<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:53:24 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0986 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0986</link>
      <description>certfr-2026-avi-0986</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0986</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AQ98798 — Security fixes for CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-33811, CVE-2026-33814, CVE-2026-39817, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aq98798</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tigera-operator&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the tigera-operator package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: tigera-operator&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the tigera-operator package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aq98798</guid>
    </item>
    <item>
      <title>EUVD-2026-338866</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338866</link>
      <description>EUVD-2026-338866</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338866</guid>
    </item>
    <item>
      <title>fkie_cve-2026-50151</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50151</link>
      <description>&lt;p&gt;oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller&amp;#39;s credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller&amp;#39;s credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-50151</guid>
    </item>
    <item>
      <title>GHSA-jxpm-75mh-9fp7 — oras-go blob upload vulnerable to credential forwarding via unvalidated Location header</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jxpm-75mh-9fp7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: oras.land/oras-go/v2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;oras-go follows a registry-controlled `Location` header during the monolithic blob upload flow and reuses the `Authorization` header from the initial `POST` request for the subsequent `PUT` request. If a malicious registry returns a cross-host `Location`, oras-go can send the caller&amp;#39;s credentials to an attacker-controlled endpoint.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;tested: v2.6.0 (commit 03243809936cce826494b5506f724c6dc11115b1, as-of 2026-01-24)
range: unknown; likely affects earlier v2.x releases that include the same upload flow&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Credential leak to an attacker-controlled endpoint and client-side ssrf to a cross-host target.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;- `registry/remote/repository.go:878-916` (`blobStore.completePushAfterInitialPost`)&lt;/p&gt;
&lt;p&gt;## Reproduction&lt;/p&gt;
&lt;p&gt;Attachments include `poc.zip` with a local-only harness (no real registry required). It runs a fake registry server that returns a cross-host `Location` and a second server that records whether it received `Authorization`.&lt;/p&gt;
&lt;p&gt;```bash
unzip -q -o poc.zip -d /tmp/poc
cd /tmp/poc/poc-F-ORAS-LOCATION-UPLOAD-001
make canonical
make control
```&lt;/p&gt;
&lt;p&gt;## Recommended Fix&lt;/p&gt;
&lt;p&gt;- validate `Location` before uploading (scheme + hostname + effective port) against the original request, or require an explicit opt-in allowlist for cross-host upload urls
- never forward `Authorization` when the upload target changes host or scheme&lt;/p&gt;
&lt;p&gt;## references&lt;/p&gt;
&lt;p&gt;- security policy: https://github.com/oras-project/oras-go/security/policy
- vulnerable code: `reg…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: oras.land/oras-go/v2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;oras-go follows a registry-controlled `Location` header during the monolithic blob upload flow and reuses the `Authorization` header from the initial `POST` request for the subsequent `PUT` request. If a malicious registry returns a cross-host `Location`, oras-go can send the caller&amp;#39;s credentials to an attacker-controlled endpoint.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;tested: v2.6.0 (commit 03243809936cce826494b5506f724c6dc11115b1, as-of 2026-01-24)
range: unknown; likely affects earlier v2.x releases that include the same upload flow&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Credential leak to an attacker-controlled endpoint and client-side ssrf to a cross-host target.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;- `registry/remote/repository.go:878-916` (`blobStore.completePushAfterInitialPost`)&lt;/p&gt;
&lt;p&gt;## Reproduction&lt;/p&gt;
&lt;p&gt;Attachments include `poc.zip` with a local-only harness (no real registry required). It runs a fake registry server that returns a cross-host `Location` and a second server that records whether it received `Authorization`.&lt;/p&gt;
&lt;p&gt;```bash
unzip -q -o poc.zip -d /tmp/poc
cd /tmp/poc/poc-F-ORAS-LOCATION-UPLOAD-001
make canonical
make control
```&lt;/p&gt;
&lt;p&gt;## Recommended Fix&lt;/p&gt;
&lt;p&gt;- validate `Location` before uploading (scheme + hostname + effective port) against the original request, or require an explicit opt-in allowlist for cross-host upload urls
- never forward `Authorization` when the upload target changes host or scheme&lt;/p&gt;
&lt;p&gt;## references&lt;/p&gt;
&lt;p&gt;- security policy: https://github.com/oras-project/oras-go/security/policy
- vulnerable code: `reg…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jxpm-75mh-9fp7</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11291-1 — helm-4.2.3-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11291-1</link>
      <description>&lt;p&gt;helm-4.2.3-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;helm-4.2.3-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11291-1</guid>
    </item>
    <item>
      <title>RHSA-2026:47737 — Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.13.10 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:47737</link>
      <description>&lt;p&gt;golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin js-yaml: js-yaml: Denial of Service via crafted YAML documents&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation sanitize-html: `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin js-yaml: js-yaml: Denial of Service via crafted YAML documents&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:47737</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23456-1 — Security update for helm</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23456-1</link>
      <description>&lt;p&gt;Security update for helm&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for helm&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23456-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-50151</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50151</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-oras-oras-go, Ubuntu:26.04:LTS: golang-oras-oras-go&lt;/p&gt;
&lt;p&gt;oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller&amp;#39;s credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-oras-oras-go, Ubuntu:26.04:LTS: golang-oras-oras-go&lt;/p&gt;
&lt;p&gt;oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller&amp;#39;s credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50151</guid>
    </item>
  </channel>
</rss>
