<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:23:11 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0692 — De multiples vulnérabilités ont été découvertes dans Ruby on Rails. Elles permettent à un attaquant de provoquer une ex…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0692</link>
      <description>certfr-2025-avi-0692</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0692</guid>
    </item>
    <item>
      <title>EUVD-2026-249815</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-249815</link>
      <description>EUVD-2026-249815</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-249815</guid>
    </item>
    <item>
      <title>fkie_cve-2025-55193</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55193</link>
      <description>&lt;p&gt;Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-55193</guid>
    </item>
    <item>
      <title>GHSA-76r7-hhxj-r776 — Active Record logging vulnerable to ANSI escape injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-76r7-hhxj-r776</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: activerecord&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned the CVE identifier CVE-2025-55193&lt;/p&gt;
&lt;p&gt;### Impact
The ID passed to `find` or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences.&lt;/p&gt;
&lt;p&gt;### Releases
The fixed releases are available at the normal locations.&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Thanks to [lio346](https://hackerone.com/lio346) from Unit 515 of OPSWAT for reporting this vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: activerecord&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned the CVE identifier CVE-2025-55193&lt;/p&gt;
&lt;p&gt;### Impact
The ID passed to `find` or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences.&lt;/p&gt;
&lt;p&gt;### Releases
The fixed releases are available at the normal locations.&lt;/p&gt;
&lt;p&gt;### Credits&lt;/p&gt;
&lt;p&gt;Thanks to [lio346](https://hackerone.com/lio346) from Unit 515 of OPSWAT for reporting this vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-76r7-hhxj-r776</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15479-1 — ruby3.4-rubygem-activerecord-8.0-8.0.1-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15479-1</link>
      <description>&lt;p&gt;ruby3.4-rubygem-activerecord-8.0-8.0.1-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ruby3.4-rubygem-activerecord-8.0-8.0.1-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15479-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-55193</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55193</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: rails, Ubuntu:Pro:18.04:LTS: rails, Ubuntu:Pro:20.04:LTS: rails, Ubuntu:Pro:22.04:LTS: rails, Ubuntu:24.04:LTS: rails, Ubuntu:25.10: rails, Ubuntu:26.04:LTS: rails&lt;/p&gt;
&lt;p&gt;Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55193</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1822 — Ruby on Rails: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1822</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um beliebigen Programmcode auszuführen und Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Ruby on Rails ausnutzen, um beliebigen Programmcode auszuführen und Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1822</guid>
    </item>
  </channel>
</rss>
