<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:39:26 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:25902 — Important: fence-agents security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:25902</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: fence-agents-aliyun, AlmaLinux:10: fence-agents-all, AlmaLinux:10: fence-agents-amt-ws, AlmaLinux:10: fence-agents-apc, AlmaLinux:10: fence-agents-apc-snmp, AlmaLinux:10: fence-agents-aws, AlmaLinux:10: fence-agents-azure-arm, AlmaLinux:10: fence-agents-bladecenter, AlmaLinux:10: fence-agents-brocade, AlmaLinux:10: fence-agents-cisco-mds and 45 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens (CVE-2026-48526)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: fence-agents-aliyun, AlmaLinux:10: fence-agents-all, AlmaLinux:10: fence-agents-amt-ws, AlmaLinux:10: fence-agents-apc, AlmaLinux:10: fence-agents-apc-snmp, AlmaLinux:10: fence-agents-aws, AlmaLinux:10: fence-agents-azure-arm, AlmaLinux:10: fence-agents-bladecenter, AlmaLinux:10: fence-agents-brocade, AlmaLinux:10: fence-agents-cisco-mds and 45 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens (CVE-2026-48526)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:25902</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-48526</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-48526</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: py3-jwt, Alpaquita:stream: py3-jwt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: py3-jwt, Alpaquita:stream: py3-jwt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-48526</guid>
    </item>
    <item>
      <title>BREW-azure-cli-CVE-2026-48526 — PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed</title>
      <link>https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2026-48526</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: azure-cli&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; Exploitation requires a verifier configured with both symmetric and asymmetric algorithms in `algorithms=[…]` and a raw-JSON JWK as the `key=` argument, both contrary to documented usage, hence the High attack-complexity rating.&lt;/p&gt;
&lt;p&gt;### Summary
When the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm.&lt;/p&gt;
&lt;p&gt;### Details
In JWT algorithm confusion attack, the verifier is mistakenly use of public key to be used as the shared secret in symmetric algorithms.
In pyjwt case, when the verifier is supporting both HMAC with other asymmetric algorithm and mistakenly using the public key of the issuer to verify the token as demonstrated in the following example:
  
`jws.decode(token, key=rsa_jwk_json, algorithms=[&amp;#34;HS256&amp;#34;,&amp;#34;RS256&amp;#34;])) `&lt;/p&gt;
&lt;p&gt;An attacker who specifies in the token header to use HMAC, will cause the verifier to accept the JWK as the secret key in HMAC algorithm. 
The attacker will be able to forge JWT signed with the public key of the issuer to impersonate any user.&lt;/p&gt;
&lt;p&gt;If we look on current protections implemented in the library, at class HMACAlgorithm:&lt;/p&gt;
&lt;p&gt;```
  def prepare_key(self, key: str | bytes) -&amp;gt; bytes:
        key_bytes = force_bytes(key)&lt;/p&gt;
&lt;p&gt;if is_pem_format(key_bytes) or is_ssh_key(key_bytes):
            raise InvalidKeyError(
                &amp;#34;The specified key is…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: azure-cli&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; Exploitation requires a verifier configured with both symmetric and asymmetric algorithms in `algorithms=[…]` and a raw-JSON JWK as the `key=` argument, both contrary to documented usage, hence the High attack-complexity rating.&lt;/p&gt;
&lt;p&gt;### Summary
When the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm.&lt;/p&gt;
&lt;p&gt;### Details
In JWT algorithm confusion attack, the verifier is mistakenly use of public key to be used as the shared secret in symmetric algorithms.
In pyjwt case, when the verifier is supporting both HMAC with other asymmetric algorithm and mistakenly using the public key of the issuer to verify the token as demonstrated in the following example:
  
`jws.decode(token, key=rsa_jwk_json, algorithms=[&amp;#34;HS256&amp;#34;,&amp;#34;RS256&amp;#34;])) `&lt;/p&gt;
&lt;p&gt;An attacker who specifies in the token header to use HMAC, will cause the verifier to accept the JWK as the secret key in HMAC algorithm. 
The attacker will be able to forge JWT signed with the public key of the issuer to impersonate any user.&lt;/p&gt;
&lt;p&gt;If we look on current protections implemented in the library, at class HMACAlgorithm:&lt;/p&gt;
&lt;p&gt;```
  def prepare_key(self, key: str | bytes) -&amp;gt; bytes:
        key_bytes = force_bytes(key)&lt;/p&gt;
&lt;p&gt;if is_pem_format(key_bytes) or is_ssh_key(key_bytes):
            raise InvalidKeyError(
                &amp;#34;The specified key is…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2026-48526</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AF67526 — Security fixes for CVE-2026-42304, CVE-2026-44307, CVE-2026-48522, CVE-2026-48523, CVE-2026-48524, CVE-2026-48525, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-af67526</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jupyterhub-k8s-hub&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the jupyterhub-k8s-hub package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jupyterhub-k8s-hub&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the jupyterhub-k8s-hub package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-af67526</guid>
    </item>
    <item>
      <title>EUVD-2026-366080</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366080</link>
      <description>EUVD-2026-366080</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366080</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48526</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48526</link>
      <description>&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48526</guid>
    </item>
    <item>
      <title>GHSA-xgmm-8j9v-c9wx — PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xgmm-8j9v-c9wx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyjwt&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; Exploitation requires a verifier configured with both symmetric and asymmetric algorithms in `algorithms=[…]` and a raw-JSON JWK as the `key=` argument, both contrary to documented usage, hence the High attack-complexity rating.&lt;/p&gt;
&lt;p&gt;### Summary
When the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm.&lt;/p&gt;
&lt;p&gt;### Details
In JWT algorithm confusion attack, the verifier is mistakenly use of public key to be used as the shared secret in symmetric algorithms.
In pyjwt case, when the verifier is supporting both HMAC with other asymmetric algorithm and mistakenly using the public key of the issuer to verify the token as demonstrated in the following example:
  
`jws.decode(token, key=rsa_jwk_json, algorithms=[&amp;#34;HS256&amp;#34;,&amp;#34;RS256&amp;#34;])) `&lt;/p&gt;
&lt;p&gt;An attacker who specifies in the token header to use HMAC, will cause the verifier to accept the JWK as the secret key in HMAC algorithm. 
The attacker will be able to forge JWT signed with the public key of the issuer to impersonate any user.&lt;/p&gt;
&lt;p&gt;If we look on current protections implemented in the library, at class HMACAlgorithm:&lt;/p&gt;
&lt;p&gt;```
  def prepare_key(self, key: str | bytes) -&amp;gt; bytes:
        key_bytes = force_bytes(key)&lt;/p&gt;
&lt;p&gt;if is_pem_format(key_bytes) or is_ssh_key(key_bytes):
            raise InvalidKeyError(
                &amp;#34;The specified key is…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyjwt&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; Exploitation requires a verifier configured with both symmetric and asymmetric algorithms in `algorithms=[…]` and a raw-JSON JWK as the `key=` argument, both contrary to documented usage, hence the High attack-complexity rating.&lt;/p&gt;
&lt;p&gt;### Summary
When the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm.&lt;/p&gt;
&lt;p&gt;### Details
In JWT algorithm confusion attack, the verifier is mistakenly use of public key to be used as the shared secret in symmetric algorithms.
In pyjwt case, when the verifier is supporting both HMAC with other asymmetric algorithm and mistakenly using the public key of the issuer to verify the token as demonstrated in the following example:
  
`jws.decode(token, key=rsa_jwk_json, algorithms=[&amp;#34;HS256&amp;#34;,&amp;#34;RS256&amp;#34;])) `&lt;/p&gt;
&lt;p&gt;An attacker who specifies in the token header to use HMAC, will cause the verifier to accept the JWK as the secret key in HMAC algorithm. 
The attacker will be able to forge JWT signed with the public key of the issuer to impersonate any user.&lt;/p&gt;
&lt;p&gt;If we look on current protections implemented in the library, at class HMACAlgorithm:&lt;/p&gt;
&lt;p&gt;```
  def prepare_key(self, key: str | bytes) -&amp;gt; bytes:
        key_bytes = force_bytes(key)&lt;/p&gt;
&lt;p&gt;if is_pem_format(key_bytes) or is_ssh_key(key_bytes):
            raise InvalidKeyError(
                &amp;#34;The specified key is…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xgmm-8j9v-c9wx</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-48526 — PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-48526</link>
      <description>msrc_CVE-2026-48526</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-48526</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11024-1 — python311-PyJWT-2.13.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11024-1</link>
      <description>&lt;p&gt;python311-PyJWT-2.13.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-PyJWT-2.13.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11024-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-179</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-179</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyjwt&lt;/p&gt;
&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyjwt&lt;/p&gt;
&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-179</guid>
    </item>
    <item>
      <title>RHSA-2026:25928 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:25928</link>
      <description>&lt;p&gt;ansible-lightspeed: Ansible Lightspeed: Session hijacking and unauthorized data access due to insufficient session expiration urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ansible-lightspeed: Ansible Lightspeed: Session hijacking and unauthorized data access due to insufficient session expiration urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:25928</guid>
    </item>
    <item>
      <title>RLSA-2026:25902 — Important: fence-agents security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:25902</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: fence-agents&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens (CVE-2026-48526)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: fence-agents&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens (CVE-2026-48526)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:25902</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22138-1 — Security update for python-PyJWT</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22138-1</link>
      <description>&lt;p&gt;Security update for python-PyJWT&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-PyJWT&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22138-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48526</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48526</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: pyjwt, Ubuntu:Pro:18.04:LTS: pyjwt, Ubuntu:Pro:20.04:LTS: pyjwt, Ubuntu:22.04:LTS: pyjwt, Ubuntu:24.04:LTS: pyjwt, Ubuntu:25.10: pyjwt, Ubuntu:26.04:LTS: pyjwt&lt;/p&gt;
&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: pyjwt, Ubuntu:Pro:18.04:LTS: pyjwt, Ubuntu:Pro:20.04:LTS: pyjwt, Ubuntu:22.04:LTS: pyjwt, Ubuntu:24.04:LTS: pyjwt, Ubuntu:25.10: pyjwt, Ubuntu:26.04:LTS: pyjwt&lt;/p&gt;
&lt;p&gt;PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48526</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1923 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1923</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, Daten zu manipulieren und einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, Daten zu manipulieren und einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1923</guid>
    </item>
  </channel>
</rss>
