<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:09:09 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-PW57640 — Security fixes for CVE-2025-61726, CVE-2025-61728, CVE-2025-61730, CVE-2025-61732, CVE-2025-68119, CVE-2025-68121, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-pw57640</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: grafana-alloy-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the grafana-alloy-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: grafana-alloy-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the grafana-alloy-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-pw57640</guid>
    </item>
    <item>
      <title>fkie_cve-2026-4427</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4427</link>
      <description>&lt;p&gt;Rejected reason: Duplicate of CVE-2026-32286&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rejected reason: Duplicate of CVE-2026-32286&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-4427</guid>
    </item>
    <item>
      <title>Withdrawn: GHSA-x6gf-mpr2-68h6 — Duplicate Advisory: pgproto3: Negative field length panics in DataRow.Decode</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x6gf-mpr2-68h6</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/jackc/pgproto3/v2&lt;/p&gt;
&lt;p&gt;## Duplicate Advisory&lt;/p&gt;
&lt;p&gt;This advisory has been withdrawn because it is a duplicate of GHSA-jqcq-xjh3-6g23. This link is maintained to preserve external references.&lt;/p&gt;
&lt;p&gt;## Original Description
A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/jackc/pgproto3/v2&lt;/p&gt;
&lt;p&gt;## Duplicate Advisory&lt;/p&gt;
&lt;p&gt;This advisory has been withdrawn because it is a duplicate of GHSA-jqcq-xjh3-6g23. This link is maintained to preserve external references.&lt;/p&gt;
&lt;p&gt;## Original Description
A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x6gf-mpr2-68h6</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10669-1 — alloy-1.16.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10669-1</link>
      <description>&lt;p&gt;alloy-1.16.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;alloy-1.16.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10669-1</guid>
    </item>
    <item>
      <title>RHSA-2026:10126 — Red Hat Security Advisory: RHTAS 1.3.4 - Red Hat Trusted Artifact Signer Release</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10126</link>
      <description>&lt;p&gt;google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10126</guid>
    </item>
    <item>
      <title>RLSA-2026:22450 — Important: osbuild-composer security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:22450</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728)&lt;/p&gt;
&lt;p&gt;* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)&lt;/p&gt;
&lt;p&gt;* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)&lt;/p&gt;
&lt;p&gt;* crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message (CVE-2026-4427,GHSA-jqcq-xjh3-6g23)&lt;/p&gt;
&lt;p&gt;* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server (CVE-2026-32286)&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)&lt;/p&gt;
&lt;p&gt;* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)&lt;/p&gt;
&lt;p&gt;* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728)&lt;/p&gt;
&lt;p&gt;* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)&lt;/p&gt;
&lt;p&gt;* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)&lt;/p&gt;
&lt;p&gt;* crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137)&lt;/p&gt;
&lt;p&gt;* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3: pgproto3: Denial of Service via negative field length in DataRow message (CVE-2026-4427,GHSA-jqcq-xjh3-6g23)&lt;/p&gt;
&lt;p&gt;* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)&lt;/p&gt;
&lt;p&gt;* github.com/jackc/pgproto3/v2: github.com/jackc/pgproto3/v2: Denial of Service via malicious PostgreSQL server (CVE-2026-32286)&lt;/p&gt;
&lt;p&gt;* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)&lt;/p&gt;
&lt;p&gt;* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)&lt;/p&gt;
&lt;p&gt;* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:22450</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21793-1 — Security update for alloy</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21793-1</link>
      <description>&lt;p&gt;Security update for alloy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for alloy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21793-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2026-4427</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4427</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-jackc-pgproto3, Ubuntu:25.10: golang-github-jackc-pgproto3&lt;/p&gt;
&lt;p&gt;A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-jackc-pgproto3, Ubuntu:25.10: golang-github-jackc-pgproto3&lt;/p&gt;
&lt;p&gt;A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4427</guid>
    </item>
  </channel>
</rss>
