<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:45:00 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:7383 — Critical: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:7383</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: cockpit-bridge, AlmaLinux:10: cockpit-doc, AlmaLinux:10: cockpit-packagekit, AlmaLinux:10: cockpit-storaged, AlmaLinux:10: cockpit-system&lt;/p&gt;
&lt;p&gt;Cockpit enables users to administer GNU/Linux servers using a web browser. It  
offers network configuration, log inspection, diagnostic reports, SELinux  
troubleshooting, interactive command-line sessions, and more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cockpit: ws: be more explicit when handling hostnames on cli (CVE-2026-4631)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS  
score, acknowledgments, and other related information, refer to the CVE page(s)  
listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: cockpit-bridge, AlmaLinux:10: cockpit-doc, AlmaLinux:10: cockpit-packagekit, AlmaLinux:10: cockpit-storaged, AlmaLinux:10: cockpit-system&lt;/p&gt;
&lt;p&gt;Cockpit enables users to administer GNU/Linux servers using a web browser. It  
offers network configuration, log inspection, diagnostic reports, SELinux  
troubleshooting, interactive command-line sessions, and more.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cockpit: ws: be more explicit when handling hostnames on cli (CVE-2026-4631)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS  
score, acknowledgments, and other related information, refer to the CVE page(s)  
listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:7383</guid>
    </item>
    <item>
      <title>bdu:2026-05259</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05259</link>
      <description>bdu:2026-05259</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05259</guid>
    </item>
    <item>
      <title>EUVD-2026-344038</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344038</link>
      <description>EUVD-2026-344038</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344038</guid>
    </item>
    <item>
      <title>fkie_cve-2026-4631</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4631</link>
      <description>&lt;p&gt;Cockpit&amp;#39;s remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cockpit&amp;#39;s remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-4631</guid>
    </item>
    <item>
      <title>GHSA-rq49-h582-83m7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rq49-h582-83m7</link>
      <description>&lt;p&gt;Cockpit&amp;#39;s remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cockpit&amp;#39;s remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rq49-h582-83m7</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10531-1 — cockpit-360-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10531-1</link>
      <description>&lt;p&gt;cockpit-360-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cockpit-360-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10531-1</guid>
    </item>
    <item>
      <title>RHSA-2026:7381 — Red Hat Security Advisory: cockpit: Unauthenticated remote code execution due to SSH command-line argument injection</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:7381</link>
      <description>&lt;p&gt;cockpit: Cockpit: Unauthenticated remote code execution due to SSH command-line argument injection&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cockpit: Cockpit: Unauthenticated remote code execution due to SSH command-line argument injection&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:7381</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21106-1 — Security update for cockpit</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21106-1</link>
      <description>&lt;p&gt;Security update for cockpit&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for cockpit&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21106-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-4631</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4631</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: cockpit, Ubuntu:20.04:LTS: cockpit, Ubuntu:22.04:LTS: cockpit, Ubuntu:24.04:LTS: cockpit, Ubuntu:25.10: cockpit, Ubuntu:26.04:LTS: cockpit&lt;/p&gt;
&lt;p&gt;Cockpit&amp;#39;s remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: cockpit, Ubuntu:20.04:LTS: cockpit, Ubuntu:22.04:LTS: cockpit, Ubuntu:24.04:LTS: cockpit, Ubuntu:25.10: cockpit, Ubuntu:26.04:LTS: cockpit&lt;/p&gt;
&lt;p&gt;Cockpit&amp;#39;s remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options or shell commands, achieving code execution on the Cockpit host without valid credentials. The injection occurs during the authentication flow before any credential verification takes place, meaning no login is required to exploit the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4631</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1052 — Red Hat Enterprise Linux (Cockpit): Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1052</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1052</guid>
    </item>
  </channel>
</rss>
