<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:08:15 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:37123 — Important: podman security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:37123</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: podman, AlmaLinux:9: podman-docker, AlmaLinux:9: podman-plugins, AlmaLinux:9: podman-remote, AlmaLinux:9: podman-tests&lt;/p&gt;
&lt;p&gt;The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)
  * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)
  * golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)
  * golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)
  * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)
  * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
  * podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* podman does not clean up all files and leaves orphaned files consuming disk space [almalinux-9.8.z] (JIRA:AlmaLinux-173988)
  * [FJ9.8 Bug]: [REG]The &amp;#34;podman-remote save&amp;#34; command fails for rootless users. [almalinux-9.8.z] (JIRA:AlmaLinux-192439)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowled…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: podman, AlmaLinux:9: podman-docker, AlmaLinux:9: podman-plugins, AlmaLinux:9: podman-remote, AlmaLinux:9: podman-tests&lt;/p&gt;
&lt;p&gt;The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)
  * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)
  * golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)
  * golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)
  * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)
  * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
  * podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* podman does not clean up all files and leaves orphaned files consuming disk space [almalinux-9.8.z] (JIRA:AlmaLinux-173988)
  * [FJ9.8 Bug]: [REG]The &amp;#34;podman-remote save&amp;#34; command fails for rootless users. [almalinux-9.8.z] (JIRA:AlmaLinux-192439)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowled…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:37123</guid>
    </item>
    <item>
      <title>bdu:2026-15282</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15282</link>
      <description>bdu:2026-15282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15282</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-27136</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-27136</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: buildah, Alpaquita:23: containerd, Alpaquita:23: podman, Alpaquita:23: runc, Alpaquita:23: skopeo, Alpaquita:25: buildah, Alpaquita:25: containerd, Alpaquita:25: docker-cli-buildx, Alpaquita:25: google-guest-agent, Alpaquita:25: osv-scanner and 20 more&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: buildah, Alpaquita:23: containerd, Alpaquita:23: podman, Alpaquita:23: runc, Alpaquita:23: skopeo, Alpaquita:25: buildah, Alpaquita:25: containerd, Alpaquita:25: docker-cli-buildx, Alpaquita:25: google-guest-agent, Alpaquita:25: osv-scanner and 20 more&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-27136</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0788 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</link>
      <description>certfr-2026-avi-0788</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0788</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD30368 — Security fixes for CVE-2026-2303, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-39827, CVE-2…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad30368</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: weaviate-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the weaviate-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: weaviate-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the weaviate-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad30368</guid>
    </item>
    <item>
      <title>EUVD-2026-320135</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-320135</link>
      <description>EUVD-2026-320135</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-320135</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27136</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27136</link>
      <description>&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27136</guid>
    </item>
    <item>
      <title>GHSA-m9x8-m34x-fj9q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m9x8-m34x-fj9q</link>
      <description>&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m9x8-m34x-fj9q</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-27136 — Invoking  duplicate attributes can cause XSS in golang.org/x/net/html</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-27136</link>
      <description>msrc_CVE-2026-27136</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-27136</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10856-1 — rclone-1.74.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10856-1</link>
      <description>&lt;p&gt;rclone-1.74.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rclone-1.74.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10856-1</guid>
    </item>
    <item>
      <title>RHSA-2026:36207 — Red Hat Security Advisory: RHACS 4.11.1 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:36207</link>
      <description>&lt;p&gt;stackrox: stackrox: Unbounded GraphQL query depth allows authenticated denial of service golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate axios: Axios: Prototype pollution allows information disclosure and request manipulation golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;stackrox: stackrox: Unbounded GraphQL query depth allows authenticated denial of service golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate axios: Axios: Prototype pollution allows information disclosure and request manipulation golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:36207</guid>
    </item>
    <item>
      <title>RLSA-2026:37072 — Important: podman security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:37072</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: podman&lt;/p&gt;
&lt;p&gt;The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)&lt;/p&gt;
&lt;p&gt;* podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* podman does not clean up all files and leaves orphaned files consuming disk space [rhel-10.2.z] (JIRA:Rocky Linux-173842)&lt;/p&gt;
&lt;p&gt;* [FJ10.2 Bug]: [REG]The &amp;#34;podman-remote save&amp;#34; command fails for rootless users. [rhel-10.2.z] (JI…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: podman&lt;/p&gt;
&lt;p&gt;The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)&lt;/p&gt;
&lt;p&gt;* podman: Podman: Information disclosure via malicious container image environment variables (CVE-2026-57231)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* podman does not clean up all files and leaves orphaned files consuming disk space [rhel-10.2.z] (JIRA:Rocky Linux-173842)&lt;/p&gt;
&lt;p&gt;* [FJ10.2 Bug]: [REG]The &amp;#34;podman-remote save&amp;#34; command fails for rootless users. [rhel-10.2.z] (JI…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:37072</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22065-1 — Security update for elemental-toolkit</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22065-1</link>
      <description>&lt;p&gt;Security update for elemental-toolkit&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for elemental-toolkit&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22065-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-27136</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27136</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: golang-golang-x-net-dev, Ubuntu:Pro:18.04:LTS: golang-golang-x-net-dev, Ubuntu:Pro:20.04:LTS: golang-golang-x-net-dev&lt;/p&gt;
&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: golang-golang-x-net-dev, Ubuntu:Pro:18.04:LTS: golang-golang-x-net-dev, Ubuntu:Pro:20.04:LTS: golang-golang-x-net-dev&lt;/p&gt;
&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27136</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1653 — Golang Go-Module (Net, Image, Crypto: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1653</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um erweiterte Privilegien zu erlangen, Cross-Site-Scripting-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um erweiterte Privilegien zu erlangen, Cross-Site-Scripting-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1653</guid>
    </item>
  </channel>
</rss>
