<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 05:36:43 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0315 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0315</link>
      <description>certfr-2026-avi-0315</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0315</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BA61304 — Security fixes in cosign 2.4.3-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ba61304</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cosign&lt;/p&gt;
&lt;p&gt;Package cosign version 2.4.3-r0 fixes 82 vulnerabilities: CVE-2025-0913, CVE-2025-15558, CVE-2025-22868, CVE-2025-22869, CVE-2025-22870...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cosign&lt;/p&gt;
&lt;p&gt;Package cosign version 2.4.3-r0 fixes 82 vulnerabilities: CVE-2025-0913, CVE-2025-15558, CVE-2025-22868, CVE-2025-22869, CVE-2025-22870...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ba61304</guid>
    </item>
    <item>
      <title>EUVD-2026-266512</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266512</link>
      <description>EUVD-2026-266512</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266512</guid>
    </item>
    <item>
      <title>fkie_cve-2026-24117</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24117</link>
      <description>&lt;p&gt;Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. The issue has been fixed in version 1.5.0. To workaround this issue, disable the search endpoint with --enable_retrieve_api=false.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. The issue has been fixed in version 1.5.0. To workaround this issue, disable the search endpoint with --enable_retrieve_api=false.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-24117</guid>
    </item>
    <item>
      <title>GHSA-4c4x-jm2x-pf9j — Rekor affected by Server-Side Request Forgery (SSRF) via provided public key URL</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4c4x-jm2x-pf9j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/sigstore/rekor&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`/api/v1/index/retrieve` supports retrieving a public key via a user-provided URL, allowing attackers to trigger SSRF to arbitrary internal services.&lt;/p&gt;
&lt;p&gt;Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through [Blind SSRF](https://portswigger.net/web-security/ssrf/blind).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;* SSRF to cloud metadata (169.254.169.254)
* SSRF to internal Kubernetes APIs
* SSRF to any service accessible from Fulcio&amp;#39;s network&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Upgrade to v1.5.0. Note that this is a breaking change to the search API and fully disables lookups by URL. If you require this feature, please reach out and we can discuss alternatives.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Disable the search endpoint with `--enable_retrieve_api=false`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/sigstore/rekor&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`/api/v1/index/retrieve` supports retrieving a public key via a user-provided URL, allowing attackers to trigger SSRF to arbitrary internal services.&lt;/p&gt;
&lt;p&gt;Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through [Blind SSRF](https://portswigger.net/web-security/ssrf/blind).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;* SSRF to cloud metadata (169.254.169.254)
* SSRF to internal Kubernetes APIs
* SSRF to any service accessible from Fulcio&amp;#39;s network&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Upgrade to v1.5.0. Note that this is a breaking change to the search API and fully disables lookups by URL. If you require this feature, please reach out and we can discuss alternatives.&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;Disable the search endpoint with `--enable_retrieve_api=false`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4c4x-jm2x-pf9j</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10127-1 — rekor-1.5.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10127-1</link>
      <description>&lt;p&gt;rekor-1.5.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rekor-1.5.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10127-1</guid>
    </item>
    <item>
      <title>RHSA-2026:37387 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.0 security, enhancement &amp; bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:37387</link>
      <description>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation containerd: containerd has an integer overflow in User ID handling runc: runc can be tricked into creating empty files/directories on host noobaa-core: Excessive permissions of /etc could lead to escalation of privilege in the noobaa-core container go-git: argument injection via the URL field go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects github.com/moby/moby: Moby&amp;#39;s Firewalld reload removes bridge network isolation github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation github.com/sigstore/rekor: Rekor denial of service github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation containerd: containerd has an integer overflow in User ID handling runc: runc can be tricked into creating empty files/directories on host noobaa-core: Excessive permissions of /etc could lead to escalation of privilege in the noobaa-core container go-git: argument injection via the URL field go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects github.com/moby/moby: Moby&amp;#39;s Firewalld reload removes bridge network isolation github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation github.com/sigstore/rekor: Rekor denial of service github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:37387</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-24117</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24117</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: rekor, Ubuntu:Pro:26.04:LTS: rekor&lt;/p&gt;
&lt;p&gt;Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. The issue has been fixed in version 1.5.0. To workaround this issue, disable the search endpoint with --enable_retrieve_api=false.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: rekor, Ubuntu:Pro:26.04:LTS: rekor&lt;/p&gt;
&lt;p&gt;Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since the SSRF only can trigger GET requests, the request cannot mutate state. The response from the GET request is not returned to the caller so data exfiltration is not possible. A malicious actor could attempt to probe an internal network through Blind SSRF. The issue has been fixed in version 1.5.0. To workaround this issue, disable the search endpoint with --enable_retrieve_api=false.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24117</guid>
    </item>
  </channel>
</rss>
