl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-40918</guid>
    </item>
    <item>
      <title>BREW-git-CVE-2025-40918 — Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely</title>
      <link>https://cve.radiocsirt.org/vuln/brew-git-cve-2025-40918</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: git&lt;/p&gt;
&lt;p&gt;Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely.&lt;/p&gt;
&lt;p&gt;The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.&lt;/p&gt;
&lt;p&gt;According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation
 depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: git&lt;/p&gt;
&lt;p&gt;Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely.&lt;/p&gt;
&lt;p&gt;The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.&lt;/p&gt;
&lt;p&gt;According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation
 depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-git-cve-2025-40918</guid>
    </item>
    <item>
      <title>EUVD-2026-259950</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-259950</link>
      <description>EUVD-2026-259950</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-259950</guid>
    </item>
    <item>
      <title>fkie_cve-2025-40918</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40918</link>
      <description>&lt;p&gt;Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely.&lt;/p&gt;
&lt;p&gt;The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.&lt;/p&gt;
&lt;p&gt;According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation
 depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely.&lt;/p&gt;
&lt;p&gt;The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.&lt;/p&gt;
&lt;p&gt;According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation
 depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-40918</guid>
    </item>
    <item>
      <title>GHSA-496q-8ph2-c4fj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-496q-8ph2-c4fj</link>
      <description>&lt;p&gt;Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely.&lt;/p&gt;
&lt;p&gt;The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.&lt;/p&gt;
&lt;p&gt;According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation
 depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely.&lt;/p&gt;
&lt;p&gt;The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage.&lt;/p&gt;
&lt;p&gt;According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation
 depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-496q-8ph2-c4fj</guid>
    </item>
    <item>
      <title>OESA-2026-2422 — perl-Authen-SASL security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2422</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: perl-Authen-SASL&lt;/p&gt;
&lt;p&gt;Authen::SASL::Perl is the pure Perl implementation of SASL mechanisms in the Authen::SASL framework, At the time of this writing it provides the client part implementation for the following SASL mechanisms.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID comes from a small set of numbers, and the epoch time may be guessed if not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. According to RFC 2831, the cnonce-value should be provided by the client and contain at least 64 bits of entropy to ensure security.(CVE-2025-40918)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: perl-Authen-SASL&lt;/p&gt;
&lt;p&gt;Authen::SASL::Perl is the pure Perl implementation of SASL mechanisms in the Authen::SASL framework, At the time of this writing it provides the client part implementation for the following SASL mechanisms.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID comes from a small set of numbers, and the epoch time may be guessed if not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. According to RFC 2831, the cnonce-value should be provided by the client and contain at least 64 bits of entropy to ensure security.(CVE-2025-40918)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2422</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15385-1 — perl-Authen-SASL-2.180.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15385-1</link>
      <description>&lt;p&gt;perl-Authen-SASL-2.180.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;perl-Authen-SASL-2.180.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15385-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03088-1 — Security update for perl-Authen-SASL, perl-Crypt-URandom</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03088-1</link>
      <description>&lt;p&gt;Security update for perl-Authen-SASL, perl-Crypt-URandom&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for perl-Authen-SASL, perl-Crypt-URandom&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03088-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-40918</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40918</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:16.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:18.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:20.04:LTS: libauthen-sasl-perl, Ubuntu:22.04:LTS: libauthen-sasl-perl, Ubuntu:24.04:LTS: libauthen-sasl-perl, Ubuntu:25.10: libauthen-sasl-perl, Ubuntu:26.04:LTS: libauthen-sasl-perl&lt;/p&gt;
&lt;p&gt;Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation  depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:16.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:18.04:LTS: libauthen-sasl-perl, Ubuntu:Pro:20.04:LTS: libauthen-sasl-perl, Ubuntu:22.04:LTS: libauthen-sasl-perl, Ubuntu:24.04:LTS: libauthen-sasl-perl, Ubuntu:25.10: libauthen-sasl-perl, Ubuntu:26.04:LTS: libauthen-sasl-perl&lt;/p&gt;
&lt;p&gt;Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP Date header. The built-in rand function is unsuitable for cryptographic usage. According to RFC 2831, The cnonce-value is an opaque quoted string value provided by the client and used by both client and server to avoid chosen plaintext attacks, and to provide mutual authentication. The security of the implementation  depends on a good choice. It is RECOMMENDED that it contain at least 64 bits of entropy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40918</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1032 — IBM Tivoli Network Manager: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1032</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Tivoli Network Manager ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1032</guid>
    </item>
  </channel>
</rss>
