<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:50:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-364426</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364426</link>
      <description>EUVD-2026-364426</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364426</guid>
    </item>
    <item>
      <title>fkie_cve-2026-9165</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9165</link>
      <description>&lt;p&gt;A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-9165</guid>
    </item>
    <item>
      <title>GHSA-fw53-q2vg-jr6g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fw53-q2vg-jr6g</link>
      <description>&lt;p&gt;A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fw53-q2vg-jr6g</guid>
    </item>
    <item>
      <title>RHSA-2026:36207 — Red Hat Security Advisory: RHACS 4.11.1 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:36207</link>
      <description>&lt;p&gt;stackrox: stackrox: Unbounded GraphQL query depth allows authenticated denial of service golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate axios: Axios: Prototype pollution allows information disclosure and request manipulation golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;stackrox: stackrox: Unbounded GraphQL query depth allows authenticated denial of service golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate axios: Axios: Prototype pollution allows information disclosure and request manipulation golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:36207</guid>
    </item>
  </channel>
</rss>
