<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/cleanstart/10</id>
  <title>Most recent entries from cleanstart</title>
  <updated>2026-10-02T07:10:00.326203+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-zv78301</id>
    <title>CLEANSTART-2026-ZV78301 — SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the c…</title>
    <updated>2026-10-01T12:15:40+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: consul</p>
<p>Security vulnerability affects the consul package. SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-zv78301"/>
    <published>2026-10-02T00:35:56.519832+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-zl19560</id>
    <title>CLEANSTART-2026-ZL19560 — Security fix for ghsa-9h8m-3fm2-qjrq applied in: consul 1.21.5-r0, cosign 3.0.5-r0</title>
    <updated>2026-10-01T12:15:40+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: consul, CleanStart: cosign</p>
<p>ghsa-9h8m-3fm2-qjrq affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-zl19560"/>
    <published>2026-10-02T00:35:55.915865+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-yz71204</id>
    <title>CLEANSTART-2026-YZ71204 — authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory grow…</title>
    <updated>2026-10-01T12:15:40+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: consul</p>
<p>Security vulnerability affects the consul package. An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-yz71204"/>
    <published>2026-10-02T00:35:54.739407+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ym37209</id>
    <title>CLEANSTART-2026-YM37209 — Security fix for ghsa-4f99-4q7p-p3gh applied in: consul 1.20.6-r0, consul 1.21.5-r0</title>
    <updated>2026-10-01T12:15:40+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: consul</p>
<p>ghsa-4f99-4q7p-p3gh affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ym37209"/>
    <published>2026-10-02T00:35:55.687200+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-yf33963</id>
    <title>CLEANSTART-2026-YF33963 — Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion</title>
    <updated>2026-10-01T12:15:40+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: consul</p>
<p>CVE-2026-56859 affects multiple packages. Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-yf33963"/>
    <published>2026-10-02T00:35:52.805764+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ye69312</id>
    <title>CLEANSTART-2026-YE69312 — Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbit…</title>
    <updated>2026-10-01T12:15:40+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: consul</p>
<p>CVE-2026-56858 affects multiple packages. Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ye69312"/>
    <published>2026-10-02T00:35:52.670106+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-xz73370</id>
    <title>CLEANSTART-2026-XZ73370 — Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures</title>
    <updated>2026-10-01T12:15:40+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: consul</p>
<p>CVE-2026-33818 affects multiple packages. Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-xz73370"/>
    <published>2026-10-02T00:35:52.250149+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-tz02456</id>
    <title>CLEANSTART-2026-TZ02456 — denial-of-service vulnerability exists in github</title>
    <updated>2026-10-01T12:15:40+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: consul</p>
<p>CVE-2025-65637 affects multiple packages. A denial-of-service vulnerability exists in github. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-tz02456"/>
    <published>2026-10-02T00:35:55.987828+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ts90060</id>
    <title>CLEANSTART-2026-TS90060 — Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service</title>
    <updated>2026-10-01T12:15:40+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: consul</p>
<p>Security vulnerability affects the consul package. Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ts90060"/>
    <published>2026-10-02T00:35:54.663499+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-tg08354</id>
    <title>CLEANSTART-2026-TG08354 — html</title>
    <updated>2026-10-01T12:15:40+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: consul</p>
<p>Security vulnerability affects the consul package. The html.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-tg08354"/>
    <published>2026-10-02T00:35:56.443707+00:00</published>
  </entry>
</feed>
