<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:33:47 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:19135 — Important: opentelemetry-collector security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:19135</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: opentelemetry-collector&lt;/p&gt;
&lt;p&gt;Collector with the supported components for a AlmaLinux build of OpenTelemetry&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)
  * google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)
  * github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
  * crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
  * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)
  * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
  * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
  * crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: opentelemetry-collector&lt;/p&gt;
&lt;p&gt;Collector with the supported components for a AlmaLinux build of OpenTelemetry&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)
  * google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)
  * github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
  * crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
  * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)
  * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
  * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
  * crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:19135</guid>
    </item>
    <item>
      <title>bdu:2026-04598</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04598</link>
      <description>bdu:2026-04598</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04598</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-33186</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-33186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: docker&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: docker&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-33186</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0366 — De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un contourne…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0366</link>
      <description>certfr-2026-avi-0366</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0366</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AA33691 — Security fixes in calico-fips 3.28.5-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: calico-fips&lt;/p&gt;
&lt;p&gt;Package calico-fips version 3.28.5-r4 fixes 5 vulnerabilities: CVE-2026-33186, CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2025-13281&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: calico-fips&lt;/p&gt;
&lt;p&gt;Package calico-fips version 3.28.5-r4 fixes 5 vulnerabilities: CVE-2026-33186, CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2025-13281&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aa33691</guid>
    </item>
    <item>
      <title>EUVD-2026-371800</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-371800</link>
      <description>EUVD-2026-371800</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-371800</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33186</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33186</link>
      <description>&lt;p&gt;gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, &amp;#34;deny&amp;#34; rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback &amp;#34;allow&amp;#34; rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific &amp;#34;deny&amp;#34; rules for canonical paths but allows other requests by default (a fallback &amp;#34;allow&amp;#34; rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers w…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, &amp;#34;deny&amp;#34; rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback &amp;#34;allow&amp;#34; rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific &amp;#34;deny&amp;#34; rules for canonical paths but allows other requests by default (a fallback &amp;#34;allow&amp;#34; rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers w…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33186</guid>
    </item>
    <item>
      <title>GHSA-p77j-4mvh-x3m3 — gRPC-Go has an authorization bypass via missing leading slash in :path</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p77j-4mvh-x3m3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: google.golang.org/grpc&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;It is an **Authorization Bypass** resulting from **Improper Input Validation** of the HTTP/2 `:path` pseudo-header.&lt;/p&gt;
&lt;p&gt;The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, &amp;#34;deny&amp;#34; rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback &amp;#34;allow&amp;#34; rule was present.&lt;/p&gt;
&lt;p&gt;**Who is impacted?**
This affects gRPC-Go servers that meet both of the following criteria:
1. They use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`.
2. Their security policy contains specific &amp;#34;deny&amp;#34; rules for canonical paths but allows other requests by default (a fallback &amp;#34;allow&amp;#34; rule).&lt;/p&gt;
&lt;p&gt;The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server.&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;Yes, the issue has been patched. The fix ensures that any request with a `:path` that does…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: google.golang.org/grpc&lt;/p&gt;
&lt;p&gt;### Impact
_What kind of vulnerability is it? Who is impacted?_&lt;/p&gt;
&lt;p&gt;It is an **Authorization Bypass** resulting from **Improper Input Validation** of the HTTP/2 `:path` pseudo-header.&lt;/p&gt;
&lt;p&gt;The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, &amp;#34;deny&amp;#34; rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback &amp;#34;allow&amp;#34; rule was present.&lt;/p&gt;
&lt;p&gt;**Who is impacted?**
This affects gRPC-Go servers that meet both of the following criteria:
1. They use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`.
2. Their security policy contains specific &amp;#34;deny&amp;#34; rules for canonical paths but allows other requests by default (a fallback &amp;#34;allow&amp;#34; rule).&lt;/p&gt;
&lt;p&gt;The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server.&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;Yes, the issue has been patched. The fix ensures that any request with a `:path` that does…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p77j-4mvh-x3m3</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-33186 — gRPC-Go has an authorization bypass via missing leading slash in :path</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-33186</link>
      <description>msrc_CVE-2026-33186</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-33186</guid>
    </item>
    <item>
      <title>NCSC-2026-0306 — Kwetsbaarheden verholpen in Oracle Fusion Middleware</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0306</link>
      <description>NCSC-2026-0306</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0306</guid>
    </item>
    <item>
      <title>OESA-2026-1866 — kata-containers-go security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1866</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kata-containers-go&lt;/p&gt;
&lt;p&gt;This is core component of Kata Container, to make it work, you need a isulad/docker engine.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, &amp;amp;quot;deny&amp;amp;quot; rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback &amp;amp;quot;allow&amp;amp;quot; rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific &amp;amp;quot;deny&amp;amp;quot; rules for canonical paths but allows other requests by default (a fallback &amp;amp;quot;allow&amp;amp;quot; rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: kata-containers-go&lt;/p&gt;
&lt;p&gt;This is core component of Kata Container, to make it work, you need a isulad/docker engine.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, &amp;amp;quot;deny&amp;amp;quot; rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback &amp;amp;quot;allow&amp;amp;quot; rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific &amp;amp;quot;deny&amp;amp;quot; rules for canonical paths but allows other requests by default (a fallback &amp;amp;quot;allow&amp;amp;quot; rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1866</guid>
    </item>
    <item>
      <title>openSUSE-RU-2026:21160-1 — Recommended update for dnscrypt-proxy</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-ru-2026:21160-1</link>
      <description>&lt;p&gt;Recommended update for dnscrypt-proxy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for dnscrypt-proxy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-ru-2026:21160-1</guid>
    </item>
    <item>
      <title>RHSA-2026:10093 — Red Hat Security Advisory: OpenShift Container Platform 4.19.29 bug fix and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10093</link>
      <description>&lt;p&gt;ajv: ReDoS via $data reference google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ajv: ReDoS via $data reference google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10093</guid>
    </item>
    <item>
      <title>RLSA-2026:19135 — Important: opentelemetry-collector security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:19135</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: opentelemetry-collector&lt;/p&gt;
&lt;p&gt;Collector with the supported components for a Rocky Enterprise Software Foundation build of OpenTelemetry&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)&lt;/p&gt;
&lt;p&gt;* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)&lt;/p&gt;
&lt;p&gt;* crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)&lt;/p&gt;
&lt;p&gt;* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)&lt;/p&gt;
&lt;p&gt;* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)&lt;/p&gt;
&lt;p&gt;* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: opentelemetry-collector&lt;/p&gt;
&lt;p&gt;Collector with the supported components for a Rocky Enterprise Software Foundation build of OpenTelemetry&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)&lt;/p&gt;
&lt;p&gt;* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)&lt;/p&gt;
&lt;p&gt;* crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)&lt;/p&gt;
&lt;p&gt;* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)&lt;/p&gt;
&lt;p&gt;* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)&lt;/p&gt;
&lt;p&gt;* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:19135</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1195-1 — Security update for google-cloud-sap-agent</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1195-1</link>
      <description>&lt;p&gt;Security update for google-cloud-sap-agent&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for google-cloud-sap-agent&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1195-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-33186</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: golang-google-grpc, Ubuntu:Pro:16.04:LTS: google-guest-agent, Ubuntu:18.04:LTS: golang-google-grpc, Ubuntu:Pro:18.04:LTS: google-guest-agent, Ubuntu:Pro:20.04:LTS: google-guest-agent, Ubuntu:20.04:LTS: golang-google-grpc, Ubuntu:22.04:LTS: golang-google-grpc, Ubuntu:22.04:LTS: google-guest-agent, Ubuntu:24.04:LTS: google-guest-agent, Ubuntu:Pro:24.04:LTS: golang-google-grpc and 4 more&lt;/p&gt;
&lt;p&gt;gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, &amp;#34;deny&amp;#34; rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback &amp;#34;allow&amp;#34; rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific &amp;#34;deny&amp;#34; rules for canonical paths but allows other requests by default (a fallback &amp;#34;allow&amp;#34; rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers w…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: golang-google-grpc, Ubuntu:Pro:16.04:LTS: google-guest-agent, Ubuntu:18.04:LTS: golang-google-grpc, Ubuntu:Pro:18.04:LTS: google-guest-agent, Ubuntu:Pro:20.04:LTS: google-guest-agent, Ubuntu:20.04:LTS: golang-google-grpc, Ubuntu:22.04:LTS: golang-google-grpc, Ubuntu:22.04:LTS: google-guest-agent, Ubuntu:24.04:LTS: google-guest-agent, Ubuntu:Pro:24.04:LTS: golang-google-grpc and 4 more&lt;/p&gt;
&lt;p&gt;gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, &amp;#34;deny&amp;#34; rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback &amp;#34;allow&amp;#34; rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific &amp;#34;deny&amp;#34; rules for canonical paths but allows other requests by default (a fallback &amp;#34;allow&amp;#34; rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers w…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33186</guid>
    </item>
    <item>
      <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-088</link>
      <description>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-088</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1136 — Red Hat OpenShift Container Platform (gRPC-Go): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1136</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift Container Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift Container Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1136</guid>
    </item>
  </channel>
</rss>
