<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:20:59 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1169 — De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1169</link>
      <description>certfr-2026-avi-1169</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1169</guid>
    </item>
    <item>
      <title>EUVD-2026-366594</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366594</link>
      <description>EUVD-2026-366594</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366594</guid>
    </item>
    <item>
      <title>fkie_cve-2026-88030</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-88030</link>
      <description>&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-88030</guid>
    </item>
    <item>
      <title>GHSA-4ww7-gqv6-mffc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4ww7-gqv6-mffc</link>
      <description>&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4ww7-gqv6-mffc</guid>
    </item>
    <item>
      <title>RHSA-2026:73519 — Red Hat Security Advisory: ruby:2.5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:73519</link>
      <description>&lt;p&gt;resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses rubygem-mongo: MongoDB Ruby Driver: Data disclosure and denial of service via query-operator injection&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses rubygem-mongo: MongoDB Ruby Driver: Data disclosure and denial of service via query-operator injection&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:73519</guid>
    </item>
    <item>
      <title>RLSA-2026:73519 — Important: ruby:2.5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:73519</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: rubygem-abrt, Rocky Linux:8: rubygem-bson, Rocky Linux:8: rubygem-bundler, Rocky Linux:8: rubygem-mysql2, Rocky Linux:8: rubygem-pg, Rocky Linux:8: ruby, Rocky Linux:8: rubygem-mongo&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses (CVE-2026-80212)&lt;/p&gt;
&lt;p&gt;* rubygem-mongo: MongoDB Ruby Driver: Data disclosure and denial of service via query-operator injection (CVE-2026-88030)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: rubygem-abrt, Rocky Linux:8: rubygem-bson, Rocky Linux:8: rubygem-bundler, Rocky Linux:8: rubygem-mysql2, Rocky Linux:8: rubygem-pg, Rocky Linux:8: ruby, Rocky Linux:8: rubygem-mongo&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses (CVE-2026-80212)&lt;/p&gt;
&lt;p&gt;* rubygem-mongo: MongoDB Ruby Driver: Data disclosure and denial of service via query-operator injection (CVE-2026-88030)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:73519</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-88030</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-88030</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-mongo, Ubuntu:18.04:LTS: ruby-mongo, Ubuntu:20.04:LTS: ruby-mongo, Ubuntu:22.04:LTS: ruby-mongo, Ubuntu:24.04:LTS: ruby-mongo, Ubuntu:26.04:LTS: ruby-mongo&lt;/p&gt;
&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: ruby-mongo, Ubuntu:18.04:LTS: ruby-mongo, Ubuntu:20.04:LTS: ruby-mongo, Ubuntu:22.04:LTS: ruby-mongo, Ubuntu:24.04:LTS: ruby-mongo, Ubuntu:26.04:LTS: ruby-mongo&lt;/p&gt;
&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-88030</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3320 — MongoDB: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3320</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Abfrage- und Zugriffsbeschränkungen zu umgehen, nicht vorgesehene Datensätze oder Dateien auszulesen, zu verändern oder zu löschen sowie unter bestimmten Voraussetzungen MongoDB-Server oder Anwendungen zum Absturz zu bringen und dadurch einen Denial-of-Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Abfrage- und Zugriffsbeschränkungen zu umgehen, nicht vorgesehene Datensätze oder Dateien auszulesen, zu verändern oder zu löschen sowie unter bestimmten Voraussetzungen MongoDB-Server oder Anwendungen zum Absturz zu bringen und dadurch einen Denial-of-Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3320</guid>
    </item>
  </channel>
</rss>
