<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 11:04:55 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:47085 — Important: rest security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:47085</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: rest, AlmaLinux:10: rest-devel&lt;/p&gt;
&lt;p&gt;The rest packages provide a library for access to the RESTful web services.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* librest: weak random number generation in PKCE implementation (CVE-2026-16615)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: rest, AlmaLinux:10: rest-devel&lt;/p&gt;
&lt;p&gt;The rest packages provide a library for access to the RESTful web services.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* librest: weak random number generation in PKCE implementation (CVE-2026-16615)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:47085</guid>
    </item>
    <item>
      <title>EUVD-2026-362657</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362657</link>
      <description>EUVD-2026-362657</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362657</guid>
    </item>
    <item>
      <title>fkie_cve-2026-16615</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-16615</link>
      <description>&lt;p&gt;A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated &amp;#34;code verifier&amp;#34; lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated &amp;#34;code verifier&amp;#34; lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-16615</guid>
    </item>
    <item>
      <title>GHSA-223h-642r-2f6v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-223h-642r-2f6v</link>
      <description>&lt;p&gt;A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated &amp;#34;code verifier&amp;#34; lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated &amp;#34;code verifier&amp;#34; lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-223h-642r-2f6v</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-16615 — Librest: weak random number generation in pkce implementation</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-16615</link>
      <description>msrc_CVE-2026-16615</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-16615</guid>
    </item>
    <item>
      <title>OESA-2026-3974 — rest security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3974</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: rest&lt;/p&gt;
&lt;p&gt;This library has been designed to make it easier to access web services that claim to be &amp;amp;amp;quot;RESTful&amp;amp;amp;quot;. It comprises of two parts: the first aims to make it easier to make requests by providing a wrapper around libsoup, the second aids with XML parsing by wrapping libxml2.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated &amp;amp;quot;code verifier&amp;amp;quot; lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.(CVE-2026-16615)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: rest&lt;/p&gt;
&lt;p&gt;This library has been designed to make it easier to access web services that claim to be &amp;amp;amp;quot;RESTful&amp;amp;amp;quot;. It comprises of two parts: the first aims to make it easier to make requests by providing a wrapper around libsoup, the second aids with XML parsing by wrapping libxml2.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated &amp;amp;quot;code verifier&amp;amp;quot; lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.(CVE-2026-16615)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3974</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11477-1 — librest-1_0-0-0.10.2-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11477-1</link>
      <description>&lt;p&gt;librest-1_0-0-0.10.2-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;librest-1_0-0-0.10.2-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11477-1</guid>
    </item>
    <item>
      <title>RHSA-2026:62222 — Red Hat Security Advisory: rest security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:62222</link>
      <description>&lt;p&gt;librest: weak random number generation in PKCE implementation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;librest: weak random number generation in PKCE implementation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:62222</guid>
    </item>
    <item>
      <title>RLSA-2026:47085 — Important: rest security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:47085</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: rest&lt;/p&gt;
&lt;p&gt;The rest packages provide a library for access to the RESTful web services.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* librest: weak random number generation in PKCE implementation (CVE-2026-16615)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: rest&lt;/p&gt;
&lt;p&gt;The rest packages provide a library for access to the RESTful web services.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* librest: weak random number generation in PKCE implementation (CVE-2026-16615)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:47085</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23564-1 — Security update for librest</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23564-1</link>
      <description>&lt;p&gt;Security update for librest&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for librest&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23564-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-16615</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16615</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: librest, Ubuntu:18.04:LTS: librest, Ubuntu:20.04:LTS: librest, Ubuntu:22.04:LTS: librest, Ubuntu:24.04:LTS: librest, Ubuntu:26.04:LTS: librest&lt;/p&gt;
&lt;p&gt;A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated &amp;#34;code verifier&amp;#34; lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: librest, Ubuntu:18.04:LTS: librest, Ubuntu:20.04:LTS: librest, Ubuntu:22.04:LTS: librest, Ubuntu:24.04:LTS: librest, Ubuntu:26.04:LTS: librest&lt;/p&gt;
&lt;p&gt;A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated &amp;#34;code verifier&amp;#34; lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16615</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2553 — Red Hat Enterprise Linux (librest, pipewire): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2553</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen und beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen und beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2553</guid>
    </item>
  </channel>
</rss>
