<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 03:52:20 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-61732 — Potential code smuggling via doc comments in cmd/cgo</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-61732</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go toolchain cmd/cgo, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions and 23 more&lt;/p&gt;
&lt;p&gt;A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go toolchain cmd/cgo, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions and 23 more&lt;/p&gt;
&lt;p&gt;A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-61732</guid>
    </item>
    <item>
      <title>GHSA-77fj-vx54-gvh7 — Go Markdown has an Out-of-bounds Read in SmartypantsRenderer</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-77fj-vx54-gvh7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gomarkdown/markdown&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Processing a malformed input containing a `&amp;lt;` character that is not followed by a `&amp;gt;` character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `smartLeftAngle()` function in `html/smartypants.go:367-376` performs an out-of-bounds slice operation when processing a `&amp;lt;` character that is not followed by a `&amp;gt;` character anywhere in the remaining text.
https://github.com/gomarkdown/markdown/blob/37c66b85d6ab025ba67a73ba03b7f3ef55859cca/html/smartypants.go#L367-L376
If the length of the slice is lower than its capacity, this leads to an extra byte of data read. If the length equals the capacity, this leads to a panic.&lt;/p&gt;
&lt;p&gt;### PoC
```golang
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;bytes&amp;#34;
	&amp;#34;fmt&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/gomarkdown/markdown/html&amp;#34;
)&lt;/p&gt;
&lt;p&gt;func main() {
	src := []byte(&amp;#34;&amp;lt;a&amp;#34;)&lt;/p&gt;
&lt;p&gt;fmt.Printf(&amp;#34;Input: %q  (len=%d, cap=%d)\n&amp;#34;, src, len(src), cap(src))&lt;/p&gt;
&lt;p&gt;var buf bytes.Buffer
	sp := html.NewSmartypantsRenderer(html.Smartypants)
	sp.Process(&amp;amp;buf, src) // panics: slice bounds out of range&lt;/p&gt;
&lt;p&gt;fmt.Printf(&amp;#34;Output: %q\n&amp;#34;, buf.String())
}
```&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability will lead to a Denial of Service / panic on the processing service.&lt;/p&gt;
&lt;p&gt;-- The Datadog Security Team&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gomarkdown/markdown&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Processing a malformed input containing a `&amp;lt;` character that is not followed by a `&amp;gt;` character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `smartLeftAngle()` function in `html/smartypants.go:367-376` performs an out-of-bounds slice operation when processing a `&amp;lt;` character that is not followed by a `&amp;gt;` character anywhere in the remaining text.
https://github.com/gomarkdown/markdown/blob/37c66b85d6ab025ba67a73ba03b7f3ef55859cca/html/smartypants.go#L367-L376
If the length of the slice is lower than its capacity, this leads to an extra byte of data read. If the length equals the capacity, this leads to a panic.&lt;/p&gt;
&lt;p&gt;### PoC
```golang
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;bytes&amp;#34;
	&amp;#34;fmt&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/gomarkdown/markdown/html&amp;#34;
)&lt;/p&gt;
&lt;p&gt;func main() {
	src := []byte(&amp;#34;&amp;lt;a&amp;#34;)&lt;/p&gt;
&lt;p&gt;fmt.Printf(&amp;#34;Input: %q  (len=%d, cap=%d)\n&amp;#34;, src, len(src), cap(src))&lt;/p&gt;
&lt;p&gt;var buf bytes.Buffer
	sp := html.NewSmartypantsRenderer(html.Smartypants)
	sp.Process(&amp;amp;buf, src) // panics: slice bounds out of range&lt;/p&gt;
&lt;p&gt;fmt.Printf(&amp;#34;Output: %q\n&amp;#34;, buf.String())
}
```&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability will lead to a Denial of Service / panic on the processing service.&lt;/p&gt;
&lt;p&gt;-- The Datadog Security Team&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-77fj-vx54-gvh7</guid>
    </item>
  </channel>
</rss>
