<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:26:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-375236</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-375236</link>
      <description>EUVD-2026-375236</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-375236</guid>
    </item>
    <item>
      <title>fkie_cve-2026-84716</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-84716</link>
      <description>&lt;p&gt;A flaw was found in the automation-controller instance
                  install-bundle endpoint. When a System Administrator downloads
                  an execution/hop node&amp;#39;s install bundle, the controller signs an
                  X.509 certificate with the receptor mesh certificate authority
                  in which the Common Name, DNS subject-alternative-name, and
                  receptor node-id are taken verbatim from the caller-chosen
                  instance hostname, with a hard-coded ten-year validity, a random
                  serial, and no issuance log or revocation list. Because the
                  hostname charset validator is case-insensitive while the
                  uniqueness validator is case-sensitive, an administrator can
                  register a case variant of an existing control node&amp;#39;s hostname
                  and obtain a mesh-CA-signed certificate that TLS peers, which
                  match hostnames case-insensitively, accept as that control node.
                  In managed/hosted deployments — where the customer holds
                  controller superuser but the platform operator runs the mesh —
                  this yields a long-lived, non-revocable mesh peer credential and,
                  with an on-path position, TLS impersonation or interception of
                  control/hybrid mesh nodes. It does not grant direct remote code
                  execution, because receptor work submission is gated by a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the automation-controller instance
                  install-bundle endpoint. When a System Administrator downloads
                  an execution/hop node&amp;#39;s install bundle, the controller signs an
                  X.509 certificate with the receptor mesh certificate authority
                  in which the Common Name, DNS subject-alternative-name, and
                  receptor node-id are taken verbatim from the caller-chosen
                  instance hostname, with a hard-coded ten-year validity, a random
                  serial, and no issuance log or revocation list. Because the
                  hostname charset validator is case-insensitive while the
                  uniqueness validator is case-sensitive, an administrator can
                  register a case variant of an existing control node&amp;#39;s hostname
                  and obtain a mesh-CA-signed certificate that TLS peers, which
                  match hostnames case-insensitively, accept as that control node.
                  In managed/hosted deployments — where the customer holds
                  controller superuser but the platform operator runs the mesh —
                  this yields a long-lived, non-revocable mesh peer credential and,
                  with an on-path position, TLS impersonation or interception of
                  control/hybrid mesh nodes. It does not grant direct remote code
                  execution, because receptor work submission is gated by a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-84716</guid>
    </item>
    <item>
      <title>GHSA-hcpg-prc4-w26w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hcpg-prc4-w26w</link>
      <description>&lt;p&gt;A flaw was found in the automation-controller instance
                  install-bundle endpoint. When a System Administrator downloads
                  an execution/hop node&amp;#39;s install bundle, the controller signs an
                  X.509 certificate with the receptor mesh certificate authority
                  in which the Common Name, DNS subject-alternative-name, and
                  receptor node-id are taken verbatim from the caller-chosen
                  instance hostname, with a hard-coded ten-year validity, a random
                  serial, and no issuance log or revocation list. Because the
                  hostname charset validator is case-insensitive while the
                  uniqueness validator is case-sensitive, an administrator can
                  register a case variant of an existing control node&amp;#39;s hostname
                  and obtain a mesh-CA-signed certificate that TLS peers, which
                  match hostnames case-insensitively, accept as that control node.
                  In managed/hosted deployments — where the customer holds
                  controller superuser but the platform operator runs the mesh —
                  this yields a long-lived, non-revocable mesh peer credential and,
                  with an on-path position, TLS impersonation or interception of
                  control/hybrid mesh nodes. It does not grant direct remote code
                  execution, because receptor work submission is gated by a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the automation-controller instance
                  install-bundle endpoint. When a System Administrator downloads
                  an execution/hop node&amp;#39;s install bundle, the controller signs an
                  X.509 certificate with the receptor mesh certificate authority
                  in which the Common Name, DNS subject-alternative-name, and
                  receptor node-id are taken verbatim from the caller-chosen
                  instance hostname, with a hard-coded ten-year validity, a random
                  serial, and no issuance log or revocation list. Because the
                  hostname charset validator is case-insensitive while the
                  uniqueness validator is case-sensitive, an administrator can
                  register a case variant of an existing control node&amp;#39;s hostname
                  and obtain a mesh-CA-signed certificate that TLS peers, which
                  match hostnames case-insensitively, accept as that control node.
                  In managed/hosted deployments — where the customer holds
                  controller superuser but the platform operator runs the mesh —
                  this yields a long-lived, non-revocable mesh peer credential and,
                  with an on-path position, TLS impersonation or interception of
                  control/hybrid mesh nodes. It does not grant direct remote code
                  execution, because receptor work submission is gated by a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hcpg-prc4-w26w</guid>
    </item>
    <item>
      <title>RHSA-2026:71113 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:71113</link>
      <description>&lt;p&gt;Automation-Controller: automation-controller: Kubernetes service account token exfiltration via HashiCorp Vault credential SSRF encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages js-yaml: js-yaml: Denial of Service via crafted YAML documents sqlparse: sqlparse: Denial of Service via inefficient SQL parsing nanoid: nanoid: Denial of Service via negative size input in non-secure module functions gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options gitpython: GitPython: Command Injection via Git option prefix abbreviation postcss: PostCSS: Information disclosure via crafted sourceMappingURL automation-controller: automation-controller-container: automation-controller: Named-URL 404 body oracle enable…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Automation-Controller: automation-controller: Kubernetes service account token exfiltration via HashiCorp Vault credential SSRF encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service html/template: golang: Go html/template: Cross-Site Scripting via pathological input encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages js-yaml: js-yaml: Denial of Service via crafted YAML documents sqlparse: sqlparse: Denial of Service via inefficient SQL parsing nanoid: nanoid: Denial of Service via negative size input in non-secure module functions gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options gitpython: GitPython: Command Injection via Git option prefix abbreviation postcss: PostCSS: Information disclosure via crafted sourceMappingURL automation-controller: automation-controller-container: automation-controller: Named-URL 404 body oracle enable…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:71113</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3555 — Red Hat Ansible Automation Platform (automation-controller): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</guid>
    </item>
  </channel>
</rss>
