<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:51:10 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-04122</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04122</link>
      <description>bdu:2026-04122</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04122</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-27139</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-27139</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:25: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:25: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-27139</guid>
    </item>
    <item>
      <title>BIT-golang-2026-27139 — FileInfo can escape from a Root in os</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2026-27139</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2026-27139</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0315 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0315</link>
      <description>certfr-2026-avi-0315</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0315</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AA33691 — Security fixes in calico-fips 3.28.5-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: calico-fips&lt;/p&gt;
&lt;p&gt;Package calico-fips version 3.28.5-r4 fixes 5 vulnerabilities: CVE-2026-33186, CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2025-13281&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: calico-fips&lt;/p&gt;
&lt;p&gt;Package calico-fips version 3.28.5-r4 fixes 5 vulnerabilities: CVE-2026-33186, CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2025-13281&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691</guid>
    </item>
    <item>
      <title>EUVD-2026-274906</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274906</link>
      <description>EUVD-2026-274906</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274906</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27139</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27139</link>
      <description>&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27139</guid>
    </item>
    <item>
      <title>GHSA-rv83-g57w-fr8j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rv83-g57w-fr8j</link>
      <description>&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rv83-g57w-fr8j</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-27139 — FileInfo can escape from a Root in os</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-27139</link>
      <description>msrc_CVE-2026-27139</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-27139</guid>
    </item>
    <item>
      <title>OESA-2026-1792 — golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1792</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: golang&lt;/p&gt;
&lt;p&gt;.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.(CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.(CVE-2026-27139)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: golang&lt;/p&gt;
&lt;p&gt;.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.(CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.(CVE-2026-27139)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1792</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10299-1 — go1.26-1.26.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10299-1</link>
      <description>&lt;p&gt;go1.26-1.26.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go1.26-1.26.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10299-1</guid>
    </item>
    <item>
      <title>RHSA-2026:7291 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:7291</link>
      <description>&lt;p&gt;os: os: Information disclosure via path traversal using specially crafted filenames net/http: CrossOriginProtection bypass in net/http golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html net/url: Insufficient validation of bracketed IPv6 hostnames in net/url golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication golang: archive/tar: Unbounded allocation when parsing GNU sparse map encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 golang.org/net/http: Lack of limit when parsing cookies can cause memory exhaustion in net/http crypto/x509: Quadratic complexity when checking name constraints in crypto/x509 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information golang.org/x/net/html: Infinite parsing loop in golang.org/x/net encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem net/textproto: Excessive CPU consumption in Reader.ReadResponse in net/textproto net/mail: Excessive CPU consumption in ParseAddress in net/mail golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs golang: archive/zip: Excessive CPU co…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;os: os: Information disclosure via path traversal using specially crafted filenames net/http: CrossOriginProtection bypass in net/http golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html net/url: Insufficient validation of bracketed IPv6 hostnames in net/url golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication golang: archive/tar: Unbounded allocation when parsing GNU sparse map encoding/asn1: Parsing DER payload can cause memory exhaustion in encoding/asn1 golang.org/net/http: Lack of limit when parsing cookies can cause memory exhaustion in net/http crypto/x509: Quadratic complexity when checking name constraints in crypto/x509 crypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 crypto/tls: go crypto/tls ALPN negotiation error contains attacker controlled information golang.org/x/net/html: Infinite parsing loop in golang.org/x/net encoding/pem: Quadratic complexity when parsing some invalid inputs in encoding/pem net/textproto: Excessive CPU consumption in Reader.ReadResponse in net/textproto net/mail: Excessive CPU consumption in ParseAddress in net/mail golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: crypto/x509: excluded subdomain constraint does not restrict wildcard SANs golang: archive/zip: Excessive CPU co…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:7291</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21195-1 — Security update for go1.26-openssl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21195-1</link>
      <description>&lt;p&gt;Security update for go1.26-openssl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.26-openssl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21195-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-27139</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27139</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-1.24, Ubuntu:24.04:LTS: golang-1.24, Ubuntu:25.10: golang-1.24, Ubuntu:25.10: golang-1.25, Ubuntu:26.04:LTS: golang-1.24, Ubuntu:26.04:LTS: golang-1.25, Ubuntu:26.04:LTS: golang-1.26&lt;/p&gt;
&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-1.24, Ubuntu:24.04:LTS: golang-1.24, Ubuntu:25.10: golang-1.24, Ubuntu:25.10: golang-1.25, Ubuntu:26.04:LTS: golang-1.24, Ubuntu:26.04:LTS: golang-1.25, Ubuntu:26.04:LTS: golang-1.26&lt;/p&gt;
&lt;p&gt;On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27139</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0548 — Golang Go: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0548</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0548</guid>
    </item>
  </channel>
</rss>
