<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_redhat/10</id>
  <title>Most recent entries from csaf_redhat</title>
  <updated>2026-10-02T07:10:05.359240+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:74581</id>
    <title>RHSA-2026:74581 — Red Hat Security Advisory: skopeo security update</title>
    <updated>2026-10-02T05:31:26+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:74581"/>
    <published>2026-10-01T19:11:40+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:74023</id>
    <title>RHSA-2026:74023 — Red Hat Security Advisory: OpenShift Container Platform 4.21 CNF IBU extras update</title>
    <updated>2026-10-02T05:31:26+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:74023"/>
    <published>2026-09-30T14:55:17+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:73987</id>
    <title>RHSA-2026:73987 — Red Hat Security Advisory: RHOAI 3.3.7 - Red Hat OpenShift AI</title>
    <updated>2026-10-02T05:31:25+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/url: Memory exhaustion in query parameter parsing in net/url urllib3: urllib3 Streaming API improperly handles highly compressed data nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy keras: Keras: Arbitrary file write via path traversal in archive extraction utilities sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:73987"/>
    <published>2026-09-30T13:36:01+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:73518</id>
    <title>RHSA-2026:73518 — Red Hat Security Advisory: OpenShift Container Platform 4.16 CNF vRAN extras topology aware lifecycle manager update</title>
    <updated>2026-10-02T05:31:24+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:73518"/>
    <published>2026-09-29T16:41:14+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:73508</id>
    <title>RHSA-2026:73508 — Red Hat Security Advisory: OpenShift Container Platform 4.21 CNF vRAN extras topology aware lifecycle manager update</title>
    <updated>2026-10-02T05:31:24+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:73508"/>
    <published>2026-09-29T14:46:36+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:73085</id>
    <title>RHSA-2026:73085 — Red Hat Security Advisory: OpenShift Container Platform 4.22 CNF vRAN extras topology aware lifecycle manager update</title>
    <updated>2026-10-02T05:31:23+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:73085"/>
    <published>2026-09-29T07:53:39+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:72508</id>
    <title>RHSA-2026:72508 — Red Hat Security Advisory: OpenShift Container Platform 4.20 CNF IBU extras update</title>
    <updated>2026-10-02T05:31:22+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:72508"/>
    <published>2026-09-28T13:37:39+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71455</id>
    <title>RHSA-2026:71455 — Red Hat Security Advisory: OpenShift Container Platform 4.21.35 security and extras update</title>
    <updated>2026-10-02T05:31:21+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71455"/>
    <published>2026-09-29T06:31:17+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71454</id>
    <title>RHSA-2026:71454 — Red Hat Security Advisory: OpenShift Container Platform 4.22.16 bug fix and security update</title>
    <updated>2026-10-02T05:31:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs openshift/console: openshift/console: Unauthenticated SSRF and resource exhaustion via devfile parser endpoint openshift/console: openshift/console: Unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding openshift/console: openshift/console: Unauthenticated path traversal in i18n locale handler</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71454"/>
    <published>2026-09-29T08:22:07+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:71453</id>
    <title>RHSA-2026:71453 — Red Hat Security Advisory: OpenShift Container Platform 4.21.35 bug fix and security update</title>
    <updated>2026-10-02T05:31:19+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs openshift/console: openshift/console: Unauthenticated SSRF and resource exhaustion via devfile parser endpoint openshift/console: openshift/console: Unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding openshift/console: openshift/console: Unauthenticated path traversal in i18n locale handler qs: qs: Denial of Service via improper validation in stringify function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:71453"/>
    <published>2026-09-29T07:58:22+00:00</published>
  </entry>
</feed>
