<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:41:41 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-01060</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01060</link>
      <description>bdu:2026-01060</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01060</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-23991</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-23991</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: docker-cli-buildx&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: docker-cli-buildx&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-23991</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BA61304 — Security fixes in cosign 2.4.3-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ba61304</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cosign&lt;/p&gt;
&lt;p&gt;Package cosign version 2.4.3-r0 fixes 82 vulnerabilities: CVE-2025-0913, CVE-2025-15558, CVE-2025-22868, CVE-2025-22869, CVE-2025-22870...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cosign&lt;/p&gt;
&lt;p&gt;Package cosign version 2.4.3-r0 fixes 82 vulnerabilities: CVE-2025-0913, CVE-2025-15558, CVE-2025-22868, CVE-2025-22869, CVE-2025-22870...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ba61304</guid>
    </item>
    <item>
      <title>EUVD-2026-266317</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266317</link>
      <description>EUVD-2026-266317</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266317</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23991</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23991</link>
      <description>&lt;p&gt;go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23991</guid>
    </item>
    <item>
      <title>GHSA-846p-jg2w-w324 — go-tuf affected by client DoS via malformed server response</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-846p-jg2w-w324</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/theupdateframework/go-tuf/v2&lt;/p&gt;
&lt;p&gt;# Security Disclosure: Client DoS via malformed server response&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic _during parsing_, causing a DoS. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Client crashes upon receiving and parsing malformed TUF metadata. This can cause long running services to enter an restart/crash loop.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;None currently.&lt;/p&gt;
&lt;p&gt;## Affected code&lt;/p&gt;
&lt;p&gt;The `metadata.checkType` function did not properly type assert the (untrusted) input causing it to panic on malformed data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/theupdateframework/go-tuf/v2&lt;/p&gt;
&lt;p&gt;# Security Disclosure: Client DoS via malformed server response&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;If the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic _during parsing_, causing a DoS. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Client crashes upon receiving and parsing malformed TUF metadata. This can cause long running services to enter an restart/crash loop.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;None currently.&lt;/p&gt;
&lt;p&gt;## Affected code&lt;/p&gt;
&lt;p&gt;The `metadata.checkType` function did not properly type assert the (untrusted) input causing it to panic on malformed data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-846p-jg2w-w324</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10235-1 — cosign-3.0.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10235-1</link>
      <description>&lt;p&gt;cosign-3.0.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cosign-3.0.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10235-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:20904-1 — Security update for cosign</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:20904-1</link>
      <description>&lt;p&gt;Security update for cosign&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for cosign&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:20904-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-23991</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23991</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-theupdateframework-go-tuf, Ubuntu:25.10: golang-github-theupdateframework-go-tuf, Ubuntu:26.04:LTS: golang-github-theupdateframework-go-tuf&lt;/p&gt;
&lt;p&gt;go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-theupdateframework-go-tuf, Ubuntu:25.10: golang-github-theupdateframework-go-tuf, Ubuntu:26.04:LTS: golang-github-theupdateframework-go-tuf&lt;/p&gt;
&lt;p&gt;go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic happens before any signature is validated. This means that a compromised repository/mirror/cache can DoS clients without having access to any signing key. Version 2.3.1 fixes the issue. No known workarounds are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23991</guid>
    </item>
  </channel>
</rss>
