<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:05:19 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00268</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00268</link>
      <description>bdu:2026-00268</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00268</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-61727</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-61727</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: docker, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: docker, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-61727</guid>
    </item>
    <item>
      <title>BIT-golang-2025-61727 — Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2025-61727</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2025-61727</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1078 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1078</link>
      <description>certfr-2025-avi-1078</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1078</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD15516 — Security fixes in prometheus-redis-exporter-fips 1.77.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad15516</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: prometheus-redis-exporter-fips&lt;/p&gt;
&lt;p&gt;Package prometheus-redis-exporter-fips version 1.77.0-r0 fixes 2 vulnerabilities: CVE-2025-61727, CVE-2025-61729&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: prometheus-redis-exporter-fips&lt;/p&gt;
&lt;p&gt;Package prometheus-redis-exporter-fips version 1.77.0-r0 fixes 2 vulnerabilities: CVE-2025-61727, CVE-2025-61729&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad15516</guid>
    </item>
    <item>
      <title>EUVD-2026-262521</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262521</link>
      <description>EUVD-2026-262521</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262521</guid>
    </item>
    <item>
      <title>fkie_cve-2025-61727</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-61727</link>
      <description>&lt;p&gt;An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-61727</guid>
    </item>
    <item>
      <title>GHSA-5mh9-3jwc-rp59</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5mh9-3jwc-rp59</link>
      <description>&lt;p&gt;An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5mh9-3jwc-rp59</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-61727 — Improper application of excluded DNS name constraints when verifying wildcard names in crypto/x509</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-61727</link>
      <description>msrc_CVE-2025-61727</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-61727</guid>
    </item>
    <item>
      <title>OESA-2025-2863 — golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2863</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: golang&lt;/p&gt;
&lt;p&gt;.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;crypto/x509: Exclude subdomain constraints do not restrict wildcard SANs Exclude subdomain constraints in certificate chains do not restrict the use of wildcard SANs in leaf certificates. For example, excluding the constraint on the subdomain test.example.com does not prevent the leaf certificate from claiming SAN*. example.com.(CVE-2025-61727)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: golang&lt;/p&gt;
&lt;p&gt;.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;crypto/x509: Exclude subdomain constraints do not restrict wildcard SANs Exclude subdomain constraints in certificate chains do not restrict the use of wildcard SANs in leaf certificates. For example, excluding the constraint on the subdomain test.example.com does not prevent the leaf certificate from claiming SAN*. example.com.(CVE-2025-61727)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2863</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15795-1 — go1.25-1.25.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15795-1</link>
      <description>&lt;p&gt;go1.25-1.25.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go1.25-1.25.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15795-1</guid>
    </item>
    <item>
      <title>RHSA-2026:0990 — Red Hat Security Advisory: cert-manager Operator for Red Hat OpenShift 1.18.1</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:0990</link>
      <description>&lt;p&gt;golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:0990</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21192-1 — Security update for go1.25</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21192-1</link>
      <description>&lt;p&gt;Security update for go1.25&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.25&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21192-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-61727</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-61727</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-1.24, Ubuntu:24.04:LTS: golang-1.24, Ubuntu:25.10: golang-1.24, Ubuntu:25.10: golang-1.25, Ubuntu:26.04:LTS: golang-1.24, Ubuntu:26.04:LTS: golang-1.25&lt;/p&gt;
&lt;p&gt;An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-1.24, Ubuntu:24.04:LTS: golang-1.24, Ubuntu:25.10: golang-1.24, Ubuntu:25.10: golang-1.25, Ubuntu:26.04:LTS: golang-1.24, Ubuntu:26.04:LTS: golang-1.25&lt;/p&gt;
&lt;p&gt;An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-61727</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2724 — Golang Go: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2724</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2724</guid>
    </item>
  </channel>
</rss>
