<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:17:50 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-1169 — De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1169</link>
      <description>certfr-2026-avi-1169</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1169</guid>
    </item>
    <item>
      <title>EUVD-2026-366595</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366595</link>
      <description>EUVD-2026-366595</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366595</guid>
    </item>
    <item>
      <title>fkie_cve-2026-88031</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-88031</link>
      <description>&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-88031</guid>
    </item>
    <item>
      <title>GHSA-gf3f-xg7m-h8wp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gf3f-xg7m-h8wp</link>
      <description>&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gf3f-xg7m-h8wp</guid>
    </item>
    <item>
      <title>RHSA-2026:72849 — Red Hat Security Advisory: multicluster engine for Kubernetes v2.17.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:72849</link>
      <description>&lt;p&gt;github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input etcd: etcd: Denial of Service via unbounded TLS handshake goroutines fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests go.mongodb.org/mongo-driver: go.mongodb.org/mongo-driver/v2: MongoDB Go Driver: Data deletion via query-operator injection in GridFS file IDs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input etcd: etcd: Denial of Service via unbounded TLS handshake goroutines fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding fast-uri: fast-uri: Host confusion via skipped IDN canonicalization fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests go.mongodb.org/mongo-driver: go.mongodb.org/mongo-driver/v2: MongoDB Go Driver: Data deletion via query-operator injection in GridFS file IDs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:72849</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-88031</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-88031</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-mongodb-mongo-driver, Ubuntu:26.04:LTS: golang-mongodb-mongo-driver&lt;/p&gt;
&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-mongodb-mongo-driver, Ubuntu:26.04:LTS: golang-mongodb-mongo-driver&lt;/p&gt;
&lt;p&gt;Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-88031</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3320 — MongoDB: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3320</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Abfrage- und Zugriffsbeschränkungen zu umgehen, nicht vorgesehene Datensätze oder Dateien auszulesen, zu verändern oder zu löschen sowie unter bestimmten Voraussetzungen MongoDB-Server oder Anwendungen zum Absturz zu bringen und dadurch einen Denial-of-Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in MongoDB ausnutzen, um Abfrage- und Zugriffsbeschränkungen zu umgehen, nicht vorgesehene Datensätze oder Dateien auszulesen, zu verändern oder zu löschen sowie unter bestimmten Voraussetzungen MongoDB-Server oder Anwendungen zum Absturz zu bringen und dadurch einen Denial-of-Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3320</guid>
    </item>
  </channel>
</rss>
