<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 12:41:43 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00136</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00136</link>
      <description>bdu:2026-00136</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00136</guid>
    </item>
    <item>
      <title>EUVD-2026-260736</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260736</link>
      <description>EUVD-2026-260736</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260736</guid>
    </item>
    <item>
      <title>fkie_cve-2025-49521</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49521</link>
      <description>&lt;p&gt;A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In OpenShift, it can lead to service account token theft.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In OpenShift, it can lead to service account token theft.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-49521</guid>
    </item>
    <item>
      <title>GHSA-g6ph-9xfv-87c2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g6ph-9xfv-87c2</link>
      <description>&lt;p&gt;A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In OpenShift, it can lead to service account token theft.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In OpenShift, it can lead to service account token theft.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g6ph-9xfv-87c2</guid>
    </item>
    <item>
      <title>RHSA-2025:9986 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:9986</link>
      <description>&lt;p&gt;net/http: Request smuggling due to acceptance of invalid chunked data in net/http event-driven-ansible: Authenticated Argument Injection in Git URL in EDA Project Creation event-driven-ansible: Template Injection via Git Branch and Refspec in EDA Projects&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;net/http: Request smuggling due to acceptance of invalid chunked data in net/http event-driven-ansible: Authenticated Argument Injection in Git URL in EDA Project Creation event-driven-ansible: Template Injection via Git Branch and Refspec in EDA Projects&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:9986</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1437 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1437</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um beliebige Befehle auszuführen, Informationen offenzulegen oder um einen Request-Smuggling Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um beliebige Befehle auszuführen, Informationen offenzulegen oder um einen Request-Smuggling Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1437</guid>
    </item>
  </channel>
</rss>
