<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:17:02 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-43617</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-43617</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: rsync, Alpaquita:25: rsync, Alpaquita:stream: rsync&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: rsync, Alpaquita:25: rsync, Alpaquita:stream: rsync&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-43617</guid>
    </item>
    <item>
      <title>EUVD-2026-336806</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336806</link>
      <description>EUVD-2026-336806</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336806</guid>
    </item>
    <item>
      <title>fkie_cve-2026-43617</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-43617</link>
      <description>&lt;p&gt;Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon&amp;#39;s hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon&amp;#39;s hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-43617</guid>
    </item>
    <item>
      <title>GHSA-4j4q-473w-9q2r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4j4q-473w-9q2r</link>
      <description>&lt;p&gt;Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon&amp;#39;s hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon&amp;#39;s hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4j4q-473w-9q2r</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-43617 — Rsync &lt; 3.4.3 Authorization Bypass via Hostname Resolution</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-43617</link>
      <description>msrc_CVE-2026-43617</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-43617</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10857-1 — rsync-3.4.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10857-1</link>
      <description>&lt;p&gt;rsync-3.4.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rsync-3.4.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10857-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:2048-1 — Security update for rsync</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:2048-1</link>
      <description>&lt;p&gt;Security update for rsync&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rsync&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:2048-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-43617</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43617</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: rsync, Ubuntu:Pro:16.04:LTS: rsync, Ubuntu:Pro:18.04:LTS: rsync, Ubuntu:Pro:20.04:LTS: rsync, Ubuntu:22.04:LTS: rsync, Ubuntu:24.04:LTS: rsync, Ubuntu:25.10: rsync, Ubuntu:26.04:LTS: rsync&lt;/p&gt;
&lt;p&gt;Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon&amp;#39;s hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: rsync, Ubuntu:Pro:16.04:LTS: rsync, Ubuntu:Pro:18.04:LTS: rsync, Ubuntu:Pro:20.04:LTS: rsync, Ubuntu:22.04:LTS: rsync, Ubuntu:24.04:LTS: rsync, Ubuntu:25.10: rsync, Ubuntu:26.04:LTS: rsync&lt;/p&gt;
&lt;p&gt;Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon&amp;#39;s hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-43617</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1611 — Rsync: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1611</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um seine Privilegien zu erhöhen, um Informationen offenzulegen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um seine Privilegien zu erhöhen, um Informationen offenzulegen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1611</guid>
    </item>
  </channel>
</rss>
