<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:34:45 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:46391 — Important: grafana security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:46391</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: grafana, AlmaLinux:8: grafana-selinux&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [grafana / almalinux-8.10.z] Remove Lua ExclusiveArch macro for Konflux build (JIRA:AlmaLinux-188279)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: grafana, AlmaLinux:8: grafana-selinux&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [grafana / almalinux-8.10.z] Remove Lua ExclusiveArch macro for Konflux build (JIRA:AlmaLinux-188279)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:46391</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AQ65185 — Security fixes for CVE-2025-47913, CVE-2025-47914, CVE-2025-58181, CVE-2025-61727, CVE-2025-61729, CVE-2026-1229, CVE-2…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aq65185</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: terragrunt-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the terragrunt-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: terragrunt-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the terragrunt-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aq65185</guid>
    </item>
    <item>
      <title>EUVD-2026-323552</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323552</link>
      <description>EUVD-2026-323552</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323552</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44740</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44740</link>
      <description>&lt;p&gt;Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44740</guid>
    </item>
    <item>
      <title>GHSA-m3xc-h892-ggx6 — go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m3xc-h892-ggx6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-git/go-billy/v5, Go: github.com/go-git/go-billy/v6&lt;/p&gt;
&lt;p&gt;### Impact
Multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption.&lt;/p&gt;
&lt;p&gt;These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures.&lt;/p&gt;
&lt;p&gt;### Patches
Users should upgrade to a patched version in order to mitigate this vulnerability. Versions prior to `v5` are likely to be affected, users are recommended to upgrade to a supported `go-billy` version.&lt;/p&gt;
&lt;p&gt;### Credits
Thanks to @faran66 for finding and reporting this issue privately to the go-git project. 🙇&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-git/go-billy/v5, Go: github.com/go-git/go-billy/v6&lt;/p&gt;
&lt;p&gt;### Impact
Multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption.&lt;/p&gt;
&lt;p&gt;These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures.&lt;/p&gt;
&lt;p&gt;### Patches
Users should upgrade to a patched version in order to mitigate this vulnerability. Versions prior to `v5` are likely to be affected, users are recommended to upgrade to a supported `go-billy` version.&lt;/p&gt;
&lt;p&gt;### Credits
Thanks to @faran66 for finding and reporting this issue privately to the go-git project. 🙇&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m3xc-h892-ggx6</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10856-1 — rclone-1.74.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10856-1</link>
      <description>&lt;p&gt;rclone-1.74.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rclone-1.74.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10856-1</guid>
    </item>
    <item>
      <title>RHSA-2026:32963 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:32963</link>
      <description>&lt;p&gt;github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation github.com/containerd/containerd: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation github.com/containerd/containerd: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:32963</guid>
    </item>
    <item>
      <title>RLSA-2026:46391 — Important: grafana security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:46391</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [grafana / rhel-8.10.z] Remove Lua ExclusiveArch macro for Konflux build (JIRA:Rocky Linux-188279)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [grafana / rhel-8.10.z] Remove Lua ExclusiveArch macro for Konflux build (JIRA:Rocky Linux-188279)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:46391</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22157-1 — Security update for amazon-ssm-agent</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22157-1</link>
      <description>&lt;p&gt;Security update for amazon-ssm-agent&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for amazon-ssm-agent&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22157-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-44740</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44740</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-go-git-go-billy, Ubuntu:24.04:LTS: golang-github-go-git-go-billy, Ubuntu:25.10: golang-github-go-git-go-billy, Ubuntu:26.04:LTS: golang-github-go-git-go-billy&lt;/p&gt;
&lt;p&gt;Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-go-git-go-billy, Ubuntu:24.04:LTS: golang-github-go-git-go-billy, Ubuntu:25.10: golang-github-go-git-go-billy, Ubuntu:26.04:LTS: golang-github-go-git-go-billy&lt;/p&gt;
&lt;p&gt;Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44740</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2520 — Red Hat Enterprise Linux (go-billy): Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2520</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2520</guid>
    </item>
  </channel>
</rss>
