<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:26:45 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0986 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0986</link>
      <description>certfr-2026-avi-0986</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0986</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AQ98798 — Security fixes for CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-33811, CVE-2026-33814, CVE-2026-39817, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aq98798</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tigera-operator&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the tigera-operator package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tigera-operator&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the tigera-operator package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aq98798</guid>
    </item>
    <item>
      <title>EUVD-2026-339084</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339084</link>
      <description>EUVD-2026-339084</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339084</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48978</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48978</link>
      <description>&lt;p&gt;oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry&amp;#39;s WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry&amp;#39;s WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48978</guid>
    </item>
    <item>
      <title>GHSA-xf85-363p-868w — oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xf85-363p-868w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: oras.land/oras-go/v2, Go: oras.land/oras-go&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;oras-go&amp;#39;s `auth.Client` follows the `realm` URL from a registry&amp;#39;s `WWW-Authenticate: Bearer` challenge without validating its scheme or host. The `realm` field is server-controlled by design in the OCI/distribution spec — registries legitimately point token requests at a separate auth endpoint (e.g. Docker Hub&amp;#39;s `registry-1.docker.io` -&amp;gt; `auth.docker.io`), so cross-host realms on public DNS names are not in themselves a vulnerability. Two specific patterns, however, are never legitimate under any registry trust model and can be abused by a malicious or compromised registry (or a man-in-the-middle on a plaintext connection):&lt;/p&gt;
&lt;p&gt;1. **SSRF to internal networks.** A realm of `http://169.254.169.254/...` (AWS/Azure IMDS), `http://10.0.0.x/...` (RFC 1918), or `http://127.0.0.1/...` causes oras-go running on a cloud VM or corporate workstation to issue outbound HTTP requests from inside the user&amp;#39;s trust boundary to an endpoint the user did not choose. The user&amp;#39;s stored credentials are attached to those requests, but the principal harm is the network primitive — probing internal endpoints from the client. On IMDSv1 the response body is recoverable from log channels; on IMDSv2 the probe itself can still be used for service discovery.&lt;/p&gt;
&lt;p&gt;2. **TLS downgrade.** A registry contacted over `https://` can return a realm with an `http://` scheme, causing oras-go to send the user&amp;#39;s credentials over plaintext to the token endpoint. This defeats the transport security the user chose whe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: oras.land/oras-go/v2, Go: oras.land/oras-go&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;oras-go&amp;#39;s `auth.Client` follows the `realm` URL from a registry&amp;#39;s `WWW-Authenticate: Bearer` challenge without validating its scheme or host. The `realm` field is server-controlled by design in the OCI/distribution spec — registries legitimately point token requests at a separate auth endpoint (e.g. Docker Hub&amp;#39;s `registry-1.docker.io` -&amp;gt; `auth.docker.io`), so cross-host realms on public DNS names are not in themselves a vulnerability. Two specific patterns, however, are never legitimate under any registry trust model and can be abused by a malicious or compromised registry (or a man-in-the-middle on a plaintext connection):&lt;/p&gt;
&lt;p&gt;1. **SSRF to internal networks.** A realm of `http://169.254.169.254/...` (AWS/Azure IMDS), `http://10.0.0.x/...` (RFC 1918), or `http://127.0.0.1/...` causes oras-go running on a cloud VM or corporate workstation to issue outbound HTTP requests from inside the user&amp;#39;s trust boundary to an endpoint the user did not choose. The user&amp;#39;s stored credentials are attached to those requests, but the principal harm is the network primitive — probing internal endpoints from the client. On IMDSv1 the response body is recoverable from log channels; on IMDSv2 the probe itself can still be used for service discovery.&lt;/p&gt;
&lt;p&gt;2. **TLS downgrade.** A registry contacted over `https://` can return a realm with an `http://` scheme, causing oras-go to send the user&amp;#39;s credentials over plaintext to the token endpoint. This defeats the transport security the user chose whe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xf85-363p-868w</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11186-1 — helm-4.2.2-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11186-1</link>
      <description>&lt;p&gt;helm-4.2.2-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;helm-4.2.2-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11186-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22603-1 — Security update for helm</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22603-1</link>
      <description>&lt;p&gt;Security update for helm&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for helm&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22603-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48978</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48978</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-oras-oras-go, Ubuntu:26.04:LTS: golang-oras-oras-go&lt;/p&gt;
&lt;p&gt;oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry&amp;#39;s WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-oras-oras-go, Ubuntu:26.04:LTS: golang-oras-oras-go&lt;/p&gt;
&lt;p&gt;oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry&amp;#39;s WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48978</guid>
    </item>
  </channel>
</rss>
