<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:47:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-351223</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351223</link>
      <description>EUVD-2026-351223</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351223</guid>
    </item>
    <item>
      <title>fkie_cve-2026-18941</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-18941</link>
      <description>&lt;p&gt;A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is &amp;#34;no_auth,&amp;#34; meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker, by exploiting this missing authentication, could achieve remote code execution (RCE) by storing a malicious User-Defined Function (UDF) on the feature-server, trigger a denial of service (DoS) by forcing re-materialization of all tenant features, and gain unauthorized access to cross-tenant data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is &amp;#34;no_auth,&amp;#34; meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker, by exploiting this missing authentication, could achieve remote code execution (RCE) by storing a malicious User-Defined Function (UDF) on the feature-server, trigger a denial of service (DoS) by forcing re-materialization of all tenant features, and gain unauthorized access to cross-tenant data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-18941</guid>
    </item>
    <item>
      <title>GHSA-2xfw-wg76-86w9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2xfw-wg76-86w9</link>
      <description>&lt;p&gt;A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is &amp;#34;no_auth,&amp;#34; meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker, by exploiting this missing authentication, could achieve remote code execution (RCE) by storing a malicious User-Defined Function (UDF) on the feature-server, trigger a denial of service (DoS) by forcing re-materialization of all tenant features, and gain unauthorized access to cross-tenant data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is &amp;#34;no_auth,&amp;#34; meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker, by exploiting this missing authentication, could achieve remote code execution (RCE) by storing a malicious User-Defined Function (UDF) on the feature-server, trigger a denial of service (DoS) by forcing re-materialization of all tenant features, and gain unauthorized access to cross-tenant data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2xfw-wg76-86w9</guid>
    </item>
    <item>
      <title>RHSA-2026:53261 — Red Hat Security Advisory: RHOAI 2.25.10 - Red Hat OpenShift AI</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:53261</link>
      <description>&lt;p&gt;guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex trustyai-service-operator: trustyai-service-operator: LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide odh-model-controller: odh-model-controller: Cross-namespace secret read via NIM Account CRD confused deputy odh-dashboard: odh-dashboard: Backend port 8080 trusts x-forwarded-access-token without origin validation data-science-pipelines-operator: DSPO: Operator ClusterRole grants pods/exec:*, kubeflow.org */*, and ClusterRole/Binding CRUD cluster-wide data-science-pipelines-operator: DSPO: Cryptographically weak secret generation (math/rand) for DB and S3 credentials data-science-pipelines-operator: DSPO: MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod ml-metdata: Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener data-sciences-pipeline: User-controlled ServiceAccount for workflow pods without authorization check — confused deputy data-sciences-pipeline: DSP: V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening feast: feast-operator: Feast: Default authentication mode is no_auth — shared mu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression Denial of Service (ReDoS) via detector_params.regex trustyai-service-operator: trustyai-service-operator: LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override trustyai-service-operator: trustyai-service-operator: TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide odh-model-controller: odh-model-controller: Cross-namespace secret read via NIM Account CRD confused deputy odh-dashboard: odh-dashboard: Backend port 8080 trusts x-forwarded-access-token without origin validation data-science-pipelines-operator: DSPO: Operator ClusterRole grants pods/exec:*, kubeflow.org */*, and ClusterRole/Binding CRUD cluster-wide data-science-pipelines-operator: DSPO: Cryptographically weak secret generation (math/rand) for DB and S3 credentials data-science-pipelines-operator: DSPO: MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod ml-metdata: Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener data-sciences-pipeline: User-controlled ServiceAccount for workflow pods without authorization check — confused deputy data-sciences-pipeline: DSP: V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening feast: feast-operator: Feast: Default authentication mode is no_auth — shared mu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:53261</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2750 — Red Hat OpenShift: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2750</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2750</guid>
    </item>
  </channel>
</rss>
