<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:14:46 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:19022 — Important: golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:19022</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: go-toolset, AlmaLinux:10: golang, AlmaLinux:10: golang-bin, AlmaLinux:10: golang-docs, AlmaLinux:10: golang-misc, AlmaLinux:10: golang-race, AlmaLinux:10: golang-src, AlmaLinux:10: golang-tests&lt;/p&gt;
&lt;p&gt;The golang packages provide the Go programming language compiler.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)
  * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: go-toolset, AlmaLinux:10: golang, AlmaLinux:10: golang-bin, AlmaLinux:10: golang-docs, AlmaLinux:10: golang-misc, AlmaLinux:10: golang-race, AlmaLinux:10: golang-src, AlmaLinux:10: golang-tests&lt;/p&gt;
&lt;p&gt;The golang packages provide the Go programming language compiler.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)
  * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:19022</guid>
    </item>
    <item>
      <title>bdu:2026-04124</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04124</link>
      <description>bdu:2026-04124</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04124</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-27137</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-27137</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-27137</guid>
    </item>
    <item>
      <title>BIT-golang-2026-27137 — Incorrect enforcement of email constraints in crypto/x509</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2026-27137</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2026-27137</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0299 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0299</link>
      <description>certfr-2026-avi-0299</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0299</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AB43319 — Security fixes for CVE-2025-47911, CVE-2025-58183, CVE-2025-58185, CVE-2025-58187, CVE-2025-58188, CVE-2025-58189, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ab43319</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stakater-reloader&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the stakater-reloader package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: stakater-reloader&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the stakater-reloader package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ab43319</guid>
    </item>
    <item>
      <title>EUVD-2026-371761</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-371761</link>
      <description>EUVD-2026-371761</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-371761</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27137</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27137</link>
      <description>&lt;p&gt;When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27137</guid>
    </item>
    <item>
      <title>GHSA-7hfw-r8qc-89v4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7hfw-r8qc-89v4</link>
      <description>&lt;p&gt;When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7hfw-r8qc-89v4</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-27137 — Incorrect enforcement of email constraints in crypto/x509</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-27137</link>
      <description>msrc_CVE-2026-27137</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-27137</guid>
    </item>
    <item>
      <title>OESA-2026-3879 — git-lfs security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3879</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: git-lfs&lt;/p&gt;
&lt;p&gt;Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.(CVE-2024-8244)&lt;/p&gt;
&lt;p&gt;Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk&amp;amp;apos;s Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.(CVE-2025-27613)&lt;/p&gt;
&lt;p&gt;Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.(CVE-2025-4673)&lt;/p&gt;
&lt;p&gt;If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath (&amp;amp;quot;&amp;amp;quot;, &amp;amp;quot;.&amp;amp;quot;, and &amp;amp;quot;..&amp;amp;quot;), can result in the bin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: git-lfs&lt;/p&gt;
&lt;p&gt;Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.(CVE-2024-8244)&lt;/p&gt;
&lt;p&gt;Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk&amp;amp;apos;s Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.(CVE-2025-27613)&lt;/p&gt;
&lt;p&gt;Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.(CVE-2025-4673)&lt;/p&gt;
&lt;p&gt;If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath (&amp;amp;quot;&amp;amp;quot;, &amp;amp;quot;.&amp;amp;quot;, and &amp;amp;quot;..&amp;amp;quot;), can result in the bin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3879</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10299-1 — go1.26-1.26.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10299-1</link>
      <description>&lt;p&gt;go1.26-1.26.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go1.26-1.26.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10299-1</guid>
    </item>
    <item>
      <title>RHSA-2026:10125 — Red Hat Security Advisory: RHTAS 1.3.4 - Red Hat Trusted Artifact Signer Release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10125</link>
      <description>&lt;p&gt;crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10125</guid>
    </item>
    <item>
      <title>RLSA-2026:22450 — Important: osbuild-composer security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:22450</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728)&lt;/p&gt;
&lt;p&gt;* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)&lt;/p&gt;
&lt;p&gt;* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)&lt;/p&gt;
&lt;p&gt;* crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message (CVE-2026-4427,GHSA-jqcq-xjh3-6g23)&lt;/p&gt;
&lt;p&gt;* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server (CVE-2026-32286)&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)&lt;/p&gt;
&lt;p&gt;* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)&lt;/p&gt;
&lt;p&gt;* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728)&lt;/p&gt;
&lt;p&gt;* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)&lt;/p&gt;
&lt;p&gt;* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)&lt;/p&gt;
&lt;p&gt;* crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message (CVE-2026-4427,GHSA-jqcq-xjh3-6g23)&lt;/p&gt;
&lt;p&gt;* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server (CVE-2026-32286)&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)&lt;/p&gt;
&lt;p&gt;* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)&lt;/p&gt;
&lt;p&gt;* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:22450</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21195-1 — Security update for go1.26-openssl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21195-1</link>
      <description>&lt;p&gt;Security update for go1.26-openssl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.26-openssl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21195-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-27137</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27137</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-1.24, Ubuntu:24.04:LTS: golang-1.24, Ubuntu:25.10: golang-1.24, Ubuntu:25.10: golang-1.25, Ubuntu:26.04:LTS: golang-1.24, Ubuntu:26.04:LTS: golang-1.25, Ubuntu:26.04:LTS: golang-1.26&lt;/p&gt;
&lt;p&gt;When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-1.24, Ubuntu:24.04:LTS: golang-1.24, Ubuntu:25.10: golang-1.24, Ubuntu:25.10: golang-1.25, Ubuntu:26.04:LTS: golang-1.24, Ubuntu:26.04:LTS: golang-1.25, Ubuntu:26.04:LTS: golang-1.26&lt;/p&gt;
&lt;p&gt;When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27137</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0548 — Golang Go: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0548</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0548</guid>
    </item>
  </channel>
</rss>
