<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:41:24 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-14525</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14525</link>
      <description>bdu:2025-14525</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14525</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-58188</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-58188</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-58188</guid>
    </item>
    <item>
      <title>BIT-golang-2025-58188 — Panic when validating certificates with DSA public keys in crypto/x509</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2025-58188</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2025-58188</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0966 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0966</link>
      <description>certfr-2025-avi-0966</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0966</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AB43319 — Security fixes for CVE-2025-47911, CVE-2025-58183, CVE-2025-58185, CVE-2025-58187, CVE-2025-58188, CVE-2025-58189, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ab43319</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stakater-reloader&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the stakater-reloader package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stakater-reloader&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the stakater-reloader package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ab43319</guid>
    </item>
    <item>
      <title>EUVD-2026-260053</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260053</link>
      <description>EUVD-2026-260053</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260053</guid>
    </item>
    <item>
      <title>fkie_cve-2025-58188</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58188</link>
      <description>&lt;p&gt;Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-58188</guid>
    </item>
    <item>
      <title>GHSA-7wwx-xj66-r44x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7wwx-xj66-r44x</link>
      <description>&lt;p&gt;Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7wwx-xj66-r44x</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-58188 — Panic when validating certificates with DSA public keys in crypto/x509</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-58188</link>
      <description>msrc_CVE-2025-58188</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-58188</guid>
    </item>
    <item>
      <title>OESA-2025-2649 — golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2649</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: golang&lt;/p&gt;
&lt;p&gt;.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;tar.Reader in the Go archive/tar component did not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions could cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input could result in large allocations.(CVE-2025-58183)&lt;/p&gt;
&lt;p&gt;In Go before 1.24.8 and 1.25.x before 1.25.2, when parsing DER payloads, memories were being allocated prior to fully validating the payloads. This permits an attacker to craft a big empty DER payload to cause memory exhaustion in functions such as asn1.Unmarshal, x509.ParseCertificateRequest, and ocsp.ParseResponse.(CVE-2025-58185)&lt;/p&gt;
&lt;p&gt;Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.(CVE-2025-58188)&lt;/p&gt;
&lt;p&gt;In Go before 1.24.8 and 1.25.x before 1.25.2, When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped. The impact for this is relatively limited.(CVE-2025-58189)&lt;/p&gt;
&lt;p&gt;In Go before 1.24.8 and 1.25.x before 1.25.2, The Reader.ReadResponse function constructed a response string through repeated string concatenation of lines. When the number of lines in a response is large…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: golang&lt;/p&gt;
&lt;p&gt;.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;tar.Reader in the Go archive/tar component did not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions could cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input could result in large allocations.(CVE-2025-58183)&lt;/p&gt;
&lt;p&gt;In Go before 1.24.8 and 1.25.x before 1.25.2, when parsing DER payloads, memories were being allocated prior to fully validating the payloads. This permits an attacker to craft a big empty DER payload to cause memory exhaustion in functions such as asn1.Unmarshal, x509.ParseCertificateRequest, and ocsp.ParseResponse.(CVE-2025-58185)&lt;/p&gt;
&lt;p&gt;Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.(CVE-2025-58188)&lt;/p&gt;
&lt;p&gt;In Go before 1.24.8 and 1.25.x before 1.25.2, When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped. The impact for this is relatively limited.(CVE-2025-58189)&lt;/p&gt;
&lt;p&gt;In Go before 1.24.8 and 1.25.x before 1.25.2, The Reader.ReadResponse function constructed a response string through repeated string concatenation of lines. When the number of lines in a response is large…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2649</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15608-1 — go1.24-1.24.8-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15608-1</link>
      <description>&lt;p&gt;go1.24-1.24.8-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go1.24-1.24.8-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15608-1</guid>
    </item>
    <item>
      <title>RHSA-2026:7291 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:7291</link>
      <description>&lt;p&gt;os: os: Information disclosure via path traversal using specially crafted filenames net/http: CrossOriginProtection bypass in net/http golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html net/url: Insufficient validation of bracketed IPv6 hostnames in net/url golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication golang: archive/tar: Unbounded allocation when parsing GNU sparse map encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 golang.org/net/http: Lack of limit when parsing cookies can cause memory exhaustion in net/http crypto/x509: Quadratic complexity when checking name constraints in crypto/x509 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information golang.org/x/net/html: Infinite parsing loop in golang.org/x/net encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem net/textproto: Excessive CPU consumption in Reader.ReadResponse in net/textproto net/mail: Excessive CPU consumption in ParseAddress in net/mail golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs golang: archive/zip: Excessive CPU co…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;os: os: Information disclosure via path traversal using specially crafted filenames net/http: CrossOriginProtection bypass in net/http golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html net/url: Insufficient validation of bracketed IPv6 hostnames in net/url golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication golang: archive/tar: Unbounded allocation when parsing GNU sparse map encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 golang.org/net/http: Lack of limit when parsing cookies can cause memory exhaustion in net/http crypto/x509: Quadratic complexity when checking name constraints in crypto/x509 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information golang.org/x/net/html: Infinite parsing loop in golang.org/x/net encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem net/textproto: Excessive CPU consumption in Reader.ReadResponse in net/textproto net/mail: Excessive CPU consumption in ParseAddress in net/mail golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs golang: archive/zip: Excessive CPU co…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:7291</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21192-1 — Security update for go1.25</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21192-1</link>
      <description>&lt;p&gt;Security update for go1.25&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.25&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21192-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-58188</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58188</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 26 more&lt;/p&gt;
&lt;p&gt;Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 26 more&lt;/p&gt;
&lt;p&gt;Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58188</guid>
    </item>
    <item>
      <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-088</link>
      <description>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-088</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2227 — Golang Go: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2227</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Denial of Service Angriff durchzuführen  oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Denial of Service Angriff durchzuführen  oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2227</guid>
    </item>
  </channel>
</rss>
