<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:24:33 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-24557 — Moby classic builder cache poisoning</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-24557</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; moby&lt;/p&gt;
&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being HEALTHCHECK and ONBUILD) would not cause a cache miss. An attacker with the knowledge of the Dockerfile someone is using could poison their cache by making them pull a specially crafted image that would be considered as a valid cache candidate for some build steps. 23.0+ users are only affected if they explicitly opted out of Buildkit (DOCKER_BUILDKIT=0 environment variable) or are using the /build API endpoint. All users on versions older than 23.0 could be impacted. Image build API endpoint (/build) and ImageBuild function from github.com/docker/docker/client is also affected as it the uses classic builder by default. Patches are included in 24.0.9 and 25.0.2 releases.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; moby&lt;/p&gt;
&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being HEALTHCHECK and ONBUILD) would not cause a cache miss. An attacker with the knowledge of the Dockerfile someone is using could poison their cache by making them pull a specially crafted image that would be considered as a valid cache candidate for some build steps. 23.0+ users are only affected if they explicitly opted out of Buildkit (DOCKER_BUILDKIT=0 environment variable) or are using the /build API endpoint. All users on versions older than 23.0 could be impacted. Image build API endpoint (/build) and ImageBuild function from github.com/docker/docker/client is also affected as it the uses classic builder by default. Patches are included in 24.0.9 and 25.0.2 releases.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-24557</guid>
    </item>
    <item>
      <title>GHSA-gcjh-h69q-9w9g — cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gcjh-h69q-9w9g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/google/cel-go&lt;/p&gt;
&lt;p&gt;The function `ext.NativeTypes(ParseStructTag(&amp;#34;json&amp;#34;))` does not honour the `encoding/json` skip directive `json:&amp;#34;-&amp;#34;`. Fields tagged `json:&amp;#34;-&amp;#34;` are registered in the CEL type system under the literal name `&amp;#34;-&amp;#34;` and are readable from any user-submitted CEL expression via `dyn(obj)[&amp;#34;-&amp;#34;]`.&lt;/p&gt;
&lt;p&gt;Additionally, `newNativeTypes` silently registers every nested struct reachable from the type passed to `NativeTypes`, including types from third-party dependencies the developer never examined.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;In `fieldNameByTag`, the helper used by `ParseStructTag(&amp;#34;json&amp;#34;)` to translate Go struct tags into CEL field names.&lt;/p&gt;
&lt;p&gt;See at `ext/native.go:146`:&lt;/p&gt;
&lt;p&gt;```go
func fieldNameByTag(structTagToParse string) func(field reflect.StructField) string {
    return func(field reflect.StructField) string {
        tag, found := field.Tag.Lookup(structTagToParse)
        if found {
            splits := strings.Split(tag, &amp;#34;,&amp;#34;)
            if len(splits) &amp;gt; 0 {
                // We make the assumption that the leftmost entry in the tag is the name.
                // This seems to be true for most tags that have the concept of a name/key, such as:
                // https://pkg.go.dev/encoding/xml#Marshal
                // https://pkg.go.dev/encoding/json#Marshal
                // https://pkg.go.dev/go.mongodb.org/mongo-driver/bson#hdr-Structs
                // https://pkg.go.dev/go.yaml.in/yaml/v3#Marshal
                name := splits[0]
                return name
            }
        }&lt;/p&gt;
&lt;p&gt;re…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/google/cel-go&lt;/p&gt;
&lt;p&gt;The function `ext.NativeTypes(ParseStructTag(&amp;#34;json&amp;#34;))` does not honour the `encoding/json` skip directive `json:&amp;#34;-&amp;#34;`. Fields tagged `json:&amp;#34;-&amp;#34;` are registered in the CEL type system under the literal name `&amp;#34;-&amp;#34;` and are readable from any user-submitted CEL expression via `dyn(obj)[&amp;#34;-&amp;#34;]`.&lt;/p&gt;
&lt;p&gt;Additionally, `newNativeTypes` silently registers every nested struct reachable from the type passed to `NativeTypes`, including types from third-party dependencies the developer never examined.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;In `fieldNameByTag`, the helper used by `ParseStructTag(&amp;#34;json&amp;#34;)` to translate Go struct tags into CEL field names.&lt;/p&gt;
&lt;p&gt;See at `ext/native.go:146`:&lt;/p&gt;
&lt;p&gt;```go
func fieldNameByTag(structTagToParse string) func(field reflect.StructField) string {
    return func(field reflect.StructField) string {
        tag, found := field.Tag.Lookup(structTagToParse)
        if found {
            splits := strings.Split(tag, &amp;#34;,&amp;#34;)
            if len(splits) &amp;gt; 0 {
                // We make the assumption that the leftmost entry in the tag is the name.
                // This seems to be true for most tags that have the concept of a name/key, such as:
                // https://pkg.go.dev/encoding/xml#Marshal
                // https://pkg.go.dev/encoding/json#Marshal
                // https://pkg.go.dev/go.mongodb.org/mongo-driver/bson#hdr-Structs
                // https://pkg.go.dev/go.yaml.in/yaml/v3#Marshal
                name := splits[0]
                return name
            }
        }&lt;/p&gt;
&lt;p&gt;re…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gcjh-h69q-9w9g</guid>
    </item>
  </channel>
</rss>
