<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:02:13 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:30851 — Important: perl:5.32 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:30851</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: perl, AlmaLinux:8: perl-Algorithm-Diff, AlmaLinux:8: perl-Archive-Tar, AlmaLinux:8: perl-Archive-Zip, AlmaLinux:8: perl-Attribute-Handlers, AlmaLinux:8: perl-AutoLoader, AlmaLinux:8: perl-AutoSplit, AlmaLinux:8: perl-B, AlmaLinux:8: perl-Benchmark, AlmaLinux:8: perl-CPAN and 212 more&lt;/p&gt;
&lt;p&gt;Perl is a high-level programming language that is commonly used for system administration utilities and web programming.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)
  * perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: perl, AlmaLinux:8: perl-Algorithm-Diff, AlmaLinux:8: perl-Archive-Tar, AlmaLinux:8: perl-Archive-Zip, AlmaLinux:8: perl-Attribute-Handlers, AlmaLinux:8: perl-AutoLoader, AlmaLinux:8: perl-AutoSplit, AlmaLinux:8: perl-B, AlmaLinux:8: perl-Benchmark, AlmaLinux:8: perl-CPAN and 212 more&lt;/p&gt;
&lt;p&gt;Perl is a high-level programming language that is commonly used for system administration utilities and web programming.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)
  * perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:30851</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-42496</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-42496</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl, Alpaquita:25: perl, Alpaquita:stream: perl, BellSoft Hardened Containers:23: perl, BellSoft Hardened Containers:25: perl, BellSoft Hardened Containers:stream: perl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl, Alpaquita:25: perl, Alpaquita:stream: perl, BellSoft Hardened Containers:23: perl, BellSoft Hardened Containers:25: perl, BellSoft Hardened Containers:stream: perl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-42496</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0731 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</link>
      <description>certfr-2026-avi-0731</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</guid>
    </item>
    <item>
      <title>EUVD-2026-337240</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337240</link>
      <description>EUVD-2026-337240</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337240</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42496</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42496</link>
      <description>&lt;p&gt;Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.&lt;/p&gt;
&lt;p&gt;_make_special_file() passes the tar header&amp;#39;s linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.&lt;/p&gt;
&lt;p&gt;A subsequent open through the extracted name reads or writes the attacker chosen path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.&lt;/p&gt;
&lt;p&gt;_make_special_file() passes the tar header&amp;#39;s linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.&lt;/p&gt;
&lt;p&gt;A subsequent open through the extracted name reads or writes the attacker chosen path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42496</guid>
    </item>
    <item>
      <title>GHSA-8p37-q9qq-hgx8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8p37-q9qq-hgx8</link>
      <description>&lt;p&gt;Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.&lt;/p&gt;
&lt;p&gt;_make_special_file() passes the tar header&amp;#39;s linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.&lt;/p&gt;
&lt;p&gt;A subsequent open through the extracted name reads or writes the attacker chosen path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.&lt;/p&gt;
&lt;p&gt;_make_special_file() passes the tar header&amp;#39;s linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.&lt;/p&gt;
&lt;p&gt;A subsequent open through the extracted name reads or writes the attacker chosen path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8p37-q9qq-hgx8</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-42496 — Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction dir…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42496</link>
      <description>msrc_CVE-2026-42496</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-42496</guid>
    </item>
    <item>
      <title>OESA-2026-2678 — perl-Archive-Tar security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2678</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: perl-Archive-Tar, openEuler:24.03-LTS-SP3: perl-Archive-Tar, openEuler:20.03-LTS-SP4: perl-Archive-Tar, openEuler:22.03-LTS-SP4: perl-Archive-Tar&lt;/p&gt;
&lt;p&gt;archive::Tar provides an object oriented mechanism for handling tar files. It provides class methods for quick and easy files handling while also allowing for the creation of tar file objects for custom manipulation. If you have the IO::Zlib module installed, Archive::Tar will also support compressed or gzipped tar files.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.&lt;/p&gt;
&lt;p&gt;_make_special_file() passes the tar header&amp;amp;apos;s linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.&lt;/p&gt;
&lt;p&gt;A subsequent open through the extracted name reads or writes the attacker chosen path.(CVE-2026-42496)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: perl-Archive-Tar, openEuler:24.03-LTS-SP3: perl-Archive-Tar, openEuler:20.03-LTS-SP4: perl-Archive-Tar, openEuler:22.03-LTS-SP4: perl-Archive-Tar&lt;/p&gt;
&lt;p&gt;archive::Tar provides an object oriented mechanism for handling tar files. It provides class methods for quick and easy files handling while also allowing for the creation of tar file objects for custom manipulation. If you have the IO::Zlib module installed, Archive::Tar will also support compressed or gzipped tar files.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.&lt;/p&gt;
&lt;p&gt;_make_special_file() passes the tar header&amp;amp;apos;s linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.&lt;/p&gt;
&lt;p&gt;A subsequent open through the extracted name reads or writes the attacker chosen path.(CVE-2026-42496)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2678</guid>
    </item>
    <item>
      <title>RHSA-2026:30851 — Red Hat Security Advisory: perl:5.32 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:30851</link>
      <description>&lt;p&gt;perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:30851</guid>
    </item>
    <item>
      <title>RLSA-2026:30851 — Important: perl:5.32 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:30851</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: perl, Rocky Linux:8: perl-Algorithm-Diff, Rocky Linux:8: perl-Archive-Zip, Rocky Linux:8: perl-autodie, Rocky Linux:8: perl-bignum, Rocky Linux:8: perl-Carp, Rocky Linux:8: perl-Compress-Bzip2, Rocky Linux:8: perl-Compress-Raw-Bzip2, Rocky Linux:8: perl-Compress-Raw-Lzma, Rocky Linux:8: perl-Compress-Raw-Zlib and 101 more&lt;/p&gt;
&lt;p&gt;Perl is a high-level programming language that is commonly used for system administration utilities and web programming.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)&lt;/p&gt;
&lt;p&gt;* perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: perl, Rocky Linux:8: perl-Algorithm-Diff, Rocky Linux:8: perl-Archive-Zip, Rocky Linux:8: perl-autodie, Rocky Linux:8: perl-bignum, Rocky Linux:8: perl-Carp, Rocky Linux:8: perl-Compress-Bzip2, Rocky Linux:8: perl-Compress-Raw-Bzip2, Rocky Linux:8: perl-Compress-Raw-Lzma, Rocky Linux:8: perl-Compress-Raw-Zlib and 101 more&lt;/p&gt;
&lt;p&gt;Perl is a high-level programming language that is commonly used for system administration utilities and web programming.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)&lt;/p&gt;
&lt;p&gt;* perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:30851</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-42496</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42496</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: perl, Ubuntu:Pro:18.04:LTS: perl, Ubuntu:Pro:20.04:LTS: perl, Ubuntu:22.04:LTS: perl, Ubuntu:24.04:LTS: perl, Ubuntu:25.10: perl, Ubuntu:26.04:LTS: perl&lt;/p&gt;
&lt;p&gt;Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header&amp;#39;s linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: perl, Ubuntu:Pro:18.04:LTS: perl, Ubuntu:Pro:20.04:LTS: perl, Ubuntu:22.04:LTS: perl, Ubuntu:24.04:LTS: perl, Ubuntu:25.10: perl, Ubuntu:26.04:LTS: perl&lt;/p&gt;
&lt;p&gt;Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header&amp;#39;s linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted name reads or writes the attacker chosen path.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42496</guid>
    </item>
    <item>
      <title>VDE-2026-088 — METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-088</link>
      <description>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25.&lt;/p&gt;
&lt;p&gt;The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25&lt;/p&gt;
&lt;p&gt;All other vulnerabilities are to be fixed in the upcoming releases.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-088</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2666 — cPanel cPanel/WHM (Archive-Tar): Mehrere Schwachstellen ermöglichen Manipulation von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2666</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in cPanel cPanel/WHM ausnutzen, um vertrauliche Informationen preiszugeben oder Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in cPanel cPanel/WHM ausnutzen, um vertrauliche Informationen preiszugeben oder Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2666</guid>
    </item>
  </channel>
</rss>
