<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:43:11 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:11412 — Important: yggdrasil-worker-package-manager security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:11412</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: yggdrasil-worker-package-manager&lt;/p&gt;
&lt;p&gt;yggdrasil-worker-package-manager is a simple package manager yggd worker. It knows how to install and remove packages, add, remove, enable and disable repositories, and does rudimentary detection of the host it is running on to guess the package manager to use. It only installs packages that match one of the provided allow-pattern regular expressions.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: yggdrasil-worker-package-manager&lt;/p&gt;
&lt;p&gt;yggdrasil-worker-package-manager is a simple package manager yggd worker. It knows how to install and remove packages, add, remove, enable and disable repositories, and does rudimentary detection of the host it is running on to guess the package manager to use. It only installs packages that match one of the provided allow-pattern regular expressions.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:11412</guid>
    </item>
    <item>
      <title>bdu:2026-04127</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04127</link>
      <description>bdu:2026-04127</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04127</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-25679</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-25679</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-25679</guid>
    </item>
    <item>
      <title>BIT-golang-2026-25679 — Incorrect parsing of IPv6 host literals in net/url</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2026-25679</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2026-25679</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0315 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0315</link>
      <description>certfr-2026-avi-0315</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0315</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AA33691 — Security fixes in calico-fips 3.28.5-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: calico-fips&lt;/p&gt;
&lt;p&gt;Package calico-fips version 3.28.5-r4 fixes 5 vulnerabilities: CVE-2026-33186, CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2025-13281&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: calico-fips&lt;/p&gt;
&lt;p&gt;Package calico-fips version 3.28.5-r4 fixes 5 vulnerabilities: CVE-2026-33186, CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2025-13281&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691</guid>
    </item>
    <item>
      <title>EUVD-2026-371781</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-371781</link>
      <description>EUVD-2026-371781</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-371781</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25679</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25679</link>
      <description>&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25679</guid>
    </item>
    <item>
      <title>GHSA-j3gx-2473-5fp8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j3gx-2473-5fp8</link>
      <description>&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j3gx-2473-5fp8</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-25679 — Incorrect parsing of IPv6 host literals in net/url</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-25679</link>
      <description>msrc_CVE-2026-25679</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-25679</guid>
    </item>
    <item>
      <title>OESA-2026-1792 — golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1792</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: golang&lt;/p&gt;
&lt;p&gt;.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.(CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.(CVE-2026-27139)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: golang&lt;/p&gt;
&lt;p&gt;.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.(CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.(CVE-2026-27139)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1792</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10299-1 — go1.26-1.26.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10299-1</link>
      <description>&lt;p&gt;go1.26-1.26.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go1.26-1.26.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10299-1</guid>
    </item>
    <item>
      <title>RHSA-2026:10065 — Red Hat Security Advisory: Red Hat Update Infrastructure 5.1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10065</link>
      <description>&lt;p&gt;libxslt: Processing web content may disclose sensitive information nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing python: Python: Command-line option injection in webbrowser.open() via crafted URLs libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing net/url: Incorrect parsing of IPv6 host literals in net/url vim: Vim: Arbitrary code execution via &amp;#39;helpfile&amp;#39; option processing nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module NGINX: NGINX: Denial of Service due to memory corruption via crafted MP4 file vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin vim: Vim: Denial of service and information disclosure via crafted swap file nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files vim: Vim: Arbitrary code execution via command injection in glob() function&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libxslt: Processing web content may disclose sensitive information nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing python: Python: Command-line option injection in webbrowser.open() via crafted URLs libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing net/url: Incorrect parsing of IPv6 host literals in net/url vim: Vim: Arbitrary code execution via &amp;#39;helpfile&amp;#39; option processing nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module NGINX: NGINX: Denial of Service due to memory corruption via crafted MP4 file vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin vim: Vim: Denial of service and information disclosure via crafted swap file nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files vim: Vim: Arbitrary code execution via command injection in glob() function&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10065</guid>
    </item>
    <item>
      <title>RLSA-2026:19128 — Important: yggdrasil-worker-package-manager security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:19128</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: yggdrasil-worker-package-manager&lt;/p&gt;
&lt;p&gt;yggdrasil-worker-package-manager is a simple package manager yggd worker. It knows how to install and remove packages, add, remove, enable and disable repositories, and does rudimentary detection of the host it is running on to guess the package manager to use. It only installs packages that match one of the provided allow-pattern regular expressions.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: yggdrasil-worker-package-manager&lt;/p&gt;
&lt;p&gt;yggdrasil-worker-package-manager is a simple package manager yggd worker. It knows how to install and remove packages, add, remove, enable and disable repositories, and does rudimentary detection of the host it is running on to guess the package manager to use. It only installs packages that match one of the provided allow-pattern regular expressions.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:19128</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21195-1 — Security update for go1.26-openssl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21195-1</link>
      <description>&lt;p&gt;Security update for go1.26-openssl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.26-openssl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21195-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-25679</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25679</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-1.24, Ubuntu:24.04:LTS: golang-1.24, Ubuntu:25.10: golang-1.24, Ubuntu:25.10: golang-1.25, Ubuntu:26.04:LTS: golang-1.24, Ubuntu:26.04:LTS: golang-1.25, Ubuntu:26.04:LTS: golang-1.26&lt;/p&gt;
&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-1.24, Ubuntu:24.04:LTS: golang-1.24, Ubuntu:25.10: golang-1.24, Ubuntu:25.10: golang-1.25, Ubuntu:26.04:LTS: golang-1.24, Ubuntu:26.04:LTS: golang-1.25, Ubuntu:26.04:LTS: golang-1.26&lt;/p&gt;
&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25679</guid>
    </item>
    <item>
      <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-088</link>
      <description>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-088</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0548 — Golang Go: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0548</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0548</guid>
    </item>
  </channel>
</rss>
