<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:29:10 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-92842</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-92842</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: php83, Alpaquita:stream: php83&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: php83, Alpaquita:stream: php83&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-92842</guid>
    </item>
    <item>
      <title>BIT-libphp-2026-92842 — OOB read / info leak in convert.* stream filters when line-break-chars contains NUL</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libphp-2026-92842</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libphp&lt;/p&gt;
&lt;p&gt;The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libphp&lt;/p&gt;
&lt;p&gt;The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libphp-2026-92842</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1227 — De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1227</link>
      <description>certfr-2026-avi-1227</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1227</guid>
    </item>
    <item>
      <title>EUVD-2026-377576</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-377576</link>
      <description>EUVD-2026-377576</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-377576</guid>
    </item>
    <item>
      <title>fkie_cve-2026-92842</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92842</link>
      <description>&lt;p&gt;The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-92842</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-92842 — OOB read / info leak in convert.* stream filters when line-break-chars contains NUL</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-92842</link>
      <description>msrc_CVE-2026-92842</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-92842</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11901-1 — php8-8.5.11-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11901-1</link>
      <description>&lt;p&gt;php8-8.5.11-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php8-8.5.11-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11901-1</guid>
    </item>
    <item>
      <title>RHSA-2026:70720 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:70720</link>
      <description>&lt;p&gt;php: php: Denial of Service via out-of-bounds read in mysqlnd wire protocol parser php: PHP: Denial of Service via heap buffer overflow in SOAP client php: PHP: Archive entry injection via integer overflow in TAR parser php: PHP: Denial of Service via reserved device names on Windows php: php: Denial of Service via unbounded recursion in SOAP parser php: php: Credential disclosure via cross-origin HTTP redirects php: php: Information disclosure via crafted TLS server certificate php: php: Access control bypass via partial IPv6 address comparison php: php: Server impersonation via Common Name fallback in TLS verification php: php: Information disclosure via out-of-bounds read in stream filters php: php: Out-of-bounds read via empty HTTP redirect Location header&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;php: php: Denial of Service via out-of-bounds read in mysqlnd wire protocol parser php: PHP: Denial of Service via heap buffer overflow in SOAP client php: PHP: Archive entry injection via integer overflow in TAR parser php: PHP: Denial of Service via reserved device names on Windows php: php: Denial of Service via unbounded recursion in SOAP parser php: php: Credential disclosure via cross-origin HTTP redirects php: php: Information disclosure via crafted TLS server certificate php: php: Access control bypass via partial IPv6 address comparison php: php: Server impersonation via Common Name fallback in TLS verification php: php: Information disclosure via out-of-bounds read in stream filters php: php: Out-of-bounds read via empty HTTP redirect Location header&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:70720</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-92842</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-92842</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: php5, Ubuntu:Pro:16.04:LTS: php7.0, Ubuntu:Pro:18.04:LTS: php7.2, Ubuntu:Pro:20.04:LTS: php7.4, Ubuntu:22.04:LTS: php8.1, Ubuntu:24.04:LTS: php8.3, Ubuntu:26.04:LTS: php8.5&lt;/p&gt;
&lt;p&gt;The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: php5, Ubuntu:Pro:16.04:LTS: php7.0, Ubuntu:Pro:18.04:LTS: php7.2, Ubuntu:Pro:20.04:LTS: php7.4, Ubuntu:22.04:LTS: php8.1, Ubuntu:24.04:LTS: php8.3, Ubuntu:26.04:LTS: php8.5&lt;/p&gt;
&lt;p&gt;The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate the value with pestrdup(), which stops at the first NUL byte, while keeping the original length. When the filter later emits a line break it copies the recorded length out of the truncated allocation, reading past its end and placing adjacent heap bytes into the filter output.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-92842</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3585 — PHP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3585</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in PHP ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen oder die Integrität zu verletzen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in PHP ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen oder die Integrität zu verletzen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3585</guid>
    </item>
  </channel>
</rss>
