<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:17:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-376429</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-376429</link>
      <description>EUVD-2026-376429</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-376429</guid>
    </item>
    <item>
      <title>fkie_cve-2026-84713</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84713</link>
      <description>&lt;p&gt;A flaw was found in the automation-controller notification
                  subsystem. Although NotificationTemplate.notification_
                  configuration is protected from API filtering, its recipient
                  value is copied in clear text into the unprotected
                  Notification.recipients field on every send. Because the
                  credential-types endpoint is listable by any authenticated
                  user and the API filter backend traverses object relations
                  without per-hop authorization, a user with no privileges can
                  use a relational filter as a boolean count-oracle to recover,
                  character by character and across organizations, the secret
                  recipient values of other tenants&amp;#39; notifications — including
                  PagerDuty service keys and Slack/Mattermost/RocketChat/Webhook
                  bearer-token URLs. This flaw affects confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the automation-controller notification
                  subsystem. Although NotificationTemplate.notification_
                  configuration is protected from API filtering, its recipient
                  value is copied in clear text into the unprotected
                  Notification.recipients field on every send. Because the
                  credential-types endpoint is listable by any authenticated
                  user and the API filter backend traverses object relations
                  without per-hop authorization, a user with no privileges can
                  use a relational filter as a boolean count-oracle to recover,
                  character by character and across organizations, the secret
                  recipient values of other tenants&amp;#39; notifications — including
                  PagerDuty service keys and Slack/Mattermost/RocketChat/Webhook
                  bearer-token URLs. This flaw affects confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-84713</guid>
    </item>
    <item>
      <title>GHSA-mfxr-44mv-44q4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mfxr-44mv-44q4</link>
      <description>&lt;p&gt;A flaw was found in the automation-controller notification
                  subsystem. Although NotificationTemplate.notification_
                  configuration is protected from API filtering, its recipient
                  value is copied in clear text into the unprotected
                  Notification.recipients field on every send. Because the
                  credential-types endpoint is listable by any authenticated
                  user and the API filter backend traverses object relations
                  without per-hop authorization, a user with no privileges can
                  use a relational filter as a boolean count-oracle to recover,
                  character by character and across organizations, the secret
                  recipient values of other tenants&amp;#39; notifications — including
                  PagerDuty service keys and Slack/Mattermost/RocketChat/Webhook
                  bearer-token URLs. This flaw affects confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the automation-controller notification
                  subsystem. Although NotificationTemplate.notification_
                  configuration is protected from API filtering, its recipient
                  value is copied in clear text into the unprotected
                  Notification.recipients field on every send. Because the
                  credential-types endpoint is listable by any authenticated
                  user and the API filter backend traverses object relations
                  without per-hop authorization, a user with no privileges can
                  use a relational filter as a boolean count-oracle to recover,
                  character by character and across organizations, the secret
                  recipient values of other tenants&amp;#39; notifications — including
                  PagerDuty service keys and Slack/Mattermost/RocketChat/Webhook
                  bearer-token URLs. This flaw affects confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mfxr-44mv-44q4</guid>
    </item>
    <item>
      <title>RHSA-2026:71177 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:71177</link>
      <description>&lt;p&gt;ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing sqlparse: sqlparse: Denial of Service via inefficient SQL parsing automation-controller: automation-controller-container: automation-controller: Named-URL 404 body oracle enables cross-tenant resource name enumeration automation-controller: automation-controller-container: automation-controller: JobJobEventsChildrenSummary               RBAC bypass exposes cross-tenant job event tree structure automation-controller: automation-controller-container: automation-controller: Any authenticated user reads Red Hat subscription/license details via /config/ automation-controller: automation-controller-container: automation-controller: Verbose internal exception               disclosure via HostList bare-Exception handler automation-controller: automation-controller-container: automation-controller: CUSTOM_VENV_PATH setting provides filesystem path-existence oracle on co…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing sqlparse: sqlparse: Denial of Service via inefficient SQL parsing automation-controller: automation-controller-container: automation-controller: Named-URL 404 body oracle enables cross-tenant resource name enumeration automation-controller: automation-controller-container: automation-controller: JobJobEventsChildrenSummary               RBAC bypass exposes cross-tenant job event tree structure automation-controller: automation-controller-container: automation-controller: Any authenticated user reads Red Hat subscription/license details via /config/ automation-controller: automation-controller-container: automation-controller: Verbose internal exception               disclosure via HostList bare-Exception handler automation-controller: automation-controller-container: automation-controller: CUSTOM_VENV_PATH setting provides filesystem path-existence oracle on co…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:71177</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3555 — Red Hat Ansible Automation Platform (automation-controller): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</guid>
    </item>
  </channel>
</rss>
