<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:43:55 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:23664 — Important: opentelemetry-collector security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:23664</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: opentelemetry-collector&lt;/p&gt;
&lt;p&gt;Collector with the supported components for a AlmaLinux build of OpenTelemetry&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation (CVE-2025-68156)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: opentelemetry-collector&lt;/p&gt;
&lt;p&gt;Collector with the supported components for a AlmaLinux build of OpenTelemetry&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation (CVE-2025-68156)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:23664</guid>
    </item>
    <item>
      <title>bdu:2026-05696</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05696</link>
      <description>bdu:2026-05696</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05696</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0627 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0627</link>
      <description>certfr-2026-avi-0627</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0627</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CF63541 — Security fixes in eks-distro-coredns-fips 1.35.7-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cf63541</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: eks-distro-coredns-fips&lt;/p&gt;
&lt;p&gt;Package eks-distro-coredns-fips version 1.35.7-r0 fixes 6 vulnerabilities: ghsa-cfpf-hrx2-8rv6, ghsa-p77j-4mvh-x3m3, ghsa-9h8m-3fm2-qjrq, CVE-2025-68156, CVE-2026-24051...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: eks-distro-coredns-fips&lt;/p&gt;
&lt;p&gt;Package eks-distro-coredns-fips version 1.35.7-r0 fixes 6 vulnerabilities: ghsa-cfpf-hrx2-8rv6, ghsa-p77j-4mvh-x3m3, ghsa-9h8m-3fm2-qjrq, CVE-2025-68156, CVE-2026-24051...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cf63541</guid>
    </item>
    <item>
      <title>EUVD-2026-263789</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-263789</link>
      <description>EUVD-2026-263789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-263789</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68156</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68156</link>
      <description>&lt;p&gt;Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the evaluation environment contains deeply nested or cyclic data structures, these functions may recurse indefinitely until exceed the Go runtime stack limit. This results in a stack overflow panic, causing the host application to crash. While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the
evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness. Instead of returning a recoverable evaluation error, the process may terminate unexpectedly. In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently validated data structures can lead to a process-level crash due to stack exhaustion. This issue is most relevant in scenarios where Expr is used to evaluate expressions against externally supplied or dynamically constructed environments; cyclic references (directly or indirectly) can be introduced into arrays, maps, or structs; and there are no application-level safeguards preventing deeply nested input data. In typical use cases with controlled, acyclic data, the issue may not manifest. However, when present, th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform recursive traversal over user-provided data structures without enforcing a maximum recursion depth. If the evaluation environment contains deeply nested or cyclic data structures, these functions may recurse indefinitely until exceed the Go runtime stack limit. This results in a stack overflow panic, causing the host application to crash. While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the
evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness. Instead of returning a recoverable evaluation error, the process may terminate unexpectedly. In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently validated data structures can lead to a process-level crash due to stack exhaustion. This issue is most relevant in scenarios where Expr is used to evaluate expressions against externally supplied or dynamically constructed environments; cyclic references (directly or indirectly) can be introduced into arrays, maps, or structs; and there are no application-level safeguards preventing deeply nested input data. In typical use cases with controlled, acyclic data, the issue may not manifest. However, when present, th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68156</guid>
    </item>
    <item>
      <title>GHSA-cfpf-hrx2-8rv6 — Expr has Denial of Service via Unbounded Recursion in Builtin Functions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cfpf-hrx2-8rv6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/expr-lang/expr&lt;/p&gt;
&lt;p&gt;Several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform
recursive traversal over user-provided data structures without enforcing a maximum recursion depth.&lt;/p&gt;
&lt;p&gt;If the evaluation environment contains **deeply nested** or **cyclic** data structures, these functions may recurse
indefinitely until exceed the Go runtime stack limit. This results in a **stack overflow panic**, causing the host
application to crash.&lt;/p&gt;
&lt;p&gt;While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the
evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness.
Instead of returning a recoverable evaluation error, the process may terminate unexpectedly.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently
validated data structures can lead to a **process-level crash** due to stack exhaustion.&lt;/p&gt;
&lt;p&gt;This issue is most relevant in scenarios where:&lt;/p&gt;
&lt;p&gt;* Expr is used to evaluate expressions against externally supplied or dynamically constructed environments.
* Cyclic references (directly or indirectly) can be introduced into arrays, maps, or structs.
* There are no application-level safeguards preventing deeply nested input data.&lt;/p&gt;
&lt;p&gt;In typical use cases with controlled, acyclic data, the issue may not manifest. However, when present, the resulting
panic can be used to reliably crash the a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/expr-lang/expr&lt;/p&gt;
&lt;p&gt;Several builtin functions in Expr, including `flatten`, `min`, `max`, `mean`, and `median`, perform
recursive traversal over user-provided data structures without enforcing a maximum recursion depth.&lt;/p&gt;
&lt;p&gt;If the evaluation environment contains **deeply nested** or **cyclic** data structures, these functions may recurse
indefinitely until exceed the Go runtime stack limit. This results in a **stack overflow panic**, causing the host
application to crash.&lt;/p&gt;
&lt;p&gt;While exploitability depends on whether an attacker can influence or inject cyclic or pathologically deep data into the
evaluation environment, this behavior represents a denial-of-service (DoS) risk and affects overall library robustness.
Instead of returning a recoverable evaluation error, the process may terminate unexpectedly.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In affected versions, evaluation of expressions that invoke certain builtin functions on untrusted or insufficiently
validated data structures can lead to a **process-level crash** due to stack exhaustion.&lt;/p&gt;
&lt;p&gt;This issue is most relevant in scenarios where:&lt;/p&gt;
&lt;p&gt;* Expr is used to evaluate expressions against externally supplied or dynamically constructed environments.
* Cyclic references (directly or indirectly) can be introduced into arrays, maps, or structs.
* There are no application-level safeguards preventing deeply nested input data.&lt;/p&gt;
&lt;p&gt;In typical use cases with controlled, acyclic data, the issue may not manifest. However, when present, the resulting
panic can be used to reliably crash the a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cfpf-hrx2-8rv6</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-68156 — Expr has Denial of Service via Unbounded Recursion in Builtin Functions</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-68156</link>
      <description>msrc_CVE-2025-68156</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-68156</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15825-1 — coredns-for-k8s1.33-1.12.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15825-1</link>
      <description>&lt;p&gt;coredns-for-k8s1.33-1.12.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;coredns-for-k8s1.33-1.12.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15825-1</guid>
    </item>
    <item>
      <title>RHSA-2025:23664 — Red Hat Security Advisory: opentelemetry-collector security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:23664</link>
      <description>&lt;p&gt;github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:23664</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0628-1 — Security update 5.1.2 for Multi-Linux Manager Client Tools</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0628-1</link>
      <description>&lt;p&gt;Security update 5.1.2 for Multi-Linux Manager Client Tools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update 5.1.2 for Multi-Linux Manager Client Tools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0628-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2886 — Red Hat Enterprise Linux (git-lfs, opentelemetry-collector): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2886</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Dateien zu manipulieren und einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Dateien zu manipulieren und einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2886</guid>
    </item>
  </channel>
</rss>
