<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:34:22 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:35833 — Important: container-tools:rhel8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:35833</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
  * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)
  * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)
  * golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)
  * golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
  * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)
  * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)
  * golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)
  * golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:35833</guid>
    </item>
    <item>
      <title>bdu:2026-12029</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12029</link>
      <description>bdu:2026-12029</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12029</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-39832</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-39832</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: buildah, Alpaquita:23: containerd, Alpaquita:23: podman, Alpaquita:23: skopeo, Alpaquita:25: buildah, Alpaquita:25: containerd, Alpaquita:25: docker-cli-buildx, Alpaquita:25: google-guest-agent, Alpaquita:25: osv-scanner, Alpaquita:25: podman and 13 more&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: buildah, Alpaquita:23: containerd, Alpaquita:23: podman, Alpaquita:23: skopeo, Alpaquita:25: buildah, Alpaquita:25: containerd, Alpaquita:25: docker-cli-buildx, Alpaquita:25: google-guest-agent, Alpaquita:25: osv-scanner, Alpaquita:25: podman and 13 more&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-39832</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0901 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</link>
      <description>certfr-2026-avi-0901</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD30368 — Security fixes for CVE-2026-2303, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-39827, CVE-2…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad30368</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: weaviate-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the weaviate-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: weaviate-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the weaviate-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad30368</guid>
    </item>
    <item>
      <title>EUVD-2026-368450</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368450</link>
      <description>EUVD-2026-368450</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368450</guid>
    </item>
    <item>
      <title>fkie_cve-2026-39832</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39832</link>
      <description>&lt;p&gt;When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39832</guid>
    </item>
    <item>
      <title>GHSA-f5wc-c3c7-36mc — golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f5wc-c3c7-36mc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/crypto&lt;/p&gt;
&lt;p&gt;When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/crypto&lt;/p&gt;
&lt;p&gt;When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f5wc-c3c7-36mc</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-39832 — Invoking  agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-39832</link>
      <description>msrc_CVE-2026-39832</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-39832</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10842-1 — apptainer-1.4.5-5.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10842-1</link>
      <description>&lt;p&gt;apptainer-1.4.5-5.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apptainer-1.4.5-5.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10842-1</guid>
    </item>
    <item>
      <title>RHSA-2026:36319 — Red Hat Security Advisory: RHACS 4.9.9 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:36319</link>
      <description>&lt;p&gt;stackrox: stackrox: Unbounded GraphQL query depth allows authenticated denial of service form-data: form-data: Form field override via CRLF injection net/url: Incorrect parsing of IPv6 host literals in net/url golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME net/mail: golang: Go net/mail: Denial of Service via crafted email inputs golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate net/mail: golang: net/mail: Denial of Service via pathological email address parsing golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripti…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;stackrox: stackrox: Unbounded GraphQL query depth allows authenticated denial of service form-data: form-data: Form field override via CRLF injection net/url: Incorrect parsing of IPv6 host literals in net/url golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME net/mail: golang: Go net/mail: Denial of Service via crafted email inputs golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate net/mail: golang: net/mail: Denial of Service via pathological email address parsing golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripti…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:36319</guid>
    </item>
    <item>
      <title>RLSA-2026:35833 — Important: container-tools:rhel8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:35833</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: aardvark-dns, Rocky Linux:8: cockpit-podman, Rocky Linux:8: buildah, Rocky Linux:8: conmon, Rocky Linux:8: containernetworking-plugins, Rocky Linux:8: containers-common, Rocky Linux:8: container-selinux, Rocky Linux:8: criu, Rocky Linux:8: crun, Rocky Linux:8: fuse-overlayfs and 9 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: aardvark-dns, Rocky Linux:8: cockpit-podman, Rocky Linux:8: buildah, Rocky Linux:8: conmon, Rocky Linux:8: containernetworking-plugins, Rocky Linux:8: containers-common, Rocky Linux:8: container-selinux, Rocky Linux:8: criu, Rocky Linux:8: crun, Rocky Linux:8: fuse-overlayfs and 9 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)&lt;/p&gt;
&lt;p&gt;* golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:35833</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22065-1 — Security update for elemental-toolkit</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22065-1</link>
      <description>&lt;p&gt;Security update for elemental-toolkit&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for elemental-toolkit&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22065-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-39832</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39832</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:16.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: snapd, Ubuntu:Pro:20.04:LTS: snapd, Ubuntu:Pro:20.04:LTS: golang-go.crypto, Ubuntu:22.04:LTS: snapd, Ubuntu:Pro:22.04:LTS: golang-go.crypto, Ubuntu:24.04:LTS: snapd, Ubuntu:Pro:24.04:LTS: golang-go.crypto and 4 more&lt;/p&gt;
&lt;p&gt;When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:16.04:LTS: snapd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: snapd, Ubuntu:Pro:20.04:LTS: snapd, Ubuntu:Pro:20.04:LTS: golang-go.crypto, Ubuntu:22.04:LTS: snapd, Ubuntu:Pro:22.04:LTS: golang-go.crypto, Ubuntu:24.04:LTS: snapd, Ubuntu:Pro:24.04:LTS: golang-go.crypto and 4 more&lt;/p&gt;
&lt;p&gt;When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39832</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1653 — Golang Go-Module (Net, Image, Crypto: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1653</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um erweiterte Privilegien zu erlangen, Cross-Site-Scripting-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um erweiterte Privilegien zu erlangen, Cross-Site-Scripting-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1653</guid>
    </item>
  </channel>
</rss>
