<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent vulnerabilities from the redhat CNA root</title>
    <link>https://127.0.0.1:10001</link>
    <description>Latest vulnerabilities published by the CNAs operating under the redhat root of the CVE Program.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:09:15 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-105105 (TuranSec)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-105105</link>
      <description>Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration</description>
      <content:encoded>Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-105105</guid>
      <pubDate>Sat, 03 Oct 2026 11:55:44 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-104988 (redhat)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-104988</link>
      <description>Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject</description>
      <content:encoded>Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-104988</guid>
      <pubDate>Fri, 02 Oct 2026 19:34:33 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-94422 (redhat)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-94422</link>
      <description>xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape</description>
      <content:encoded>xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-94422</guid>
      <pubDate>Fri, 02 Oct 2026 13:54:10 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-95512 (redhat)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-95512</link>
      <description>Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader</description>
      <content:encoded>Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-95512</guid>
      <pubDate>Fri, 02 Oct 2026 09:05:11 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-86345 (redhat)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-86345</link>
      <description>389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result</description>
      <content:encoded>389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-86345</guid>
      <pubDate>Thu, 01 Oct 2026 23:27:47 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-86344 (redhat)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-86344</link>
      <description>389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue</description>
      <content:encoded>389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-86344</guid>
      <pubDate>Thu, 01 Oct 2026 21:29:55 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103484 (PostgreSQL)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103484</link>
      <description>pgvector buffer overflow in IVFFlat index build</description>
      <content:encoded>pgvector buffer overflow in IVFFlat index build</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103484</guid>
      <pubDate>Thu, 01 Oct 2026 19:49:03 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103884 (redhat)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-103884</link>
      <description>Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read</description>
      <content:encoded>Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-103884</guid>
      <pubDate>Thu, 01 Oct 2026 17:16:21 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-56098 (redhat)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-56098</link>
      <description>Rubygem-katello: improper authorization logic allows resource enumeration</description>
      <content:encoded>Rubygem-katello: improper authorization logic allows resource enumeration</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-56098</guid>
      <pubDate>Thu, 01 Oct 2026 17:14:56 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-56097 (redhat)</title>
      <link>https://127.0.0.1:10001/vuln/cve-2026-56097</link>
      <description>Rubygem-katello: sql injection in registry proxy via labels</description>
      <content:encoded>Rubygem-katello: sql injection in registry proxy via labels</content:encoded>
      <guid isPermaLink="false">https://127.0.0.1:10001/vuln/cve-2026-56097</guid>
      <pubDate>Thu, 01 Oct 2026 17:14:50 +0000</pubDate>
    </item>
  </channel>
</rss>
