<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:08:07 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-253818</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-253818</link>
      <description>EUVD-2026-253818</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-253818</guid>
    </item>
    <item>
      <title>fkie_cve-2025-59937</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59937</link>
      <description>&lt;p&gt;go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of the mail.Address values when a sender- or recipient address is passed to the corresponding MAIL FROM or RCPT TO commands of the SMTP client, there is a possibility of wrong address routing or even ESMTP parameter smuggling. For successful exploitation, it is required that the user&amp;#39;s code allows for arbitrary mail address input (i. e. through a web form or similar). If only static mail addresses are used (i. e. in a config file) and the mail addresses in use do not consist of quoted local parts, this should not affect users. This issue is fixed in version 0.7.1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of the mail.Address values when a sender- or recipient address is passed to the corresponding MAIL FROM or RCPT TO commands of the SMTP client, there is a possibility of wrong address routing or even ESMTP parameter smuggling. For successful exploitation, it is required that the user&amp;#39;s code allows for arbitrary mail address input (i. e. through a web form or similar). If only static mail addresses are used (i. e. in a config file) and the mail addresses in use do not consist of quoted local parts, this should not affect users. This issue is fixed in version 0.7.1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-59937</guid>
    </item>
    <item>
      <title>GHSA-wpwj-69cm-q9c5 — go-mail has insufficient address encoding when passing mail addresses to the SMTP client</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wpwj-69cm-q9c5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/wneessen/go-mail&lt;/p&gt;
&lt;p&gt;### Impact
Due to incorrect handling of the `mail.Address` values when a sender- or recipient address is passed to the corresponding `MAIL FROM` or `RCPT TO` commands of the SMTP client, this could lead to a possible wrong address routing or even to ESMTP parameter smuggling.&lt;/p&gt;
&lt;p&gt;#### Vulnerability details
Instead of making use of the `String()` method of `mail.Address`, which takes care of proper escaping and quotation of mail address, we used the `Address` value of the `mail.Address` which is the raw value when passing it to our SMTP client.&lt;/p&gt;
&lt;p&gt;This meant, if a mail address like this was set: `&amp;#34;toni.tester@example.com&amp;gt; ORCPT=admin@admin.com&amp;#34;@example.com` for a sender or recipient, instead of the correctly quoted/escaped address, the SMTP client would get the raw value passed which would translate into something like this being passed to the SMTP server: `RCPT TO:&amp;lt;toni.tester@example.com&amp;gt; ORCPT=admin@admin.com@example.com&amp;gt;`.&lt;/p&gt;
&lt;p&gt;Since ORCTP is a valid command for the SMTP server, the mail would be routed to the wrong address. Additionally, other SMTP commands could potientially be smuggled in using this method causing unexpected behaviour.&lt;/p&gt;
&lt;p&gt;#### Exploitation requirements
For successful exploitation of this vulnerability it is required that the user&amp;#39;s code is allowing for arbitrary mail address input (i. e. through a web form or similar). If only static mail addresses are used (i. e. in a config file) and the mail addresses in use do not consist of quoted local parts, this should n…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/wneessen/go-mail&lt;/p&gt;
&lt;p&gt;### Impact
Due to incorrect handling of the `mail.Address` values when a sender- or recipient address is passed to the corresponding `MAIL FROM` or `RCPT TO` commands of the SMTP client, this could lead to a possible wrong address routing or even to ESMTP parameter smuggling.&lt;/p&gt;
&lt;p&gt;#### Vulnerability details
Instead of making use of the `String()` method of `mail.Address`, which takes care of proper escaping and quotation of mail address, we used the `Address` value of the `mail.Address` which is the raw value when passing it to our SMTP client.&lt;/p&gt;
&lt;p&gt;This meant, if a mail address like this was set: `&amp;#34;toni.tester@example.com&amp;gt; ORCPT=admin@admin.com&amp;#34;@example.com` for a sender or recipient, instead of the correctly quoted/escaped address, the SMTP client would get the raw value passed which would translate into something like this being passed to the SMTP server: `RCPT TO:&amp;lt;toni.tester@example.com&amp;gt; ORCPT=admin@admin.com@example.com&amp;gt;`.&lt;/p&gt;
&lt;p&gt;Since ORCTP is a valid command for the SMTP server, the mail would be routed to the wrong address. Additionally, other SMTP commands could potientially be smuggled in using this method causing unexpected behaviour.&lt;/p&gt;
&lt;p&gt;#### Exploitation requirements
For successful exploitation of this vulnerability it is required that the user&amp;#39;s code is allowing for arbitrary mail address input (i. e. through a web form or similar). If only static mail addresses are used (i. e. in a config file) and the mail addresses in use do not consist of quoted local parts, this should n…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wpwj-69cm-q9c5</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15710-1 — govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1</guid>
    </item>
  </channel>
</rss>
