<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 22:34:26 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0967 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967</link>
      <description>certfr-2025-avi-0967</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0967</guid>
    </item>
    <item>
      <title>EUVD-2026-248537</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248537</link>
      <description>EUVD-2026-248537</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248537</guid>
    </item>
    <item>
      <title>fkie_cve-2024-58266</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-58266</link>
      <description>&lt;p&gt;The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-58266</guid>
    </item>
    <item>
      <title>GHSA-r7qv-8r2h-pg27 — Multiple issues involving quote API in shlex</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r7qv-8r2h-pg27</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: shlex&lt;/p&gt;
&lt;p&gt;## Issue 1: Failure to quote characters&lt;/p&gt;
&lt;p&gt;Affected versions of this crate allowed the bytes `{` and `\xa0` to appear unquoted and unescaped in command arguments.&lt;/p&gt;
&lt;p&gt;If the output of `quote` or `join` is passed to a shell, then what should be a single command argument could be interpreted as multiple arguments.&lt;/p&gt;
&lt;p&gt;This does not *directly* allow arbitrary command execution (you can&amp;#39;t inject a command substitution or similar).  But depending on the command you&amp;#39;re running, being able to inject multiple arguments where only one is expected could lead to undesired consequences, potentially including arbitrary command execution.&lt;/p&gt;
&lt;p&gt;The flaw was corrected in version 1.2.1 by escaping additional characters. Updating to 1.3.0 is recommended, but 1.2.1 offers a more minimal fix if desired.&lt;/p&gt;
&lt;p&gt;Workaround: Check for the bytes `{` and `\xa0` in `quote`/`join` input or output.&lt;/p&gt;
&lt;p&gt;(Note: `{` is problematic because it is used for glob expansion.  `\xa0` is problematic because it&amp;#39;s treated as a word separator in [specific environments][solved-xa0].)&lt;/p&gt;
&lt;p&gt;## Issue 2: Dangerous API w.r.t. nul bytes&lt;/p&gt;
&lt;p&gt;Version 1.3.0 deprecates the `quote` and `join` APIs in favor of `try_quote` and `try_join`, which behave the same except that they have `Result` return type, returning `Err` if the input contains nul bytes.&lt;/p&gt;
&lt;p&gt;Strings containing nul bytes generally cannot be used in Unix command arguments or environment variables, and most shells cannot handle nul bytes even internally.  If you try to pass one anyway, then the resu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: shlex&lt;/p&gt;
&lt;p&gt;## Issue 1: Failure to quote characters&lt;/p&gt;
&lt;p&gt;Affected versions of this crate allowed the bytes `{` and `\xa0` to appear unquoted and unescaped in command arguments.&lt;/p&gt;
&lt;p&gt;If the output of `quote` or `join` is passed to a shell, then what should be a single command argument could be interpreted as multiple arguments.&lt;/p&gt;
&lt;p&gt;This does not *directly* allow arbitrary command execution (you can&amp;#39;t inject a command substitution or similar).  But depending on the command you&amp;#39;re running, being able to inject multiple arguments where only one is expected could lead to undesired consequences, potentially including arbitrary command execution.&lt;/p&gt;
&lt;p&gt;The flaw was corrected in version 1.2.1 by escaping additional characters. Updating to 1.3.0 is recommended, but 1.2.1 offers a more minimal fix if desired.&lt;/p&gt;
&lt;p&gt;Workaround: Check for the bytes `{` and `\xa0` in `quote`/`join` input or output.&lt;/p&gt;
&lt;p&gt;(Note: `{` is problematic because it is used for glob expansion.  `\xa0` is problematic because it&amp;#39;s treated as a word separator in [specific environments][solved-xa0].)&lt;/p&gt;
&lt;p&gt;## Issue 2: Dangerous API w.r.t. nul bytes&lt;/p&gt;
&lt;p&gt;Version 1.3.0 deprecates the `quote` and `join` APIs in favor of `try_quote` and `try_join`, which behave the same except that they have `Result` return type, returning `Err` if the input contains nul bytes.&lt;/p&gt;
&lt;p&gt;Strings containing nul bytes generally cannot be used in Unix command arguments or environment variables, and most shells cannot handle nul bytes even internally.  If you try to pass one anyway, then the resu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r7qv-8r2h-pg27</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-58266 — The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may f…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-58266</link>
      <description>msrc_CVE-2024-58266</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-58266</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15433-1 — framework-inputmodule-control-0.2.0-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15433-1</link>
      <description>&lt;p&gt;framework-inputmodule-control-0.2.0-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;framework-inputmodule-control-0.2.0-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15433-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2024-0006 — Multiple issues involving quote API</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2024-0006</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: shlex&lt;/p&gt;
&lt;p&gt;## Issue 1: Failure to quote characters&lt;/p&gt;
&lt;p&gt;Affected versions of this crate allowed the bytes `{` and `\xa0` to appear
unquoted and unescaped in command arguments.&lt;/p&gt;
&lt;p&gt;If the output of `quote` or `join` is passed to a shell, then what should be a
single command argument could be interpreted as multiple arguments.&lt;/p&gt;
&lt;p&gt;This does not *directly* allow arbitrary command execution (you can&amp;#39;t inject a
command substitution or similar).  But depending on the command you&amp;#39;re running,
being able to inject multiple arguments where only one is expected could lead
to undesired consequences, potentially including arbitrary command execution.&lt;/p&gt;
&lt;p&gt;The flaw was corrected in version 1.2.1 by escaping additional characters.
Updating to 1.3.0 is recommended, but 1.2.1 offers a more minimal fix if
desired.&lt;/p&gt;
&lt;p&gt;Workaround: Check for the bytes `{` and `\xa0` in `quote`/`join` input or
output.&lt;/p&gt;
&lt;p&gt;(Note: `{` is problematic because it is used for glob expansion.  `\xa0` is
problematic because it&amp;#39;s treated as a word separator in [specific
environments][solved-xa0].)&lt;/p&gt;
&lt;p&gt;## Issue 2: Dangerous API w.r.t. nul bytes&lt;/p&gt;
&lt;p&gt;Version 1.3.0 deprecates the `quote` and `join` APIs in favor of `try_quote`
and `try_join`, which behave the same except that they have `Result` return
type, returning `Err` if the input contains nul bytes.&lt;/p&gt;
&lt;p&gt;Strings containing nul bytes generally cannot be used in Unix command arguments
or environment variables, and most shells cannot handle nul bytes even
internally.  If you try to pass one anyway, then the resu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: shlex&lt;/p&gt;
&lt;p&gt;## Issue 1: Failure to quote characters&lt;/p&gt;
&lt;p&gt;Affected versions of this crate allowed the bytes `{` and `\xa0` to appear
unquoted and unescaped in command arguments.&lt;/p&gt;
&lt;p&gt;If the output of `quote` or `join` is passed to a shell, then what should be a
single command argument could be interpreted as multiple arguments.&lt;/p&gt;
&lt;p&gt;This does not *directly* allow arbitrary command execution (you can&amp;#39;t inject a
command substitution or similar).  But depending on the command you&amp;#39;re running,
being able to inject multiple arguments where only one is expected could lead
to undesired consequences, potentially including arbitrary command execution.&lt;/p&gt;
&lt;p&gt;The flaw was corrected in version 1.2.1 by escaping additional characters.
Updating to 1.3.0 is recommended, but 1.2.1 offers a more minimal fix if
desired.&lt;/p&gt;
&lt;p&gt;Workaround: Check for the bytes `{` and `\xa0` in `quote`/`join` input or
output.&lt;/p&gt;
&lt;p&gt;(Note: `{` is problematic because it is used for glob expansion.  `\xa0` is
problematic because it&amp;#39;s treated as a word separator in [specific
environments][solved-xa0].)&lt;/p&gt;
&lt;p&gt;## Issue 2: Dangerous API w.r.t. nul bytes&lt;/p&gt;
&lt;p&gt;Version 1.3.0 deprecates the `quote` and `join` APIs in favor of `try_quote`
and `try_join`, which behave the same except that they have `Result` return
type, returning `Err` if the input contains nul bytes.&lt;/p&gt;
&lt;p&gt;Strings containing nul bytes generally cannot be used in Unix command arguments
or environment variables, and most shells cannot handle nul bytes even
internally.  If you try to pass one anyway, then the resu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2024-0006</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:20717-1 — Security update for rust-keylime</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:20717-1</link>
      <description>&lt;p&gt;Security update for rust-keylime&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rust-keylime&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:20717-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-58266</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58266</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: rust-shlex, Ubuntu:22.04:LTS: rust-shlex, Ubuntu:24.04:LTS: rust-shlex, Ubuntu:25.10: rust-shlex, Ubuntu:26.04:LTS: rust-shlex&lt;/p&gt;
&lt;p&gt;The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: rust-shlex, Ubuntu:22.04:LTS: rust-shlex, Ubuntu:24.04:LTS: rust-shlex, Ubuntu:25.10: rust-shlex, Ubuntu:26.04:LTS: rust-shlex&lt;/p&gt;
&lt;p&gt;The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58266</guid>
    </item>
  </channel>
</rss>
