<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:21:12 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BO50567 — Security fixes in argo-cd 3.1.12-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bo50567</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-cd&lt;/p&gt;
&lt;p&gt;Package argo-cd version 3.1.12-r0 fixes 3 vulnerabilities: CVE-2025-13281, CVE-2025-5187, CVE-2025-4563&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-cd&lt;/p&gt;
&lt;p&gt;Package argo-cd version 3.1.12-r0 fixes 3 vulnerabilities: CVE-2025-13281, CVE-2025-5187, CVE-2025-4563&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bo50567</guid>
    </item>
    <item>
      <title>EUVD-2026-245564</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-245564</link>
      <description>EUVD-2026-245564</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-245564</guid>
    </item>
    <item>
      <title>fkie_cve-2025-4563</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-4563</link>
      <description>&lt;p&gt;A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-4563</guid>
    </item>
    <item>
      <title>GHSA-hj2p-8wj8-pfq4 — kubernetes allows nodes to bypass dynamic resource allocation authorization checks</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hj2p-8wj8-pfq4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: k8s.io/kubernetes&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: k8s.io/kubernetes&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hj2p-8wj8-pfq4</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-4563 — Nodes can bypass dynamic resource allocation authorization checks</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-4563</link>
      <description>msrc_CVE-2025-4563</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-4563</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2025-4563</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4563</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: kubernetes, Ubuntu:22.04:LTS: kubernetes, Ubuntu:24.04:LTS: kubernetes&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: kubernetes, Ubuntu:22.04:LTS: kubernetes, Ubuntu:24.04:LTS: kubernetes&lt;/p&gt;
&lt;p&gt;A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to perform equivalent validation during pod creation. This allows a compromised node to create mirror pods that access unauthorized dynamic resources, potentially leading to privilege escalation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4563</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1357 — Kubernetes: Schwachstelle ermöglicht umgehen von Sicherheitsmechanismen.</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1357</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um Sicheheritmechnismen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Kubernetes ausnutzen, um Sicheheritmechnismen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1357</guid>
    </item>
  </channel>
</rss>
