<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:05:27 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-13936</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-13936</link>
      <description>bdu:2025-13936</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-13936</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-61725</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-61725</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-61725</guid>
    </item>
    <item>
      <title>BIT-golang-2025-61725 — Excessive CPU consumption in ParseAddress in net/mail</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2025-61725</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2025-61725</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0966 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0966</link>
      <description>certfr-2025-avi-0966</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0966</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AB43319 — Security fixes for CVE-2025-47911, CVE-2025-58183, CVE-2025-58185, CVE-2025-58187, CVE-2025-58188, CVE-2025-58189, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ab43319</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stakater-reloader&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the stakater-reloader package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stakater-reloader&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the stakater-reloader package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ab43319</guid>
    </item>
    <item>
      <title>EUVD-2026-262980</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262980</link>
      <description>EUVD-2026-262980</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262980</guid>
    </item>
    <item>
      <title>fkie_cve-2025-61725</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-61725</link>
      <description>&lt;p&gt;The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-61725</guid>
    </item>
    <item>
      <title>GHSA-qh38-484v-w52x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qh38-484v-w52x</link>
      <description>&lt;p&gt;The ParseAddress function constructeds domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The ParseAddress function constructeds domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qh38-484v-w52x</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-61725 — Excessive CPU consumption in ParseAddress in net/mail</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-61725</link>
      <description>msrc_CVE-2025-61725</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-61725</guid>
    </item>
    <item>
      <title>OESA-2026-4067 — git-lfs security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4067</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: git-lfs&lt;/p&gt;
&lt;p&gt;Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Processing an incomplete post-handshake message for a QUIC connection can cause a panic.(CVE-2023-39321)&lt;/p&gt;
&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.(CVE-2023-39322)&lt;/p&gt;
&lt;p&gt;Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.(CVE-2025-22874)&lt;/p&gt;
&lt;p&gt;Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository&amp;amp;apos;s working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. The git lfs checkout and git lfs pull commands do not check for symbolic links before writing to files in the working tree, allowing an attacker to craft a repository containing symbolic or hard links that cause Git LFS to write to arbitrary file system locations accessible to the user running these comman…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: git-lfs&lt;/p&gt;
&lt;p&gt;Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Processing an incomplete post-handshake message for a QUIC connection can cause a panic.(CVE-2023-39321)&lt;/p&gt;
&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.(CVE-2023-39322)&lt;/p&gt;
&lt;p&gt;Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.(CVE-2025-22874)&lt;/p&gt;
&lt;p&gt;Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository&amp;amp;apos;s working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. The git lfs checkout and git lfs pull commands do not check for symbolic links before writing to files in the working tree, allowing an attacker to craft a repository containing symbolic or hard links that cause Git LFS to write to arbitrary file system locations accessible to the user running these comman…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4067</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15608-1 — go1.24-1.24.8-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15608-1</link>
      <description>&lt;p&gt;go1.24-1.24.8-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go1.24-1.24.8-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15608-1</guid>
    </item>
    <item>
      <title>RHSA-2026:7291 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:7291</link>
      <description>&lt;p&gt;os: os: Information disclosure via path traversal using specially crafted filenames net/http: CrossOriginProtection bypass in net/http golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html net/url: Insufficient validation of bracketed IPv6 hostnames in net/url golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication golang: archive/tar: Unbounded allocation when parsing GNU sparse map encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 golang.org/net/http: Lack of limit when parsing cookies can cause memory exhaustion in net/http crypto/x509: Quadratic complexity when checking name constraints in crypto/x509 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information golang.org/x/net/html: Infinite parsing loop in golang.org/x/net encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem net/textproto: Excessive CPU consumption in Reader.ReadResponse in net/textproto net/mail: Excessive CPU consumption in ParseAddress in net/mail golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs golang: archive/zip: Excessive CPU co…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;os: os: Information disclosure via path traversal using specially crafted filenames net/http: CrossOriginProtection bypass in net/http golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html net/url: Insufficient validation of bracketed IPv6 hostnames in net/url golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication golang: archive/tar: Unbounded allocation when parsing GNU sparse map encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 golang.org/net/http: Lack of limit when parsing cookies can cause memory exhaustion in net/http crypto/x509: Quadratic complexity when checking name constraints in crypto/x509 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information golang.org/x/net/html: Infinite parsing loop in golang.org/x/net encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem net/textproto: Excessive CPU consumption in Reader.ReadResponse in net/textproto net/mail: Excessive CPU consumption in ParseAddress in net/mail golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs golang: archive/zip: Excessive CPU co…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:7291</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21192-1 — Security update for go1.25</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21192-1</link>
      <description>&lt;p&gt;Security update for go1.25&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.25&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21192-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-61725</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-61725</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 26 more&lt;/p&gt;
&lt;p&gt;The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 26 more&lt;/p&gt;
&lt;p&gt;The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-61725</guid>
    </item>
    <item>
      <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-088</link>
      <description>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-088</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2227 — Golang Go: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2227</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Denial of Service Angriff durchzuführen  oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Denial of Service Angriff durchzuführen  oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2227</guid>
    </item>
  </channel>
</rss>
