<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://127.0.0.1:10001/cna-root/redhat/recent</id>
  <title>Most recent vulnerabilities from the redhat CNA root</title>
  <updated>2026-10-03T16:09:15.054558+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>info@circl.lu</email>
  </author>
  <link href="https://127.0.0.1:10001" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Latest vulnerabilities published by the CNAs operating under the redhat root of the CVE Program.</subtitle>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-105105</id>
    <title>CVE-2026-105105 (TuranSec)</title>
    <updated>2026-10-03T11:55:44.853000+00:00</updated>
    <content>Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-105105"/>
    <summary>Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration</summary>
    <published>2026-10-03T11:55:44.853000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-104988</id>
    <title>CVE-2026-104988 (redhat)</title>
    <updated>2026-10-02T19:34:33.328000+00:00</updated>
    <content>Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-104988"/>
    <summary>Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject</summary>
    <published>2026-10-02T19:34:33.328000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-94422</id>
    <title>CVE-2026-94422 (redhat)</title>
    <updated>2026-10-02T13:54:10.589000+00:00</updated>
    <content>xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-94422"/>
    <summary>xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape</summary>
    <published>2026-10-02T13:54:10.589000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-95512</id>
    <title>CVE-2026-95512 (redhat)</title>
    <updated>2026-10-02T09:05:11.245000+00:00</updated>
    <content>Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-95512"/>
    <summary>Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader</summary>
    <published>2026-10-02T09:05:11.245000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-86345</id>
    <title>CVE-2026-86345 (redhat)</title>
    <updated>2026-10-01T23:27:47.752000+00:00</updated>
    <content>389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-86345"/>
    <summary>389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result</summary>
    <published>2026-10-01T23:27:47.752000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-86344</id>
    <title>CVE-2026-86344 (redhat)</title>
    <updated>2026-10-01T21:29:55.877000+00:00</updated>
    <content>389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-86344"/>
    <summary>389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue</summary>
    <published>2026-10-01T21:29:55.877000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-103484</id>
    <title>CVE-2026-103484 (PostgreSQL)</title>
    <updated>2026-10-01T19:49:03.670000+00:00</updated>
    <content>pgvector buffer overflow in IVFFlat index build</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-103484"/>
    <summary>pgvector buffer overflow in IVFFlat index build</summary>
    <published>2026-10-01T19:49:03.670000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-103884</id>
    <title>CVE-2026-103884 (redhat)</title>
    <updated>2026-10-01T17:16:21.093000+00:00</updated>
    <content>Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-103884"/>
    <summary>Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read</summary>
    <published>2026-10-01T17:16:21.093000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-56098</id>
    <title>CVE-2026-56098 (redhat)</title>
    <updated>2026-10-01T17:14:56.199000+00:00</updated>
    <content>Rubygem-katello: improper authorization logic allows resource enumeration</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-56098"/>
    <summary>Rubygem-katello: improper authorization logic allows resource enumeration</summary>
    <published>2026-10-01T17:14:56.199000+00:00</published>
  </entry>
  <entry>
    <id>https://127.0.0.1:10001/vuln/cve-2026-56097</id>
    <title>CVE-2026-56097 (redhat)</title>
    <updated>2026-10-01T17:14:50.454000+00:00</updated>
    <content>Rubygem-katello: sql injection in registry proxy via labels</content>
    <link href="https://127.0.0.1:10001/vuln/cve-2026-56097"/>
    <summary>Rubygem-katello: sql injection in registry proxy via labels</summary>
    <published>2026-10-01T17:14:50.454000+00:00</published>
  </entry>
</feed>
