<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:39:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-380653</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-380653</link>
      <description>EUVD-2026-380653</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-380653</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42965</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42965</link>
      <description>&lt;p&gt;A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42965</guid>
    </item>
    <item>
      <title>GHSA-76ww-43j5-78x5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-76ww-43j5-78x5</link>
      <description>&lt;p&gt;A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-76ww-43j5-78x5</guid>
    </item>
    <item>
      <title>RHSA-2026:54583 — Red Hat Security Advisory: OpenShift Container Platform 4.20.34 bug fix and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:54583</link>
      <description>&lt;p&gt;golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting net/mail: golang: Go net/mail: Denial of Service via crafted email inputs net/mail: golang: net/mail: Denial of Service via pathological email address parsing openshift/router: openshift/router: cloud metadata SSRF via FQDN-typed EndpointSlice bypasses destination validation openstack-ironic: Prevent rehoming resources to nodes with different owner openshift/console: Authenticated SSRF with full response reflection and path neutralization via Dev Console webhook helpers in OpenShift Console openshift/console: Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting net/mail: golang: Go net/mail: Denial of Service via crafted email inputs net/mail: golang: net/mail: Denial of Service via pathological email address parsing openshift/router: openshift/router: cloud metadata SSRF via FQDN-typed EndpointSlice bypasses destination validation openstack-ironic: Prevent rehoming resources to nodes with different owner openshift/console: Authenticated SSRF with full response reflection and path neutralization via Dev Console webhook helpers in OpenShift Console openshift/console: Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:54583</guid>
    </item>
  </channel>
</rss>
