<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from cleanstart</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:59:18 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-ZV78301 — SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the c…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-zv78301</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the consul package. SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the consul package. SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-zv78301</guid>
      <pubDate>Fri, 02 Oct 2026 00:35:56 +0000</pubDate>
    </item>
    <item>
      <title>CLEANSTART-2026-ZL19560 — Security fix for ghsa-9h8m-3fm2-qjrq applied in: consul 1.21.5-r0, cosign 3.0.5-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-zl19560</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul, CleanStart: cosign&lt;/p&gt;
&lt;p&gt;ghsa-9h8m-3fm2-qjrq affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul, CleanStart: cosign&lt;/p&gt;
&lt;p&gt;ghsa-9h8m-3fm2-qjrq affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-zl19560</guid>
      <pubDate>Fri, 02 Oct 2026 00:35:55 +0000</pubDate>
    </item>
    <item>
      <title>CLEANSTART-2026-YZ71204 — authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory grow…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-yz71204</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the consul package. An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the consul package. An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-yz71204</guid>
      <pubDate>Fri, 02 Oct 2026 00:35:54 +0000</pubDate>
    </item>
    <item>
      <title>CLEANSTART-2026-YM37209 — Security fix for ghsa-4f99-4q7p-p3gh applied in: consul 1.20.6-r0, consul 1.21.5-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ym37209</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;ghsa-4f99-4q7p-p3gh affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;ghsa-4f99-4q7p-p3gh affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ym37209</guid>
      <pubDate>Fri, 02 Oct 2026 00:35:55 +0000</pubDate>
    </item>
    <item>
      <title>CLEANSTART-2026-YF33963 — Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-yf33963</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;CVE-2026-56859 affects multiple packages. Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;CVE-2026-56859 affects multiple packages. Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-yf33963</guid>
      <pubDate>Fri, 02 Oct 2026 00:35:52 +0000</pubDate>
    </item>
    <item>
      <title>CLEANSTART-2026-YE69312 — Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbit…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ye69312</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;CVE-2026-56858 affects multiple packages. Previously, pathological inputs could close an unescaped &amp;#39;/&amp;#39; early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;CVE-2026-56858 affects multiple packages. Previously, pathological inputs could close an unescaped &amp;#39;/&amp;#39; early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ye69312</guid>
      <pubDate>Fri, 02 Oct 2026 00:35:52 +0000</pubDate>
    </item>
    <item>
      <title>CLEANSTART-2026-XZ73370 — Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-xz73370</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;CVE-2026-33818 affects multiple packages. Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;CVE-2026-33818 affects multiple packages. Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-xz73370</guid>
      <pubDate>Fri, 02 Oct 2026 00:35:52 +0000</pubDate>
    </item>
    <item>
      <title>CLEANSTART-2026-TZ02456 — denial-of-service vulnerability exists in github</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-tz02456</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;CVE-2025-65637 affects multiple packages. A denial-of-service vulnerability exists in github. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;CVE-2025-65637 affects multiple packages. A denial-of-service vulnerability exists in github. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-tz02456</guid>
      <pubDate>Fri, 02 Oct 2026 00:35:55 +0000</pubDate>
    </item>
    <item>
      <title>CLEANSTART-2026-TS90060 — Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ts90060</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the consul package. Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the consul package. Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ts90060</guid>
      <pubDate>Fri, 02 Oct 2026 00:35:54 +0000</pubDate>
    </item>
    <item>
      <title>CLEANSTART-2026-TG08354 — html</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-tg08354</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the consul package. The html.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: consul&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the consul package. The html.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-tg08354</guid>
      <pubDate>Fri, 02 Oct 2026 00:35:56 +0000</pubDate>
    </item>
  </channel>
</rss>
