<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:35:43 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:12176 — Important: fence-agents security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:12176</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: fence-agents-aliyun, AlmaLinux:8: fence-agents-all, AlmaLinux:8: fence-agents-amt-ws, AlmaLinux:8: fence-agents-apc, AlmaLinux:8: fence-agents-apc-snmp, AlmaLinux:8: fence-agents-aws, AlmaLinux:8: fence-agents-azure-arm, AlmaLinux:8: fence-agents-bladecenter, AlmaLinux:8: fence-agents-brocade, AlmaLinux:8: fence-agents-cisco-mds and 38 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves (CVE-2026-26007)
  * pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)
  * pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: fence-agents-aliyun, AlmaLinux:8: fence-agents-all, AlmaLinux:8: fence-agents-amt-ws, AlmaLinux:8: fence-agents-apc, AlmaLinux:8: fence-agents-apc-snmp, AlmaLinux:8: fence-agents-aws, AlmaLinux:8: fence-agents-azure-arm, AlmaLinux:8: fence-agents-bladecenter, AlmaLinux:8: fence-agents-brocade, AlmaLinux:8: fence-agents-cisco-mds and 38 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves (CVE-2026-26007)
  * pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)
  * pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:12176</guid>
    </item>
    <item>
      <title>bdu:2026-11378</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-11378</link>
      <description>bdu:2026-11378</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-11378</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-26007</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-26007</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: py3-cryptography, Alpaquita:stream: py3-cryptography&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: py3-cryptography, Alpaquita:stream: py3-cryptography&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-26007</guid>
    </item>
    <item>
      <title>BREW-ansible@10-CVE-2026-26007 — cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible@10-cve-2026-26007</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible@10&lt;/p&gt;
&lt;p&gt;## Vulnerability Summary&lt;/p&gt;
&lt;p&gt;The `public_key_from_numbers` (or `EllipticCurvePublicNumbers.public_key()`), `EllipticCurvePublicNumbers.public_key()`, `load_der_public_key()` and `load_pem_public_key()` functions do not verify that the point belongs to the expected prime-order subgroup of the curve.&lt;/p&gt;
&lt;p&gt;This missing validation allows an attacker to provide a public key point `P` from a small-order subgroup.  This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as `S = [victim_private_key]P` via ECDH,  this leaks information about `victim_private_key mod (small_subgroup_order)`. For curves with cofactor &amp;gt; 1, this reveals the least significant bits of the private key.  When these weak public keys are used in ECDSA , it&amp;#39;s easy to forge signatures on the small subgroup.&lt;/p&gt;
&lt;p&gt;Only SECT curves are impacted by this.&lt;/p&gt;
&lt;p&gt;## Credit&lt;/p&gt;
&lt;p&gt;This vulnerability was discovered by:
- XlabAI Team of Tencent Xuanwu Lab
- Atuin Automated Vulnerability Discovery Engine&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible@10&lt;/p&gt;
&lt;p&gt;## Vulnerability Summary&lt;/p&gt;
&lt;p&gt;The `public_key_from_numbers` (or `EllipticCurvePublicNumbers.public_key()`), `EllipticCurvePublicNumbers.public_key()`, `load_der_public_key()` and `load_pem_public_key()` functions do not verify that the point belongs to the expected prime-order subgroup of the curve.&lt;/p&gt;
&lt;p&gt;This missing validation allows an attacker to provide a public key point `P` from a small-order subgroup.  This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as `S = [victim_private_key]P` via ECDH,  this leaks information about `victim_private_key mod (small_subgroup_order)`. For curves with cofactor &amp;gt; 1, this reveals the least significant bits of the private key.  When these weak public keys are used in ECDSA , it&amp;#39;s easy to forge signatures on the small subgroup.&lt;/p&gt;
&lt;p&gt;Only SECT curves are impacted by this.&lt;/p&gt;
&lt;p&gt;## Credit&lt;/p&gt;
&lt;p&gt;This vulnerability was discovered by:
- XlabAI Team of Tencent Xuanwu Lab
- Atuin Automated Vulnerability Discovery Engine&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible@10-cve-2026-26007</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0316 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</link>
      <description>certfr-2026-avi-0316</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AN24336 — Security fixes for CVE-2024-12797, CVE-2024-52303, CVE-2024-52304, CVE-2024-56201, CVE-2024-56326, CVE-2025-24023, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-an24336</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-2&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the airflow-2 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-2&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the airflow-2 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-an24336</guid>
    </item>
    <item>
      <title>EUVD-2026-369291</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-369291</link>
      <description>EUVD-2026-369291</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-369291</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26007</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26007</link>
      <description>&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor &amp;gt; 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it&amp;#39;s easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor &amp;gt; 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it&amp;#39;s easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26007</guid>
    </item>
    <item>
      <title>GHSA-r6ph-v2qm-q3c2 — cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r6ph-v2qm-q3c2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cryptography&lt;/p&gt;
&lt;p&gt;## Vulnerability Summary&lt;/p&gt;
&lt;p&gt;The `public_key_from_numbers` (or `EllipticCurvePublicNumbers.public_key()`), `EllipticCurvePublicNumbers.public_key()`, `load_der_public_key()` and `load_pem_public_key()` functions do not verify that the point belongs to the expected prime-order subgroup of the curve.&lt;/p&gt;
&lt;p&gt;This missing validation allows an attacker to provide a public key point `P` from a small-order subgroup.  This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as `S = [victim_private_key]P` via ECDH,  this leaks information about `victim_private_key mod (small_subgroup_order)`. For curves with cofactor &amp;gt; 1, this reveals the least significant bits of the private key.  When these weak public keys are used in ECDSA , it&amp;#39;s easy to forge signatures on the small subgroup.&lt;/p&gt;
&lt;p&gt;Only SECT curves are impacted by this.&lt;/p&gt;
&lt;p&gt;## Credit&lt;/p&gt;
&lt;p&gt;This vulnerability was discovered by:
- XlabAI Team of Tencent Xuanwu Lab
- Atuin Automated Vulnerability Discovery Engine&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cryptography&lt;/p&gt;
&lt;p&gt;## Vulnerability Summary&lt;/p&gt;
&lt;p&gt;The `public_key_from_numbers` (or `EllipticCurvePublicNumbers.public_key()`), `EllipticCurvePublicNumbers.public_key()`, `load_der_public_key()` and `load_pem_public_key()` functions do not verify that the point belongs to the expected prime-order subgroup of the curve.&lt;/p&gt;
&lt;p&gt;This missing validation allows an attacker to provide a public key point `P` from a small-order subgroup.  This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as `S = [victim_private_key]P` via ECDH,  this leaks information about `victim_private_key mod (small_subgroup_order)`. For curves with cofactor &amp;gt; 1, this reveals the least significant bits of the private key.  When these weak public keys are used in ECDSA , it&amp;#39;s easy to forge signatures on the small subgroup.&lt;/p&gt;
&lt;p&gt;Only SECT curves are impacted by this.&lt;/p&gt;
&lt;p&gt;## Credit&lt;/p&gt;
&lt;p&gt;This vulnerability was discovered by:
- XlabAI Team of Tencent Xuanwu Lab
- Atuin Automated Vulnerability Discovery Engine&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r6ph-v2qm-q3c2</guid>
    </item>
    <item>
      <title>OESA-2026-1669 — python-cryptography security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1669</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-cryptography&lt;/p&gt;
&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;This vulnerability exists in the pyca cryptography library due to missing subgroup validation for SECT curves. An attacker could exploit this to perform subgroup attacks, potentially leading to security bypass.(CVE-2026-26007)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-cryptography&lt;/p&gt;
&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;This vulnerability exists in the pyca cryptography library due to missing subgroup validation for SECT curves. An attacker could exploit this to perform subgroup attacks, potentially leading to security bypass.(CVE-2026-26007)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1669</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10205-1 — python311-cryptography-46.0.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10205-1</link>
      <description>&lt;p&gt;python311-cryptography-46.0.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-cryptography-46.0.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10205-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2141</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2141</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cryptography&lt;/p&gt;
&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor &amp;gt; 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it&amp;#39;s easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cryptography&lt;/p&gt;
&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor &amp;gt; 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it&amp;#39;s easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2141</guid>
    </item>
    <item>
      <title>RHSA-2026:10184 — Red Hat Security Advisory: RHOAI 2.25.5 - Red Hat OpenShift AI</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10184</link>
      <description>&lt;p&gt;vllm: Server Side request forgery (SSRF) in MediaConnector feast: Feast: Remote Code Execution via insecure YAML deserialization openshift-ai: Trusty AI Grants All Authenticated users to list pods in any namespace nltk: Zip Slip Vulnerability in nltk Leading to Code Execution golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data cbor2: cbor2: Information Disclosure via shared memory in CBORDecoder reuse aiohttp: AIOHTTP&amp;#39;s HTTP Parser auto_decompress feature is vulnerable to zip bomb aiohttp: aiohttp: Denial of Service via specially crafted POST request aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request python-markdown: denial of service via malformed HTML-like sequences nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function nltk: NLTK: Arbitrary file read via path traversal vulnerability io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files google-cloud-aiplatform: google-cloud-aiplatform: Arbitrary code execution via Stored Cross-Site Scripting (XSS) tensorflow: TensorFlow: Local privilege escalation via…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vllm: Server Side request forgery (SSRF) in MediaConnector feast: Feast: Remote Code Execution via insecure YAML deserialization openshift-ai: Trusty AI Grants All Authenticated users to list pods in any namespace nltk: Zip Slip Vulnerability in nltk Leading to Code Execution golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data cbor2: cbor2: Information Disclosure via shared memory in CBORDecoder reuse aiohttp: AIOHTTP&amp;#39;s HTTP Parser auto_decompress feature is vulnerable to zip bomb aiohttp: aiohttp: Denial of Service via specially crafted POST request aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request python-markdown: denial of service via malformed HTML-like sequences nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function nltk: NLTK: Arbitrary file read via path traversal vulnerability io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files google-cloud-aiplatform: google-cloud-aiplatform: Arbitrary code execution via Stored Cross-Site Scripting (XSS) tensorflow: TensorFlow: Local privilege escalation via…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10184</guid>
    </item>
    <item>
      <title>RLSA-2026:19355 — Important: fence-agents security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:19355</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: fence-agents&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves (CVE-2026-26007)&lt;/p&gt;
&lt;p&gt;* pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)&lt;/p&gt;
&lt;p&gt;* pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: fence-agents&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves (CVE-2026-26007)&lt;/p&gt;
&lt;p&gt;* pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)&lt;/p&gt;
&lt;p&gt;* pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:19355</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:20655-1 — Security update for python-cryptography</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:20655-1</link>
      <description>&lt;p&gt;Security update for python-cryptography&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-cryptography&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:20655-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-26007</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-26007</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-cryptography, Ubuntu:Pro:18.04:LTS: python-cryptography, Ubuntu:Pro:20.04:LTS: python-cryptography, Ubuntu:22.04:LTS: python-cryptography, Ubuntu:24.04:LTS: python-cryptography, Ubuntu:25.10: python-cryptography&lt;/p&gt;
&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor &amp;gt; 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it&amp;#39;s easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-cryptography, Ubuntu:Pro:18.04:LTS: python-cryptography, Ubuntu:Pro:20.04:LTS: python-cryptography, Ubuntu:22.04:LTS: python-cryptography, Ubuntu:24.04:LTS: python-cryptography, Ubuntu:25.10: python-cryptography&lt;/p&gt;
&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor &amp;gt; 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it&amp;#39;s easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-26007</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0935 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0935</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0935</guid>
    </item>
  </channel>
</rss>
