<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:01:54 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-24686</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-24686</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: docker-cli-buildx&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: docker-cli-buildx&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-24686</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-AP98474 — Security fix for CVE-2026-24686 applied in: cosign 2.4.3-r0, cosign 2.5.3-r0, kubescape 3.0.47-r0, policy-controller 0.…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ap98474</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cosign, CleanStart: kubescape, CleanStart: policy-controller, CleanStart: sigstore-scaffolding, CleanStart: tkn&lt;/p&gt;
&lt;p&gt;CVE-2026-24686 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cosign, CleanStart: kubescape, CleanStart: policy-controller, CleanStart: sigstore-scaffolding, CleanStart: tkn&lt;/p&gt;
&lt;p&gt;CVE-2026-24686 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ap98474</guid>
    </item>
    <item>
      <title>EUVD-2026-266646</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266646</link>
      <description>EUVD-2026-266646</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266646</guid>
    </item>
    <item>
      <title>fkie_cve-2026-24686</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24686</link>
      <description>&lt;p&gt;go-tuf is a Go implementation of The Update Framework (TUF). go-tuf&amp;#39;s TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. Starting in version 2.0.0 and prior to version 2.4.1, if an application accepts a map file from an untrusted source, an attacker can supply a `repoName` containing traversal (e.g., `../escaped-repo`) and cause go-tuf to create directories and write the root metadata file outside the intended `LocalMetadataDir` cache base, within the running process&amp;#39;s filesystem permissions. Version 2.4.1 contains a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go-tuf is a Go implementation of The Update Framework (TUF). go-tuf&amp;#39;s TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. Starting in version 2.0.0 and prior to version 2.4.1, if an application accepts a map file from an untrusted source, an attacker can supply a `repoName` containing traversal (e.g., `../escaped-repo`) and cause go-tuf to create directories and write the root metadata file outside the intended `LocalMetadataDir` cache base, within the running process&amp;#39;s filesystem permissions. Version 2.4.1 contains a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-24686</guid>
    </item>
    <item>
      <title>GHSA-jqc5-w2xx-5vq4 — go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jqc5-w2xx-5vq4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/theupdateframework/go-tuf/v2&lt;/p&gt;
&lt;p&gt;# Security Vulnerability: Path Traversal in TAP 4 Multirepo Client&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;go-tuf&amp;#39;s TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. If an application accepts a map file from an untrusted source, an attacker can supply a `repoName` containing traversal (e.g., `../escaped-repo`) and cause go-tuf to create directories and write the root metadata file outside the intended `LocalMetadataDir` cache base, within the running process&amp;#39;s filesystem permissions.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;| Field | Value |
|-------|-------|
| **File** | `metadata/multirepo/multirepo.go` |
| **Function** | `(*MultiRepoClient) initTUFClients() error` |
| **Callsite** | `metadataDir := filepath.Join(client.Config.LocalMetadataDir, repoName)` (around line 129 at the pinned commit) |&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;When the TAP 4 map file content is attacker-controlled, this enables arbitrary file write relative to the process permissions (via metadata persistence during client initialization). This can be used to overwrite files writable by the process (for example, configuration files in writable directories) and may enable further compromise depending on the deployment environment.&lt;/p&gt;
&lt;p&gt;&amp;gt; **Note:** Exploitability is deployment-dependent. If the map file is always local and trusted (not attacker-controlled), this reduces to a misconfiguration risk rather than a remotely triggerable issue.&lt;/p&gt;
&lt;p&gt;## Attacker Model&lt;/p&gt;
&lt;p&gt;- Attacker…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/theupdateframework/go-tuf/v2&lt;/p&gt;
&lt;p&gt;# Security Vulnerability: Path Traversal in TAP 4 Multirepo Client&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;go-tuf&amp;#39;s TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. If an application accepts a map file from an untrusted source, an attacker can supply a `repoName` containing traversal (e.g., `../escaped-repo`) and cause go-tuf to create directories and write the root metadata file outside the intended `LocalMetadataDir` cache base, within the running process&amp;#39;s filesystem permissions.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;| Field | Value |
|-------|-------|
| **File** | `metadata/multirepo/multirepo.go` |
| **Function** | `(*MultiRepoClient) initTUFClients() error` |
| **Callsite** | `metadataDir := filepath.Join(client.Config.LocalMetadataDir, repoName)` (around line 129 at the pinned commit) |&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;When the TAP 4 map file content is attacker-controlled, this enables arbitrary file write relative to the process permissions (via metadata persistence during client initialization). This can be used to overwrite files writable by the process (for example, configuration files in writable directories) and may enable further compromise depending on the deployment environment.&lt;/p&gt;
&lt;p&gt;&amp;gt; **Note:** Exploitability is deployment-dependent. If the map file is always local and trusted (not attacker-controlled), this reduces to a misconfiguration risk rather than a remotely triggerable issue.&lt;/p&gt;
&lt;p&gt;## Attacker Model&lt;/p&gt;
&lt;p&gt;- Attacker…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jqc5-w2xx-5vq4</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10664-1 — kyverno-1.18.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10664-1</link>
      <description>&lt;p&gt;kyverno-1.18.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kyverno-1.18.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10664-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-24686</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24686</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-theupdateframework-go-tuf, Ubuntu:25.10: golang-github-theupdateframework-go-tuf, Ubuntu:26.04:LTS: golang-github-theupdateframework-go-tuf&lt;/p&gt;
&lt;p&gt;go-tuf is a Go implementation of The Update Framework (TUF). go-tuf&amp;#39;s TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. Starting in version 2.0.0 and prior to version 2.4.1, if an application accepts a map file from an untrusted source, an attacker can supply a `repoName` containing traversal (e.g., `../escaped-repo`) and cause go-tuf to create directories and write the root metadata file outside the intended `LocalMetadataDir` cache base, within the running process&amp;#39;s filesystem permissions. Version 2.4.1 contains a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-theupdateframework-go-tuf, Ubuntu:25.10: golang-github-theupdateframework-go-tuf, Ubuntu:26.04:LTS: golang-github-theupdateframework-go-tuf&lt;/p&gt;
&lt;p&gt;go-tuf is a Go implementation of The Update Framework (TUF). go-tuf&amp;#39;s TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. Starting in version 2.0.0 and prior to version 2.4.1, if an application accepts a map file from an untrusted source, an attacker can supply a `repoName` containing traversal (e.g., `../escaped-repo`) and cause go-tuf to create directories and write the root metadata file outside the intended `LocalMetadataDir` cache base, within the running process&amp;#39;s filesystem permissions. Version 2.4.1 contains a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-24686</guid>
    </item>
  </channel>
</rss>
