<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 22:18:44 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-68121 — Unexpected session resumption in crypto/tls</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-68121</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go standard library crypto/tls&lt;/p&gt;
&lt;p&gt;During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go standard library crypto/tls&lt;/p&gt;
&lt;p&gt;During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-68121</guid>
    </item>
    <item>
      <title>GHSA-m3xc-h892-ggx6 — go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m3xc-h892-ggx6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-git/go-billy/v5, Go: github.com/go-git/go-billy/v6&lt;/p&gt;
&lt;p&gt;### Impact
Multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption.&lt;/p&gt;
&lt;p&gt;These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures.&lt;/p&gt;
&lt;p&gt;### Patches
Users should upgrade to a patched version in order to mitigate this vulnerability. Versions prior to `v5` are likely to be affected, users are recommended to upgrade to a supported `go-billy` version.&lt;/p&gt;
&lt;p&gt;### Credits
Thanks to @faran66 for finding and reporting this issue privately to the go-git project. 🙇&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/go-git/go-billy/v5, Go: github.com/go-git/go-billy/v6&lt;/p&gt;
&lt;p&gt;### Impact
Multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption.&lt;/p&gt;
&lt;p&gt;These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures.&lt;/p&gt;
&lt;p&gt;### Patches
Users should upgrade to a patched version in order to mitigate this vulnerability. Versions prior to `v5` are likely to be affected, users are recommended to upgrade to a supported `go-billy` version.&lt;/p&gt;
&lt;p&gt;### Credits
Thanks to @faran66 for finding and reporting this issue privately to the go-git project. 🙇&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m3xc-h892-ggx6</guid>
    </item>
  </channel>
</rss>
