<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 02:53:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-232705</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232705</link>
      <description>EUVD-2026-232705</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232705</guid>
    </item>
    <item>
      <title>fkie_cve-2022-29245</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-29245</link>
      <description>&lt;p&gt;SSH.NET is a Secure Shell (SSH) library for .NET. In versions 2020.0.0 and 2020.0.1, during an `X25519` key exchange, the client’s private key is generated with `System.Random`. `System.Random` is not a cryptographically secure random number generator, it must therefore not be used for cryptographic purposes. When establishing an SSH connection to a remote host, during the X25519 key exchange, the private key is generated with a weak random number generator whose seed can be brute forced. This allows an attacker who is able to eavesdrop on the communications to decrypt them. Version 2020.0.2 contains a patch for this issue. As a workaround, one may disable support for `curve25519-sha256` and `curve25519-sha256@libssh.org` key exchange algorithms.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SSH.NET is a Secure Shell (SSH) library for .NET. In versions 2020.0.0 and 2020.0.1, during an `X25519` key exchange, the client’s private key is generated with `System.Random`. `System.Random` is not a cryptographically secure random number generator, it must therefore not be used for cryptographic purposes. When establishing an SSH connection to a remote host, during the X25519 key exchange, the private key is generated with a weak random number generator whose seed can be brute forced. This allows an attacker who is able to eavesdrop on the communications to decrypt them. Version 2020.0.2 contains a patch for this issue. As a workaround, one may disable support for `curve25519-sha256` and `curve25519-sha256@libssh.org` key exchange algorithms.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-29245</guid>
    </item>
    <item>
      <title>GHSA-72p8-v4hg-v45p — Weak private key generation in SSH.NET</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-72p8-v4hg-v45p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: SSH.NET&lt;/p&gt;
&lt;p&gt;During an **X25519** key exchange, the client’s private is generated with [**System.Random**](https://docs.microsoft.com/en-us/dotnet/api/system.random):&lt;/p&gt;
&lt;p&gt;```cs
var rnd = new Random();
_privateKey = new byte[MontgomeryCurve25519.PrivateKeySizeInBytes];
rnd.NextBytes(_privateKey);
```&lt;/p&gt;
&lt;p&gt;Source: [KeyExchangeECCurve25519.cs](https://github.com/sshnet/SSH.NET/blob/bc99ada7da3f05f50d9379f2644941d91d5bf05a/src/Renci.SshNet/Security/KeyExchangeECCurve25519.cs#L51)  
Source commit: https://github.com/sshnet/SSH.NET/commit/b58a11c0da55da1f5bad46faad2e9b71b7cb35b3&lt;/p&gt;
&lt;p&gt;[**System.Random**](https://docs.microsoft.com/en-us/dotnet/api/system.random) is not a cryptographically secure random number generator, it must therefore not be used for cryptographic purposes.&lt;/p&gt;
&lt;p&gt;### Impact
When establishing an SSH connection to a remote host, during the X25519 key exchange, the private key is generated with
a weak random number generator whose seed can be bruteforced. This allows an attacker able to eavesdrop the
communications to decrypt them.&lt;/p&gt;
&lt;p&gt;### Workarounds
To ensure you&amp;#39;re not affected by this vulnerability, you can disable support for `curve25519-sha256` and `curve25519-sha256@libssh.org` key exchange algorithms by invoking the following method before a connection is established:
```cs
private static void RemoveUnsecureKEX(BaseClient client)
{
    client.ConnectionInfo.KeyExchangeAlgorithms.Remove(&amp;#34;curve25519-sha256&amp;#34;);
    client.ConnectionInfo.KeyExchangeAlgorithms.Remove(&amp;#34;curve25519-sha256@libssh.o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: SSH.NET&lt;/p&gt;
&lt;p&gt;During an **X25519** key exchange, the client’s private is generated with [**System.Random**](https://docs.microsoft.com/en-us/dotnet/api/system.random):&lt;/p&gt;
&lt;p&gt;```cs
var rnd = new Random();
_privateKey = new byte[MontgomeryCurve25519.PrivateKeySizeInBytes];
rnd.NextBytes(_privateKey);
```&lt;/p&gt;
&lt;p&gt;Source: [KeyExchangeECCurve25519.cs](https://github.com/sshnet/SSH.NET/blob/bc99ada7da3f05f50d9379f2644941d91d5bf05a/src/Renci.SshNet/Security/KeyExchangeECCurve25519.cs#L51)  
Source commit: https://github.com/sshnet/SSH.NET/commit/b58a11c0da55da1f5bad46faad2e9b71b7cb35b3&lt;/p&gt;
&lt;p&gt;[**System.Random**](https://docs.microsoft.com/en-us/dotnet/api/system.random) is not a cryptographically secure random number generator, it must therefore not be used for cryptographic purposes.&lt;/p&gt;
&lt;p&gt;### Impact
When establishing an SSH connection to a remote host, during the X25519 key exchange, the private key is generated with
a weak random number generator whose seed can be bruteforced. This allows an attacker able to eavesdrop the
communications to decrypt them.&lt;/p&gt;
&lt;p&gt;### Workarounds
To ensure you&amp;#39;re not affected by this vulnerability, you can disable support for `curve25519-sha256` and `curve25519-sha256@libssh.org` key exchange algorithms by invoking the following method before a connection is established:
```cs
private static void RemoveUnsecureKEX(BaseClient client)
{
    client.ConnectionInfo.KeyExchangeAlgorithms.Remove(&amp;#34;curve25519-sha256&amp;#34;);
    client.ConnectionInfo.KeyExchangeAlgorithms.Remove(&amp;#34;curve25519-sha256@libssh.o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-72p8-v4hg-v45p</guid>
    </item>
    <item>
      <title>gsd-2022-29245</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-29245</link>
      <description>gsd-2022-29245</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-29245</guid>
    </item>
  </channel>
</rss>
