<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 09:45:13 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-47912 — Insufficient validation of bracketed IPv6 hostnames in net/url</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-47912</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go standard library net/url&lt;/p&gt;
&lt;p&gt;The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: &amp;#34;http://[::1]/&amp;#34;. IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go standard library net/url&lt;/p&gt;
&lt;p&gt;The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: &amp;#34;http://[::1]/&amp;#34;. IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-47912</guid>
    </item>
    <item>
      <title>GHSA-f6x5-jh6r-wrfv — golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f6x5-jh6r-wrfv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/crypto&lt;/p&gt;
&lt;p&gt;SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: golang.org/x/crypto&lt;/p&gt;
&lt;p&gt;SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f6x5-jh6r-wrfv</guid>
    </item>
  </channel>
</rss>
