<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:18:37 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-14966</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14966</link>
      <description>bdu:2026-14966</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14966</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-48165</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-48165</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: mariadb, Alpaquita:25: mariadb, Alpaquita:stream: mariadb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: mariadb, Alpaquita:25: mariadb, Alpaquita:stream: mariadb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-48165</guid>
    </item>
    <item>
      <title>BIT-mariadb-2026-48165 — MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side</title>
      <link>https://cve.radiocsirt.org/vuln/bit-mariadb-2026-48165</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mariadb&lt;/p&gt;
&lt;p&gt;MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could&amp;#39;ve used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mariadb&lt;/p&gt;
&lt;p&gt;MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could&amp;#39;ve used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-mariadb-2026-48165</guid>
    </item>
    <item>
      <title>EUVD-2026-343632</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343632</link>
      <description>EUVD-2026-343632</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343632</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48165</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48165</link>
      <description>&lt;p&gt;MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could&amp;#39;ve used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could&amp;#39;ve used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48165</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10934-1 — libmariadbd-devel-11.8.8-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10934-1</link>
      <description>&lt;p&gt;libmariadbd-devel-11.8.8-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libmariadbd-devel-11.8.8-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10934-1</guid>
    </item>
    <item>
      <title>RHSA-2026:25143 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:25143</link>
      <description>&lt;p&gt;mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check mariadb: Arbitrary shell command execution via improper sanitization in CONNECT engine mariadb: mbstream: Unauthorized file creation via path traversal mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries urllib3: urllib3: Denial of Service due to excessive HTTP response decompression mariadb: Arbitrary code execution via improper parameter validation during SST mariadb: Arbitrary code execution via global system variable manipulation by a high-privileged user mariadb: MariaDB Server: Arbitrary code execution via wsrep_notify_cmd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer mariadb: MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check mariadb: Arbitrary shell command execution via improper sanitization in CONNECT engine mariadb: mbstream: Unauthorized file creation via path traversal mariadb: MariaDB: Privilege bypass allows unauthorized file write via subqueries urllib3: urllib3: Denial of Service due to excessive HTTP response decompression mariadb: Arbitrary code execution via improper parameter validation during SST mariadb: Arbitrary code execution via global system variable manipulation by a high-privileged user mariadb: MariaDB Server: Arbitrary code execution via wsrep_notify_cmd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:25143</guid>
    </item>
    <item>
      <title>RLSA-2026:33093 — Important: mariadb10.11 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:33093</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: mariadb10.11&lt;/p&gt;
&lt;p&gt;MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mariadb: MariaDB Server: Arbitrary code execution via wsrep_notify_cmd (CVE-2026-49261)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Rebase MariaDB 10.11 to 10.11.18 in Rocky Linux10 (JIRA:Rocky Linux-183086)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: mariadb10.11&lt;/p&gt;
&lt;p&gt;MariaDB is a community developed fork from MySQL - a multi-user, multi-threaded SQL database server. It is a client/server implementation consisting of a server daemon (mariadbd) and many different client programs and libraries. The base package contains the standard MariaDB/MySQL client programs and utilities.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mariadb: MariaDB Server: Arbitrary code execution via wsrep_notify_cmd (CVE-2026-49261)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* Rebase MariaDB 10.11 to 10.11.18 in Rocky Linux10 (JIRA:Rocky Linux-183086)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:33093</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22095-1 — Security update for mariadb</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22095-1</link>
      <description>&lt;p&gt;Security update for mariadb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for mariadb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22095-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48165</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48165</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: mariadb-10.0, Ubuntu:18.04:LTS: mariadb-10.1, Ubuntu:20.04:LTS: mariadb-10.3, Ubuntu:22.04:LTS: mariadb-10.6, Ubuntu:24.04:LTS: mariadb, Ubuntu:25.10: mariadb, Ubuntu:26.04:LTS: mariadb&lt;/p&gt;
&lt;p&gt;MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could&amp;#39;ve used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: mariadb-10.0, Ubuntu:18.04:LTS: mariadb-10.1, Ubuntu:20.04:LTS: mariadb-10.3, Ubuntu:22.04:LTS: mariadb-10.6, Ubuntu:24.04:LTS: mariadb, Ubuntu:25.10: mariadb, Ubuntu:26.04:LTS: mariadb&lt;/p&gt;
&lt;p&gt;MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could&amp;#39;ve used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48165</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1744 — MariaDB: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1744</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MariaDB ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in MariaDB ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1744</guid>
    </item>
  </channel>
</rss>
