<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:15:21 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:67148 — Important: osbuild-composer security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:67148</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: osbuild-composer, AlmaLinux:8: osbuild-composer-core, AlmaLinux:8: osbuild-composer-worker&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)
  * crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
  * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
  * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
  * github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)
  * github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: osbuild-composer, AlmaLinux:8: osbuild-composer-core, AlmaLinux:8: osbuild-composer-worker&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)
  * crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)
  * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
  * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
  * github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)
  * github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:67148</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BR58082 — Echo is a Go web framework</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-br58082</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kube-metrics-adapter&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the kube-metrics-adapter package. Echo is a Go web framework. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kube-metrics-adapter&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the kube-metrics-adapter package. Echo is a Go web framework. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-br58082</guid>
    </item>
    <item>
      <title>EUVD-2026-330680</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330680</link>
      <description>EUVD-2026-330680</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330680</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55677</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55677</link>
      <description>&lt;p&gt;Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo&amp;#39;s router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo&amp;#39;s router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55677</guid>
    </item>
    <item>
      <title>GHSA-vfp3-v2gw-7wfq — Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vfp3-v2gw-7wfq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/labstack/echo/v5, Go: github.com/labstack/echo/v4, Go: github.com/labstack/echo&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Echo&amp;#39;s router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving `%2F` as-is), while `StaticDirectoryHandler` unescapes `%2F` to `/` before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Root cause 1 — `router.go` lines 798-802:**
The router uses `req.URL.RawPath` for route matching when `useEscapedPathForRouting` is false (the default). This means `/admin%2Fsecret.txt` is treated as a single path segment and does NOT match the `/admin/*` route pattern.&lt;/p&gt;
&lt;p&gt;```go
if !r.useEscapedPathForRouting &amp;amp;&amp;amp; req.URL.RawPath != &amp;#34;&amp;#34; {
    path = req.URL.RawPath
}
```&lt;/p&gt;
&lt;p&gt;**Root cause 2 — `echo.go` lines 559-568:**
`StaticDirectoryHandler` calls `url.PathUnescape()` on the path parameter before opening files. This converts `%2F` back to `/`, resolving `admin/secret.txt` on disk.&lt;/p&gt;
&lt;p&gt;```go
if !disablePathUnescaping {
    tmpPath, err := url.PathUnescape(p)
    p = tmpPath
}
name := filepath.ToSlash(filepath.Clean(strings.TrimPrefix(p, &amp;#34;/&amp;#34;)))
```&lt;/p&gt;
&lt;p&gt;### PoC (Screenshot)
Sample:
&amp;lt;img width=&amp;#34;1291&amp;#34; height=&amp;#34;970&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/0bc58059-3e6d-4678-ab25-a5c79b006738&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;403:
&amp;lt;img width=&amp;#34;526&amp;#34; height=&amp;#34;194&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/2f55ffdd-87b2-4a1b-8a13-130ebad0f257&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Bypass with encoded slash:
&amp;lt;img width=&amp;#34;592&amp;#34; height=&amp;#34;203&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/labstack/echo/v5, Go: github.com/labstack/echo/v4, Go: github.com/labstack/echo&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Echo&amp;#39;s router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving `%2F` as-is), while `StaticDirectoryHandler` unescapes `%2F` to `/` before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Root cause 1 — `router.go` lines 798-802:**
The router uses `req.URL.RawPath` for route matching when `useEscapedPathForRouting` is false (the default). This means `/admin%2Fsecret.txt` is treated as a single path segment and does NOT match the `/admin/*` route pattern.&lt;/p&gt;
&lt;p&gt;```go
if !r.useEscapedPathForRouting &amp;amp;&amp;amp; req.URL.RawPath != &amp;#34;&amp;#34; {
    path = req.URL.RawPath
}
```&lt;/p&gt;
&lt;p&gt;**Root cause 2 — `echo.go` lines 559-568:**
`StaticDirectoryHandler` calls `url.PathUnescape()` on the path parameter before opening files. This converts `%2F` back to `/`, resolving `admin/secret.txt` on disk.&lt;/p&gt;
&lt;p&gt;```go
if !disablePathUnescaping {
    tmpPath, err := url.PathUnescape(p)
    p = tmpPath
}
name := filepath.ToSlash(filepath.Clean(strings.TrimPrefix(p, &amp;#34;/&amp;#34;)))
```&lt;/p&gt;
&lt;p&gt;### PoC (Screenshot)
Sample:
&amp;lt;img width=&amp;#34;1291&amp;#34; height=&amp;#34;970&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/0bc58059-3e6d-4678-ab25-a5c79b006738&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;403:
&amp;lt;img width=&amp;#34;526&amp;#34; height=&amp;#34;194&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/2f55ffdd-87b2-4a1b-8a13-130ebad0f257&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Bypass with encoded slash:
&amp;lt;img width=&amp;#34;592&amp;#34; height=&amp;#34;203&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vfp3-v2gw-7wfq</guid>
    </item>
    <item>
      <title>RHSA-2026:44622 — Red Hat Security Advisory: Multicluster Global Hub 1.6.4 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:44622</link>
      <description>&lt;p&gt;golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default grafana: Grafana: Privilege escalation via dashboard overwrite net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: Integer Overflow in Avro Decoder github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin github.com/containerd/containerd: containerd: Security bypass via Contain…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default grafana: Grafana: Privilege escalation via dashboard overwrite net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: Integer Overflow in Avro Decoder github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin github.com/containerd/containerd: containerd: Security bypass via Contain…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:44622</guid>
    </item>
    <item>
      <title>RHSA-2026:57541 — Red Hat Security Advisory: osbuild-composer security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:57541</link>
      <description>&lt;p&gt;golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:57541</guid>
    </item>
    <item>
      <title>RLSA-2026:66432 — Important: osbuild-composer security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:66432</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502)&lt;/p&gt;
&lt;p&gt;* github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)&lt;/p&gt;
&lt;p&gt;* github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: osbuild-composer&lt;/p&gt;
&lt;p&gt;A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud.  It is compatible with composer-cli and cockpit-composer clients.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)&lt;/p&gt;
&lt;p&gt;* golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502)&lt;/p&gt;
&lt;p&gt;* github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)&lt;/p&gt;
&lt;p&gt;* github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:66432</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-55677</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55677</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: golang-github-labstack-echo.v2, Ubuntu:20.04:LTS: golang-github-labstack-echo.v3, Ubuntu:22.04:LTS: golang-github-labstack-echo, Ubuntu:22.04:LTS: golang-github-labstack-echo.v2, Ubuntu:22.04:LTS: golang-github-labstack-echo.v3, Ubuntu:24.04:LTS: golang-github-labstack-echo, Ubuntu:25.10: golang-github-labstack-echo, Ubuntu:26.04:LTS: golang-github-labstack-echo&lt;/p&gt;
&lt;p&gt;Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo&amp;#39;s router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: golang-github-labstack-echo.v2, Ubuntu:20.04:LTS: golang-github-labstack-echo.v3, Ubuntu:22.04:LTS: golang-github-labstack-echo, Ubuntu:22.04:LTS: golang-github-labstack-echo.v2, Ubuntu:22.04:LTS: golang-github-labstack-echo.v3, Ubuntu:24.04:LTS: golang-github-labstack-echo, Ubuntu:25.10: golang-github-labstack-echo, Ubuntu:26.04:LTS: golang-github-labstack-echo&lt;/p&gt;
&lt;p&gt;Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo&amp;#39;s router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55677</guid>
    </item>
  </channel>
</rss>
