<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 08:02:47 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-27145 — Inefficient candidate hostname parsing in crypto/x509</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-27145</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go standard library crypto/x509, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 10, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Ansible Automation Platform 2.7 for RHEL 10, Red Hat Ansible Automation Platform 2.7 for RHEL 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support and 121 more&lt;/p&gt;
&lt;p&gt;(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, &amp;#34;.&amp;#34;) to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname&amp;#39;s label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go standard library crypto/x509, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 10, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Ansible Automation Platform 2.7 for RHEL 10, Red Hat Ansible Automation Platform 2.7 for RHEL 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support and 121 more&lt;/p&gt;
&lt;p&gt;(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, &amp;#34;.&amp;#34;) to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname&amp;#39;s label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-27145</guid>
    </item>
    <item>
      <title>GHSA-gcjh-h69q-9w9g — cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gcjh-h69q-9w9g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/google/cel-go&lt;/p&gt;
&lt;p&gt;The function `ext.NativeTypes(ParseStructTag(&amp;#34;json&amp;#34;))` does not honour the `encoding/json` skip directive `json:&amp;#34;-&amp;#34;`. Fields tagged `json:&amp;#34;-&amp;#34;` are registered in the CEL type system under the literal name `&amp;#34;-&amp;#34;` and are readable from any user-submitted CEL expression via `dyn(obj)[&amp;#34;-&amp;#34;]`.&lt;/p&gt;
&lt;p&gt;Additionally, `newNativeTypes` silently registers every nested struct reachable from the type passed to `NativeTypes`, including types from third-party dependencies the developer never examined.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;In `fieldNameByTag`, the helper used by `ParseStructTag(&amp;#34;json&amp;#34;)` to translate Go struct tags into CEL field names.&lt;/p&gt;
&lt;p&gt;See at `ext/native.go:146`:&lt;/p&gt;
&lt;p&gt;```go
func fieldNameByTag(structTagToParse string) func(field reflect.StructField) string {
    return func(field reflect.StructField) string {
        tag, found := field.Tag.Lookup(structTagToParse)
        if found {
            splits := strings.Split(tag, &amp;#34;,&amp;#34;)
            if len(splits) &amp;gt; 0 {
                // We make the assumption that the leftmost entry in the tag is the name.
                // This seems to be true for most tags that have the concept of a name/key, such as:
                // https://pkg.go.dev/encoding/xml#Marshal
                // https://pkg.go.dev/encoding/json#Marshal
                // https://pkg.go.dev/go.mongodb.org/mongo-driver/bson#hdr-Structs
                // https://pkg.go.dev/go.yaml.in/yaml/v3#Marshal
                name := splits[0]
                return name
            }
        }&lt;/p&gt;
&lt;p&gt;re…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/google/cel-go&lt;/p&gt;
&lt;p&gt;The function `ext.NativeTypes(ParseStructTag(&amp;#34;json&amp;#34;))` does not honour the `encoding/json` skip directive `json:&amp;#34;-&amp;#34;`. Fields tagged `json:&amp;#34;-&amp;#34;` are registered in the CEL type system under the literal name `&amp;#34;-&amp;#34;` and are readable from any user-submitted CEL expression via `dyn(obj)[&amp;#34;-&amp;#34;]`.&lt;/p&gt;
&lt;p&gt;Additionally, `newNativeTypes` silently registers every nested struct reachable from the type passed to `NativeTypes`, including types from third-party dependencies the developer never examined.&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;In `fieldNameByTag`, the helper used by `ParseStructTag(&amp;#34;json&amp;#34;)` to translate Go struct tags into CEL field names.&lt;/p&gt;
&lt;p&gt;See at `ext/native.go:146`:&lt;/p&gt;
&lt;p&gt;```go
func fieldNameByTag(structTagToParse string) func(field reflect.StructField) string {
    return func(field reflect.StructField) string {
        tag, found := field.Tag.Lookup(structTagToParse)
        if found {
            splits := strings.Split(tag, &amp;#34;,&amp;#34;)
            if len(splits) &amp;gt; 0 {
                // We make the assumption that the leftmost entry in the tag is the name.
                // This seems to be true for most tags that have the concept of a name/key, such as:
                // https://pkg.go.dev/encoding/xml#Marshal
                // https://pkg.go.dev/encoding/json#Marshal
                // https://pkg.go.dev/go.mongodb.org/mongo-driver/bson#hdr-Structs
                // https://pkg.go.dev/go.yaml.in/yaml/v3#Marshal
                name := splits[0]
                return name
            }
        }&lt;/p&gt;
&lt;p&gt;re…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gcjh-h69q-9w9g</guid>
    </item>
  </channel>
</rss>
