<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:07:55 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: BELL-CVE-2025-66221 — CVE-2025-66221 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-66221</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-66221</guid>
    </item>
    <item>
      <title>BREW-aws-sam-cli-CVE-2025-66221 — Werkzeug safe_join() allows Windows special device names</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2025-66221</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aws-sam-cli&lt;/p&gt;
&lt;p&gt;Werkzeug&amp;#39;s `safe_join` function allows path segments with Windows device names. On Windows, there are special device names such as `CON`, `AUX`, etc that are implicitly present and readable in every directory. `send_from_directory` uses `safe_join` to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aws-sam-cli&lt;/p&gt;
&lt;p&gt;Werkzeug&amp;#39;s `safe_join` function allows path segments with Windows device names. On Windows, there are special device names such as `CON`, `AUX`, etc that are implicitly present and readable in every directory. `send_from_directory` uses `safe_join` to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2025-66221</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1064 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1064</link>
      <description>certfr-2025-avi-1064</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1064</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AZ09261 — Security fixes for CVE-2023-46136, CVE-2024-12797, CVE-2024-34069, CVE-2024-49766, CVE-2024-49767, CVE-2025-62727, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the airflow-3 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the airflow-3 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261</guid>
    </item>
    <item>
      <title>EUVD-2026-262100</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-262100</link>
      <description>EUVD-2026-262100</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-262100</guid>
    </item>
    <item>
      <title>fkie_cve-2025-66221</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-66221</link>
      <description>&lt;p&gt;Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug&amp;#39;s safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. send_from_directory uses safe_join to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely. This issue has been patched in version 3.1.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug&amp;#39;s safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. send_from_directory uses safe_join to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely. This issue has been patched in version 3.1.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-66221</guid>
    </item>
    <item>
      <title>GHSA-hgf8-39gv-g3f2 — Werkzeug safe_join() allows Windows special device names</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hgf8-39gv-g3f2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: werkzeug&lt;/p&gt;
&lt;p&gt;Werkzeug&amp;#39;s `safe_join` function allows path segments with Windows device names. On Windows, there are special device names such as `CON`, `AUX`, etc that are implicitly present and readable in every directory. `send_from_directory` uses `safe_join` to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: werkzeug&lt;/p&gt;
&lt;p&gt;Werkzeug&amp;#39;s `safe_join` function allows path segments with Windows device names. On Windows, there are special device names such as `CON`, `AUX`, etc that are implicitly present and readable in every directory. `send_from_directory` uses `safe_join` to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hgf8-39gv-g3f2</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-66221 — Werkzeug safe_join() allows Windows special device names</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-66221</link>
      <description>msrc_CVE-2025-66221</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-66221</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15848-1 — python311-openapi-core-0.22.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15848-1</link>
      <description>&lt;p&gt;python311-openapi-core-0.22.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-openapi-core-0.22.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15848-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2046 — Werkzeug safe_join() allows Windows special device names</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2046</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: werkzeug&lt;/p&gt;
&lt;p&gt;Werkzeug&amp;#39;s `safe_join` function allows path segments with Windows device names. On Windows, there are special device names such as `CON`, `AUX`, etc that are implicitly present and readable in every directory. `send_from_directory` uses `safe_join` to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: werkzeug&lt;/p&gt;
&lt;p&gt;Werkzeug&amp;#39;s `safe_join` function allows path segments with Windows device names. On Windows, there are special device names such as `CON`, `AUX`, etc that are implicitly present and readable in every directory. `send_from_directory` uses `safe_join` to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2046</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2025-66221</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-66221</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-werkzeug, Ubuntu:Pro:18.04:LTS: python-werkzeug, Ubuntu:20.04:LTS: python-werkzeug, Ubuntu:22.04:LTS: python-werkzeug, Ubuntu:24.04:LTS: python-werkzeug, Ubuntu:25.10: python-werkzeug, Ubuntu:25.04: python-werkzeug&lt;/p&gt;
&lt;p&gt;Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug&amp;#39;s safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. send_from_directory uses safe_join to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely. This issue has been patched in version 3.1.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-werkzeug, Ubuntu:Pro:18.04:LTS: python-werkzeug, Ubuntu:20.04:LTS: python-werkzeug, Ubuntu:22.04:LTS: python-werkzeug, Ubuntu:24.04:LTS: python-werkzeug, Ubuntu:25.10: python-werkzeug, Ubuntu:25.04: python-werkzeug&lt;/p&gt;
&lt;p&gt;Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug&amp;#39;s safe_join function allows path segments with Windows device names. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. send_from_directory uses safe_join to safely serve files at user-specified paths under a directory. If the application is running on Windows, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely. This issue has been patched in version 3.1.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-66221</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2933 — Splunk SOAR: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</guid>
    </item>
  </channel>
</rss>
