<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:41:32 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0556 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556</link>
      <description>certfr-2026-avi-0556</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-LY29111 — DataRow</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ly29111</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: grafana-alloy&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the grafana-alloy package. The DataRow.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: grafana-alloy&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the grafana-alloy package. The DataRow.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ly29111</guid>
    </item>
    <item>
      <title>EUVD-2026-366112</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366112</link>
      <description>EUVD-2026-366112</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366112</guid>
    </item>
    <item>
      <title>fkie_cve-2026-32286</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32286</link>
      <description>&lt;p&gt;The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-32286</guid>
    </item>
    <item>
      <title>GHSA-jqcq-xjh3-6g23 — Denial of service in github.com/jackc/pgproto3/v2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jqcq-xjh3-6g23</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/jackc/pgproto3/v2&lt;/p&gt;
&lt;p&gt;The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/jackc/pgproto3/v2&lt;/p&gt;
&lt;p&gt;The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jqcq-xjh3-6g23</guid>
    </item>
    <item>
      <title>RHSA-2026:11070 — Red Hat Security Advisory: RHACS 4.8.11 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:11070</link>
      <description>&lt;p&gt;immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:11070</guid>
    </item>
    <item>
      <title>RHSA-2026:22450 — Red Hat Security Advisory: osbuild-composer security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:22450</link>
      <description>&lt;p&gt;golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:22450</guid>
    </item>
    <item>
      <title>RLSA-2026:22450 — Important: osbuild-composer security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:22450</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728)&lt;/p&gt;
&lt;p&gt;* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)&lt;/p&gt;
&lt;p&gt;* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)&lt;/p&gt;
&lt;p&gt;* crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message (CVE-2026-4427,GHSA-jqcq-xjh3-6g23)&lt;/p&gt;
&lt;p&gt;* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server (CVE-2026-32286)&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)&lt;/p&gt;
&lt;p&gt;* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)&lt;/p&gt;
&lt;p&gt;* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728)&lt;/p&gt;
&lt;p&gt;* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)&lt;/p&gt;
&lt;p&gt;* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)&lt;/p&gt;
&lt;p&gt;* crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message (CVE-2026-4427,GHSA-jqcq-xjh3-6g23)&lt;/p&gt;
&lt;p&gt;* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server (CVE-2026-32286)&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)&lt;/p&gt;
&lt;p&gt;* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)&lt;/p&gt;
&lt;p&gt;* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:22450</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-32286</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32286</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-jackc-pgproto3, Ubuntu:25.10: golang-github-jackc-pgproto3, Ubuntu:26.04:LTS: golang-github-jackc-pgproto3&lt;/p&gt;
&lt;p&gt;The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-jackc-pgproto3, Ubuntu:25.10: golang-github-jackc-pgproto3, Ubuntu:26.04:LTS: golang-github-jackc-pgproto3&lt;/p&gt;
&lt;p&gt;The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32286</guid>
    </item>
  </channel>
</rss>
