<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:19:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-14688</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14688</link>
      <description>bdu:2025-14688</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14688</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1129 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1129</link>
      <description>certfr-2025-avi-1129</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1129</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD41794 — SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the c…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad41794</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cert-manager-webhook-pdns-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cert-manager-webhook-pdns-fips package. SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cert-manager-webhook-pdns-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cert-manager-webhook-pdns-fips package. SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad41794</guid>
    </item>
    <item>
      <title>EUVD-2026-261473</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261473</link>
      <description>EUVD-2026-261473</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261473</guid>
    </item>
    <item>
      <title>fkie_cve-2025-58181</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58181</link>
      <description>&lt;p&gt;SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-58181</guid>
    </item>
    <item>
      <title>GHSA-j5w8-q4qc-rx2x — golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j5w8-q4qc-rx2x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/crypto&lt;/p&gt;
&lt;p&gt;SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/crypto&lt;/p&gt;
&lt;p&gt;SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j5w8-q4qc-rx2x</guid>
    </item>
    <item>
      <title>OESA-2026-3398 — buildah security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3398</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: buildah&lt;/p&gt;
&lt;p&gt;The  package provides a command line tool which can be used to * create a working container from scratch or * create a working container from an image as a starting point * mount/umount a working container&amp;amp;amp;apos;s root file system for manipulation * save container&amp;amp;amp;apos;s root file system layer to create a new image * delete a working container or an image&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.(CVE-2025-47914)&lt;/p&gt;
&lt;p&gt;SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.(CVE-2025-58181)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: buildah&lt;/p&gt;
&lt;p&gt;The  package provides a command line tool which can be used to * create a working container from scratch or * create a working container from an image as a starting point * mount/umount a working container&amp;amp;amp;apos;s root file system for manipulation * save container&amp;amp;amp;apos;s root file system layer to create a new image * delete a working container or an image&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.(CVE-2025-47914)&lt;/p&gt;
&lt;p&gt;SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.(CVE-2025-58181)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3398</guid>
    </item>
    <item>
      <title>openSUSE-RU-2026:20010-1 — Recommended update for trivy</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-ru-2026:20010-1</link>
      <description>&lt;p&gt;Recommended update for trivy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for trivy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-ru-2026:20010-1</guid>
    </item>
    <item>
      <title>RHSA-2026:15979 — Red Hat Security Advisory: Red Hat Ceph Storage</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:15979</link>
      <description>&lt;p&gt;nodemailer: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate js-yaml: js-yaml prototype pollution in merge glob: glob: Command Injection Vulnerability via Malicious Filenames github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodemailer: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate js-yaml: js-yaml prototype pollution in merge glob: glob: Command Injection Vulnerability via Malicious Filenames github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:15979</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0439-1 — Security update for apptainer</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0439-1</link>
      <description>&lt;p&gt;Security update for apptainer&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for apptainer&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0439-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-58181</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58181</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: google-guest-agent, Ubuntu:Pro:16.04:LTS: golang-go.crypto, Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:16.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: golang-go.crypto, Ubuntu:Pro:18.04:LTS: google-guest-agent, Ubuntu:Pro:20.04:LTS: google-guest-agent, Ubuntu:Pro:20.04:LTS: snapd and 13 more&lt;/p&gt;
&lt;p&gt;SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: google-guest-agent, Ubuntu:Pro:16.04:LTS: golang-go.crypto, Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:16.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: golang-go.crypto, Ubuntu:Pro:18.04:LTS: google-guest-agent, Ubuntu:Pro:20.04:LTS: google-guest-agent, Ubuntu:Pro:20.04:LTS: snapd and 13 more&lt;/p&gt;
&lt;p&gt;SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58181</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2645 — Golang Go: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2645</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2645</guid>
    </item>
  </channel>
</rss>
