<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:54:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-07149</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07149</link>
      <description>bdu:2026-07149</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07149</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-33747</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-33747</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: docker&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: docker&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-33747</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-DU09908 — BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-du09908</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: docker-cli-buildx&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the docker-cli-buildx package. BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: docker-cli-buildx&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the docker-cli-buildx package. BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-du09908</guid>
    </item>
    <item>
      <title>EUVD-2026-277883</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277883</link>
      <description>EUVD-2026-277883</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277883</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33747</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33747</link>
      <description>&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33747</guid>
    </item>
    <item>
      <title>GHSA-4c29-8rgm-jvjj — BuildKit's Malicious frontend can cause file escape outside of storage root</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4c29-8rgm-jvjj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/moby/buildkit&lt;/p&gt;
&lt;p&gt;### Impact
When using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context.&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been fixed in v0.28.1+&lt;/p&gt;
&lt;p&gt;### Workarounds
Issue requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/moby/buildkit&lt;/p&gt;
&lt;p&gt;### Impact
When using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context.&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been fixed in v0.28.1+&lt;/p&gt;
&lt;p&gt;### Workarounds
Issue requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4c29-8rgm-jvjj</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10456-1 — tailscale-1.96.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10456-1</link>
      <description>&lt;p&gt;tailscale-1.96.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tailscale-1.96.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10456-1</guid>
    </item>
    <item>
      <title>RHSA-2026:10125 — Red Hat Security Advisory: RHTAS 1.3.4 - Red Hat Trusted Artifact Signer Release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10125</link>
      <description>&lt;p&gt;crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10125</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21851-1 — Security update for docker-stable</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21851-1</link>
      <description>&lt;p&gt;Security update for docker-stable&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for docker-stable&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21851-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-33747</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33747</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:Pro:18.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io-app, Ubuntu:22.04:LTS: docker.io-app, Ubuntu:Pro:22.04:LTS: docker.io, Ubuntu:24.04:LTS: docker.io-app, Ubuntu:Pro:24.04:LTS: docker.io, Ubuntu:25.10: docker.io, Ubuntu:25.10: docker.io-app and 2 more&lt;/p&gt;
&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:Pro:18.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io-app, Ubuntu:22.04:LTS: docker.io-app, Ubuntu:Pro:22.04:LTS: docker.io, Ubuntu:24.04:LTS: docker.io-app, Ubuntu:Pro:24.04:LTS: docker.io, Ubuntu:25.10: docker.io, Ubuntu:25.10: docker.io-app and 2 more&lt;/p&gt;
&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33747</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0873 — docker: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0873</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in docker ausnutzen, um Sicherheitsvorkehrungen zu umgehen und Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in docker ausnutzen, um Sicherheitsvorkehrungen zu umgehen und Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0873</guid>
    </item>
  </channel>
</rss>
