<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:55:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-07210</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07210</link>
      <description>bdu:2026-07210</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07210</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-33748</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-33748</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: docker&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: docker&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-33748</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-CI85082 — Security fix for CVE-2026-33748 applied in: docker 29.3.0-r1, docker-compose 5.1.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci85082</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: docker, CleanStart: docker-compose&lt;/p&gt;
&lt;p&gt;CVE-2026-33748 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: docker, CleanStart: docker-compose&lt;/p&gt;
&lt;p&gt;CVE-2026-33748 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ci85082</guid>
    </item>
    <item>
      <title>EUVD-2026-277879</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277879</link>
      <description>EUVD-2026-277879</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277879</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33748</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33748</link>
      <description>&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33748</guid>
    </item>
    <item>
      <title>GHSA-4vrq-3vrq-g6gg — BuildKit Git URL subdir component can cause access to restricted files</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4vrq-3vrq-g6gg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/moby/buildkit&lt;/p&gt;
&lt;p&gt;### Impact
Insufficient validation of Git URL fragment subdir components (`&amp;lt;url&amp;gt;#&amp;lt;ref&amp;gt;:&amp;lt;subdir&amp;gt;`, [docs](https://docs.docker.com/build/concepts/context/#url-fragments)) may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem.&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been fixed in version v0.28.1&lt;/p&gt;
&lt;p&gt;### Workarounds
The issue affects only builds that use Git URLs with a subpath component. Avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/moby/buildkit&lt;/p&gt;
&lt;p&gt;### Impact
Insufficient validation of Git URL fragment subdir components (`&amp;lt;url&amp;gt;#&amp;lt;ref&amp;gt;:&amp;lt;subdir&amp;gt;`, [docs](https://docs.docker.com/build/concepts/context/#url-fragments)) may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem.&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been fixed in version v0.28.1&lt;/p&gt;
&lt;p&gt;### Workarounds
The issue affects only builds that use Git URLs with a subpath component. Avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4vrq-3vrq-g6gg</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10651-1 — trivy-0.70.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10651-1</link>
      <description>&lt;p&gt;trivy-0.70.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;trivy-0.70.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10651-1</guid>
    </item>
    <item>
      <title>RHSA-2026:10125 — Red Hat Security Advisory: RHTAS 1.3.4 - Red Hat Trusted Artifact Signer Release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10125</link>
      <description>&lt;p&gt;crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10125</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21851-1 — Security update for docker-stable</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21851-1</link>
      <description>&lt;p&gt;Security update for docker-stable&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for docker-stable&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21851-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-33748</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33748</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:Pro:18.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io-app, Ubuntu:22.04:LTS: docker.io-app, Ubuntu:Pro:22.04:LTS: docker.io, Ubuntu:24.04:LTS: docker.io-app, Ubuntu:Pro:24.04:LTS: docker.io, Ubuntu:25.10: docker.io, Ubuntu:25.10: docker.io-app and 2 more&lt;/p&gt;
&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:Pro:18.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io-app, Ubuntu:22.04:LTS: docker.io-app, Ubuntu:Pro:22.04:LTS: docker.io, Ubuntu:24.04:LTS: docker.io-app, Ubuntu:Pro:24.04:LTS: docker.io, Ubuntu:25.10: docker.io, Ubuntu:25.10: docker.io-app and 2 more&lt;/p&gt;
&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33748</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0873 — docker: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0873</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in docker ausnutzen, um Sicherheitsvorkehrungen zu umgehen und Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in docker ausnutzen, um Sicherheitsvorkehrungen zu umgehen und Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0873</guid>
    </item>
  </channel>
</rss>
