<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:07:14 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:30851 — Important: perl:5.32 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:30851</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: perl, AlmaLinux:8: perl-Algorithm-Diff, AlmaLinux:8: perl-Archive-Tar, AlmaLinux:8: perl-Archive-Zip, AlmaLinux:8: perl-Attribute-Handlers, AlmaLinux:8: perl-AutoLoader, AlmaLinux:8: perl-AutoSplit, AlmaLinux:8: perl-B, AlmaLinux:8: perl-Benchmark, AlmaLinux:8: perl-CPAN and 212 more&lt;/p&gt;
&lt;p&gt;Perl is a high-level programming language that is commonly used for system administration utilities and web programming.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)
  * perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: perl, AlmaLinux:8: perl-Algorithm-Diff, AlmaLinux:8: perl-Archive-Tar, AlmaLinux:8: perl-Archive-Zip, AlmaLinux:8: perl-Attribute-Handlers, AlmaLinux:8: perl-AutoLoader, AlmaLinux:8: perl-AutoSplit, AlmaLinux:8: perl-B, AlmaLinux:8: perl-Benchmark, AlmaLinux:8: perl-CPAN and 212 more&lt;/p&gt;
&lt;p&gt;Perl is a high-level programming language that is commonly used for system administration utilities and web programming.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)
  * perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:30851</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-48962</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-48962</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl, Alpaquita:25: perl, Alpaquita:stream: perl, BellSoft Hardened Containers:23: perl, BellSoft Hardened Containers:25: perl, BellSoft Hardened Containers:stream: perl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl, Alpaquita:25: perl, Alpaquita:stream: perl, BellSoft Hardened Containers:23: perl, BellSoft Hardened Containers:25: perl, BellSoft Hardened Containers:stream: perl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-48962</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0731 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</link>
      <description>certfr-2026-avi-0731</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</guid>
    </item>
    <item>
      <title>EUVD-2026-347579</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-347579</link>
      <description>EUVD-2026-347579</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-347579</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48962</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48962</link>
      <description>&lt;p&gt;IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.&lt;/p&gt;
&lt;p&gt;_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.&lt;/p&gt;
&lt;p&gt;Arbitrary Perl in the output glob executes at the calling process&amp;#39;s privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.&lt;/p&gt;
&lt;p&gt;_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.&lt;/p&gt;
&lt;p&gt;Arbitrary Perl in the output glob executes at the calling process&amp;#39;s privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48962</guid>
    </item>
    <item>
      <title>GHSA-q6wx-vhvq-x7h6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q6wx-vhvq-x7h6</link>
      <description>&lt;p&gt;IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.&lt;/p&gt;
&lt;p&gt;_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.&lt;/p&gt;
&lt;p&gt;Arbitrary Perl in the output glob executes at the calling process&amp;#39;s privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.&lt;/p&gt;
&lt;p&gt;_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.&lt;/p&gt;
&lt;p&gt;Arbitrary Perl in the output glob executes at the calling process&amp;#39;s privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q6wx-vhvq-x7h6</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-48962 — IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled o…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-48962</link>
      <description>msrc_CVE-2026-48962</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-48962</guid>
    </item>
    <item>
      <title>NCSC-2026-0321 — Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0321</link>
      <description>NCSC-2026-0321</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0321</guid>
    </item>
    <item>
      <title>OESA-2026-2610 — perl-IO-Compress security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2610</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: perl-IO-Compress&lt;/p&gt;
&lt;p&gt;This distribution provides a Perl interface to allow reading and writing of compressed data created with the zlib and bzip2 libraries.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.&lt;/p&gt;
&lt;p&gt;_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.&lt;/p&gt;
&lt;p&gt;Arbitrary Perl in the output glob executes at the calling process&amp;amp;apos;s privilege.(CVE-2026-48962)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: perl-IO-Compress&lt;/p&gt;
&lt;p&gt;This distribution provides a Perl interface to allow reading and writing of compressed data created with the zlib and bzip2 libraries.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.&lt;/p&gt;
&lt;p&gt;_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.&lt;/p&gt;
&lt;p&gt;Arbitrary Perl in the output glob executes at the calling process&amp;amp;apos;s privilege.(CVE-2026-48962)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2610</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10939-1 — perl-IO-Compress-2.220.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10939-1</link>
      <description>&lt;p&gt;perl-IO-Compress-2.220.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;perl-IO-Compress-2.220.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10939-1</guid>
    </item>
    <item>
      <title>RHSA-2026:29182 — Red Hat Security Advisory: perl-IO-Compress security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:29182</link>
      <description>&lt;p&gt;perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:29182</guid>
    </item>
    <item>
      <title>RLSA-2026:30851 — Important: perl:5.32 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:30851</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: perl, Rocky Linux:8: perl-Algorithm-Diff, Rocky Linux:8: perl-Archive-Zip, Rocky Linux:8: perl-autodie, Rocky Linux:8: perl-bignum, Rocky Linux:8: perl-Carp, Rocky Linux:8: perl-Compress-Bzip2, Rocky Linux:8: perl-Compress-Raw-Bzip2, Rocky Linux:8: perl-Compress-Raw-Lzma, Rocky Linux:8: perl-Compress-Raw-Zlib and 101 more&lt;/p&gt;
&lt;p&gt;Perl is a high-level programming language that is commonly used for system administration utilities and web programming.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)&lt;/p&gt;
&lt;p&gt;* perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: perl, Rocky Linux:8: perl-Algorithm-Diff, Rocky Linux:8: perl-Archive-Zip, Rocky Linux:8: perl-autodie, Rocky Linux:8: perl-bignum, Rocky Linux:8: perl-Carp, Rocky Linux:8: perl-Compress-Bzip2, Rocky Linux:8: perl-Compress-Raw-Bzip2, Rocky Linux:8: perl-Compress-Raw-Lzma, Rocky Linux:8: perl-Compress-Raw-Zlib and 101 more&lt;/p&gt;
&lt;p&gt;Perl is a high-level programming language that is commonly used for system administration utilities and web programming.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)&lt;/p&gt;
&lt;p&gt;* perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:30851</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48962</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48962</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: perl, Ubuntu:Pro:16.04:LTS: perl, Ubuntu:16.04:LTS: libio-compress-perl, Ubuntu:Pro:18.04:LTS: perl, Ubuntu:18.04:LTS: libio-compress-perl, Ubuntu:Pro:20.04:LTS: perl, Ubuntu:20.04:LTS: libio-compress-perl, Ubuntu:22.04:LTS: libio-compress-perl, Ubuntu:22.04:LTS: perl, Ubuntu:24.04:LTS: libio-compress-perl and 5 more&lt;/p&gt;
&lt;p&gt;IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process&amp;#39;s privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: perl, Ubuntu:Pro:16.04:LTS: perl, Ubuntu:16.04:LTS: libio-compress-perl, Ubuntu:Pro:18.04:LTS: perl, Ubuntu:18.04:LTS: libio-compress-perl, Ubuntu:Pro:20.04:LTS: perl, Ubuntu:20.04:LTS: libio-compress-perl, Ubuntu:22.04:LTS: libio-compress-perl, Ubuntu:22.04:LTS: perl, Ubuntu:24.04:LTS: libio-compress-perl and 5 more&lt;/p&gt;
&lt;p&gt;IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process&amp;#39;s privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48962</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2063 — Red Hat Enterprise Linux (perl-IO-Compress): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rec…</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2063</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2063</guid>
    </item>
  </channel>
</rss>
