<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:57:43 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15305</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15305</link>
      <description>bdu:2026-15305</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15305</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-42502</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-42502</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: buildah, Alpaquita:23: containerd, Alpaquita:23: podman, Alpaquita:23: runc, Alpaquita:23: skopeo, Alpaquita:25: buildah, Alpaquita:25: containerd, Alpaquita:25: docker-cli-buildx, Alpaquita:25: google-guest-agent, Alpaquita:25: osv-scanner and 20 more&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: buildah, Alpaquita:23: containerd, Alpaquita:23: podman, Alpaquita:23: runc, Alpaquita:23: skopeo, Alpaquita:25: buildah, Alpaquita:25: containerd, Alpaquita:25: docker-cli-buildx, Alpaquita:25: google-guest-agent, Alpaquita:25: osv-scanner and 20 more&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-42502</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0674 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0674</link>
      <description>certfr-2026-avi-0674</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0674</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD30368 — Security fixes for CVE-2026-2303, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-39827, CVE-2…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad30368</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: weaviate-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the weaviate-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: weaviate-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the weaviate-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad30368</guid>
    </item>
    <item>
      <title>EUVD-2026-320139</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-320139</link>
      <description>EUVD-2026-320139</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-320139</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42502</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42502</link>
      <description>&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42502</guid>
    </item>
    <item>
      <title>GHSA-wrh2-89vg-4j9g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wrh2-89vg-4j9g</link>
      <description>&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wrh2-89vg-4j9g</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-42502 — Invoking  incorrect handling of HTML elements in foreign content in golang.org/x/net/html</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42502</link>
      <description>msrc_CVE-2026-42502</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-42502</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10856-1 — rclone-1.74.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10856-1</link>
      <description>&lt;p&gt;rclone-1.74.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rclone-1.74.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10856-1</guid>
    </item>
    <item>
      <title>RHSA-2026:26546 — Red Hat Security Advisory: RHACS 4.9.8 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:26546</link>
      <description>&lt;p&gt;golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:26546</guid>
    </item>
    <item>
      <title>RLSA-2026:66432 — Important: osbuild-composer security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:66432</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502)&lt;/p&gt;
&lt;p&gt;* github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)&lt;/p&gt;
&lt;p&gt;* github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502)&lt;/p&gt;
&lt;p&gt;* github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)&lt;/p&gt;
&lt;p&gt;* github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:66432</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22065-1 — Security update for elemental-toolkit</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22065-1</link>
      <description>&lt;p&gt;Security update for elemental-toolkit&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for elemental-toolkit&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22065-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-42502</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42502</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: golang-golang-x-net-dev, Ubuntu:Pro:18.04:LTS: golang-golang-x-net-dev, Ubuntu:Pro:20.04:LTS: golang-golang-x-net-dev&lt;/p&gt;
&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: golang-golang-x-net-dev, Ubuntu:Pro:18.04:LTS: golang-golang-x-net-dev, Ubuntu:Pro:20.04:LTS: golang-golang-x-net-dev&lt;/p&gt;
&lt;p&gt;Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42502</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1653 — Golang Go-Module (Net, Image, Crypto: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1653</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um erweiterte Privilegien zu erlangen, Cross-Site-Scripting-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um erweiterte Privilegien zu erlangen, Cross-Site-Scripting-Angriffe durchzuführen, Sicherheitsmaßnahmen zu umgehen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1653</guid>
    </item>
  </channel>
</rss>
