<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:56:35.634872+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-00025</id>
    <title>bdu:2020-00025</title>
    <updated>2026-10-02T13:56:35.652186+00:00</updated>
    <content>bdu:2020-00025</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-00025"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2019-11253</id>
    <title>Withdrawn: BELL-CVE-2019-11253 — CVE-2019-11253 does not affect BellSoft software</title>
    <updated>2026-10-02T13:56:35.652222+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2019-11253"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-591</id>
    <title>certfr-2022-avi-591 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T13:56:35.652242+00:00</updated>
    <content>certfr-2022-avi-591</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-591"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-zg19712</id>
    <title>CLEANSTART-2025-ZG19712 — Improper input validation in the Kubernetes API server in versions v1</title>
    <updated>2026-10-02T13:56:35.652259+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: containerd</p>
<p>Security vulnerability affects the containerd package. Improper input validation in the Kubernetes API server in versions v1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-zg19712"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-175917</id>
    <title>EUVD-2026-175917</title>
    <updated>2026-10-02T13:56:35.652286+00:00</updated>
    <content>EUVD-2026-175917</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-175917"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-11253</id>
    <title>fkie_cve-2019-11253</title>
    <updated>2026-10-02T13:56:35.652298+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-11253"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pmqp-h87c-mr78</id>
    <title>GHSA-pmqp-h87c-mr78 — XML Entity Expansion and Improper Input Validation in Kubernetes API server</title>
    <updated>2026-10-02T13:56:35.652354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: k8s.io/kubernetes</p>
<p>Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.</p>
<p>### Specific Go Packages Affected
k8s.io/kubernetes/pkg/apiserver</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pmqp-h87c-mr78"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-11253</id>
    <title>gsd-2019-11253</title>
    <updated>2026-10-02T13:56:35.652395+00:00</updated>
    <content>gsd-2019-11253</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-11253"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10901-1</id>
    <title>openSUSE-SU-2024:10901-1 — kubernetes-apiserver-1.22.2-21.2 on GA media</title>
    <updated>2026-10-02T13:56:35.652407+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kubernetes-apiserver-1.22.2-21.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10901-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhea-2019:3809</id>
    <title>RHEA-2019:3809 — Red Hat Enhancement Advisory: Red Hat OpenShift Service Mesh 1.0.2 RPMs</title>
    <updated>2026-10-02T13:56:35.652428+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhea-2019:3809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0510</id>
    <title>WID-SEC-W-2022-0510 — IBM DB2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:56:35.652444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um Dateien zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, willkürlichen Code mit erhöhten Rechten auszuführen, Informationen falsch darzustellen und beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0510"/>
  </entry>
</feed>
