<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:47:06 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1762 — Important: container-tools:rhel8 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1762</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.
Security Fix(es):
* psgo: Privilege escalation in &amp;#39;podman top&amp;#39; (CVE-2022-1227)
* prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)
* podman: Default inheritable capabilities for linux container should be empty (CVE-2022-27649)
* crun: Default inheritable capabilities for linux container should be empty (CVE-2022-27650)
* buildah: Default inheritable capabilities for linux container should be empty (CVE-2022-27651)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.
Security Fix(es):
* psgo: Privilege escalation in &amp;#39;podman top&amp;#39; (CVE-2022-1227)
* prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)
* podman: Default inheritable capabilities for linux container should be empty (CVE-2022-27649)
* crun: Default inheritable capabilities for linux container should be empty (CVE-2022-27650)
* buildah: Default inheritable capabilities for linux container should be empty (CVE-2022-27651)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1762</guid>
    </item>
    <item>
      <title>bdu:2022-05475</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05475</link>
      <description>bdu:2022-05475</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05475</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0562 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0562</link>
      <description>certfr-2025-avi-0562</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0562</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-EP15881 — Security fixes in cert-manager-webhook-pdns-fips 2.3.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ep15881</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cert-manager-webhook-pdns-fips&lt;/p&gt;
&lt;p&gt;Package cert-manager-webhook-pdns-fips version 2.3.0-r0 fixes 17 vulnerabilities: CVE-2022-1996, CVE-2023-45142, CVE-2023-25151, CVE-2022-21698, CVE-2022-30636...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cert-manager-webhook-pdns-fips&lt;/p&gt;
&lt;p&gt;Package cert-manager-webhook-pdns-fips version 2.3.0-r0 fixes 17 vulnerabilities: CVE-2022-1996, CVE-2023-45142, CVE-2023-25151, CVE-2022-21698, CVE-2022-30636...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ep15881</guid>
    </item>
    <item>
      <title>EUVD-2026-234449</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-234449</link>
      <description>EUVD-2026-234449</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-234449</guid>
    </item>
    <item>
      <title>fkie_cve-2022-21698</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21698</link>
      <description>&lt;p&gt;client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods. In order to be affected, an instrumented software must use any of `promhttp.InstrumentHandler*` middleware except `RequestsInFlight`; not filter any specific methods (e.g GET) before middleware; pass metric with `method` label name to our middleware; and not have any firewall/LB/proxy that filters away requests with unknown `method`. client_golang version 1.11.1 contains a patch for this issue. Several workarounds are available, including removing the `method` label name from counter/gauge used in the InstrumentHandler; turning off affected promhttp handlers; adding custom middleware before promhttp handler that will sanitize the request method given by Go http.Request; and using a reverse proxy or web application firewall, configured to only allow a limited set of methods.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods. In order to be affected, an instrumented software must use any of `promhttp.InstrumentHandler*` middleware except `RequestsInFlight`; not filter any specific methods (e.g GET) before middleware; pass metric with `method` label name to our middleware; and not have any firewall/LB/proxy that filters away requests with unknown `method`. client_golang version 1.11.1 contains a patch for this issue. Several workarounds are available, including removing the `method` label name from counter/gauge used in the InstrumentHandler; turning off affected promhttp handlers; adding custom middleware before promhttp handler that will sanitize the request method given by Go http.Request; and using a reverse proxy or web application firewall, configured to only allow a limited set of methods.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-21698</guid>
    </item>
    <item>
      <title>GHSA-cg3q-j54f-5p7p — Uncontrolled Resource Consumption in promhttp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cg3q-j54f-5p7p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/prometheus/client_golang&lt;/p&gt;
&lt;p&gt;This is the Go client library for Prometheus. It has two separate parts, one for instrumenting application code, and one for creating clients that talk to the Prometheus HTTP API. client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;HTTP server susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods.&lt;/p&gt;
&lt;p&gt;###  Affected Configuration&lt;/p&gt;
&lt;p&gt;In order to be affected, an instrumented software must&lt;/p&gt;
&lt;p&gt;* Use any of `promhttp.InstrumentHandler*` middleware except `RequestsInFlight`.
* Do not filter any specific methods (e.g GET) before middleware.
* Pass metric with `method` label name to our middleware.
* Not have any firewall/LB/proxy that filters away requests with unknown `method`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;* https://github.com/prometheus/client_golang/pull/962
* https://github.com/prometheus/client_golang/pull/987&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If you cannot upgrade to [v1.11.1 or above](https://github.com/prometheus/client_golang/releases/tag/v1.11.1), in order to stop being affected you can:&lt;/p&gt;
&lt;p&gt;* Remove `method` label name from counter/gauge you use in the InstrumentHandler.
* Turn off affected promhttp handlers.
* Add custom middleware before promhttp handler that will sanitize the request method given by Go http.Request.
* Use a reverse proxy or web application firewall, configured to o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/prometheus/client_golang&lt;/p&gt;
&lt;p&gt;This is the Go client library for Prometheus. It has two separate parts, one for instrumenting application code, and one for creating clients that talk to the Prometheus HTTP API. client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;HTTP server susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods.&lt;/p&gt;
&lt;p&gt;###  Affected Configuration&lt;/p&gt;
&lt;p&gt;In order to be affected, an instrumented software must&lt;/p&gt;
&lt;p&gt;* Use any of `promhttp.InstrumentHandler*` middleware except `RequestsInFlight`.
* Do not filter any specific methods (e.g GET) before middleware.
* Pass metric with `method` label name to our middleware.
* Not have any firewall/LB/proxy that filters away requests with unknown `method`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;* https://github.com/prometheus/client_golang/pull/962
* https://github.com/prometheus/client_golang/pull/987&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;If you cannot upgrade to [v1.11.1 or above](https://github.com/prometheus/client_golang/releases/tag/v1.11.1), in order to stop being affected you can:&lt;/p&gt;
&lt;p&gt;* Remove `method` label name from counter/gauge you use in the InstrumentHandler.
* Turn off affected promhttp handlers.
* Add custom middleware before promhttp handler that will sanitize the request method given by Go http.Request.
* Use a reverse proxy or web application firewall, configured to o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cg3q-j54f-5p7p</guid>
    </item>
    <item>
      <title>gsd-2022-21698</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-21698</link>
      <description>gsd-2022-21698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-21698</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-21698 — Uncontrolled Resource Consumption in promhttp</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-21698</link>
      <description>msrc_CVE-2022-21698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-21698</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11965-1 — kubeseal-0.17.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11965-1</link>
      <description>&lt;p&gt;kubeseal-0.17.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kubeseal-0.17.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11965-1</guid>
    </item>
    <item>
      <title>RHBA-2022:5876 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.10.26 extras update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2022:5876</link>
      <description>&lt;p&gt;prometheus/client_golang: Denial of service using InstrumentHandlerCounter&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;prometheus/client_golang: Denial of service using InstrumentHandlerCounter&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2022:5876</guid>
    </item>
    <item>
      <title>SUSE-EL-9-CLIENT-TOOLS-2026-2254 — Security update 5.0.8 for Multi-Linux Manager Client Tools</title>
      <link>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2026-2254</link>
      <description>&lt;p&gt;Security update 5.0.8 for Multi-Linux Manager Client Tools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update 5.0.8 for Multi-Linux Manager Client Tools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2026-2254</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-21698</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21698</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: golang-github-prometheus-client-golang, Ubuntu:20.04:LTS: golang-github-prometheus-client-golang, Ubuntu:22.04:LTS: golang-github-prometheus-client-golang, Ubuntu:24.04:LTS: golang-github-prometheus-client-golang, Ubuntu:25.10: golang-github-prometheus-client-golang, Ubuntu:26.04:LTS: golang-github-prometheus-client-golang&lt;/p&gt;
&lt;p&gt;client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods. In order to be affected, an instrumented software must use any of `promhttp.InstrumentHandler*` middleware except `RequestsInFlight`; not filter any specific methods (e.g GET) before middleware; pass metric with `method` label name to our middleware; and not have any firewall/LB/proxy that filters away requests with unknown `method`. client_golang version 1.11.1 contains a patch for this issue. Several workarounds are available, including removing the `method` label name from counter/gauge used in the InstrumentHandler; turning off affected promhttp handlers; adding custom middleware before promhttp handler that will sanitize the request method given by Go http.Request; and using a reverse proxy or web application firewall, configured to only allow a limited set of methods.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: golang-github-prometheus-client-golang, Ubuntu:20.04:LTS: golang-github-prometheus-client-golang, Ubuntu:22.04:LTS: golang-github-prometheus-client-golang, Ubuntu:24.04:LTS: golang-github-prometheus-client-golang, Ubuntu:25.10: golang-github-prometheus-client-golang, Ubuntu:26.04:LTS: golang-github-prometheus-client-golang&lt;/p&gt;
&lt;p&gt;client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods. In order to be affected, an instrumented software must use any of `promhttp.InstrumentHandler*` middleware except `RequestsInFlight`; not filter any specific methods (e.g GET) before middleware; pass metric with `method` label name to our middleware; and not have any firewall/LB/proxy that filters away requests with unknown `method`. client_golang version 1.11.1 contains a patch for this issue. Several workarounds are available, including removing the `method` label name from counter/gauge used in the InstrumentHandler; turning off affected promhttp handlers; adding custom middleware before promhttp handler that will sanitize the request method given by Go http.Request; and using a reverse proxy or web application firewall, configured to only allow a limited set of methods.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21698</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0069 — Red Hat OpenShift Logging Subsystem: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0069</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Logging Subsystem ausnutzen, um Sicherheitsmechanismen zu umgehen und um einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Logging Subsystem ausnutzen, um Sicherheitsmechanismen zu umgehen und um einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0069</guid>
    </item>
  </channel>
</rss>
