<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 21:24:55 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-15558 — Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-15558</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Docker CLI, Docker Compose, Red Hat Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat Builds for Red Hat OpenShift, Red Hat Gatekeeper 3, Red Hat Kernel Module Management Operator for Red Hat Openshift, Red Hat Machine Deletion Remediation Operator, Red Hat Multicluster Engine for Kubernetes, Red Hat Multicluster Global Hub, Red Hat OpenShift Pipelines and 19 more&lt;/p&gt;
&lt;p&gt;Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens Docker Desktop or invokes Docker CLI plugin features, and allow privilege-escalation if the docker CLI is executed as a privileged user.&lt;/p&gt;
&lt;p&gt;This issue affects Docker CLI: through 29.1.5 and Windows binaries acting as a CLI-plugin manager using the  github.com/docker/cli/cli-plugins/manager https://pkg.go.dev/github.com/docker/cli@v29.1.5+incompatible/cli-plugins/manager  package, such as Docker Compose.&lt;/p&gt;
&lt;p&gt;This issue does not impact non-Windows binaries, and projects not using the plugin-manager code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Docker CLI, Docker Compose, Red Hat Assisted Installer for Red Hat OpenShift Container Platform 2, Red Hat Builds for Red Hat OpenShift, Red Hat Gatekeeper 3, Red Hat Kernel Module Management Operator for Red Hat Openshift, Red Hat Machine Deletion Remediation Operator, Red Hat Multicluster Engine for Kubernetes, Red Hat Multicluster Global Hub, Red Hat OpenShift Pipelines and 19 more&lt;/p&gt;
&lt;p&gt;Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens Docker Desktop or invokes Docker CLI plugin features, and allow privilege-escalation if the docker CLI is executed as a privileged user.&lt;/p&gt;
&lt;p&gt;This issue affects Docker CLI: through 29.1.5 and Windows binaries acting as a CLI-plugin manager using the  github.com/docker/cli/cli-plugins/manager https://pkg.go.dev/github.com/docker/cli@v29.1.5+incompatible/cli-plugins/manager  package, such as Docker Compose.&lt;/p&gt;
&lt;p&gt;This issue does not impact non-Windows binaries, and projects not using the plugin-manager code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-15558</guid>
    </item>
    <item>
      <title>GHSA-mqqf-5wvp-8fh8 — chi has an open redirect vulnerability in the RedirectSlashes middleware</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mqqf-5wvp-8fh8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-chi/chi/v5&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `RedirectSlashes` function in middleware/strip.go does not perform correct input validation and can lead to an open redirect vulnerability.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `RedirectSlashes` function performs a `Trim` to all forward slash (`/`) characters, while prepending a single one at the begining of the path (Line 52).&lt;/p&gt;
&lt;p&gt;However, it does not trim backslashes (`\`).&lt;/p&gt;
&lt;p&gt;```go
File: middleware/strip.go
41: func RedirectSlashes(next http.Handler) http.Handler {
...
51: 			// Trim all leading and trailing slashes (e.g., &amp;#34;//evil.com&amp;#34;, &amp;#34;/some/path//&amp;#34;)
52: 			path = &amp;#34;/&amp;#34; + strings.Trim(path, &amp;#34;/&amp;#34;)
...
62: }
```&lt;/p&gt;
&lt;p&gt;Also, from version 5.2.2 onwards the `RedirectSlashes` function does not take into consideration the `Host` Header in the redirect response returned. This was done in order to combat another [[vulnerability](https://github.com/go-chi/chi/security/advisories/GHSA-vrw8-fxc6-2r93)](https://github.com/go-chi/chi/security/advisories/GHSA-vrw8-fxc6-2r93).&lt;/p&gt;
&lt;p&gt;The above make it possible for a response in the following form:&lt;/p&gt;
&lt;p&gt;```
HTTP/1.1 301 Moved Permanently
Location: /\evil.com
```&lt;/p&gt;
&lt;p&gt;The `/\evil.com` will be transformed by most browsers (Chrome, Firefox, etc. not Safari) into `//evil.com` which is a protocol relative URL and will result in a redirect to `evil.com`, essentially making it an open redirect vulnerability.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;A minimal working example can be seen below.&lt;/p&gt;
&lt;p&gt;```go
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;fmt&amp;#34;
	&amp;#34;net/http&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/go-chi/chi/v5&amp;#34;
	&amp;#34;github.com/go-chi/chi/v5/middle…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-chi/chi/v5&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `RedirectSlashes` function in middleware/strip.go does not perform correct input validation and can lead to an open redirect vulnerability.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `RedirectSlashes` function performs a `Trim` to all forward slash (`/`) characters, while prepending a single one at the begining of the path (Line 52).&lt;/p&gt;
&lt;p&gt;However, it does not trim backslashes (`\`).&lt;/p&gt;
&lt;p&gt;```go
File: middleware/strip.go
41: func RedirectSlashes(next http.Handler) http.Handler {
...
51: 			// Trim all leading and trailing slashes (e.g., &amp;#34;//evil.com&amp;#34;, &amp;#34;/some/path//&amp;#34;)
52: 			path = &amp;#34;/&amp;#34; + strings.Trim(path, &amp;#34;/&amp;#34;)
...
62: }
```&lt;/p&gt;
&lt;p&gt;Also, from version 5.2.2 onwards the `RedirectSlashes` function does not take into consideration the `Host` Header in the redirect response returned. This was done in order to combat another [[vulnerability](https://github.com/go-chi/chi/security/advisories/GHSA-vrw8-fxc6-2r93)](https://github.com/go-chi/chi/security/advisories/GHSA-vrw8-fxc6-2r93).&lt;/p&gt;
&lt;p&gt;The above make it possible for a response in the following form:&lt;/p&gt;
&lt;p&gt;```
HTTP/1.1 301 Moved Permanently
Location: /\evil.com
```&lt;/p&gt;
&lt;p&gt;The `/\evil.com` will be transformed by most browsers (Chrome, Firefox, etc. not Safari) into `//evil.com` which is a protocol relative URL and will result in a redirect to `evil.com`, essentially making it an open redirect vulnerability.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;A minimal working example can be seen below.&lt;/p&gt;
&lt;p&gt;```go
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;fmt&amp;#34;
	&amp;#34;net/http&amp;#34;&lt;/p&gt;
&lt;p&gt;&amp;#34;github.com/go-chi/chi/v5&amp;#34;
	&amp;#34;github.com/go-chi/chi/v5/middle…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mqqf-5wvp-8fh8</guid>
    </item>
  </channel>
</rss>
