<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:52:58.886126+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-45157</id>
    <title>cnvd-2019-45157</title>
    <updated>2026-10-03T10:52:59.064367+00:00</updated>
    <content>cnvd-2019-45157</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-45157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-58019</id>
    <title>EUVD-2026-58019</title>
    <updated>2026-10-03T10:52:59.064408+00:00</updated>
    <content>EUVD-2026-58019</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-58019"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-16770</id>
    <title>fkie_cve-2019-16770</title>
    <updated>2026-10-03T10:52:59.064424+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough. This vulnerability is patched in Puma 4.3.1 and 3.12.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-16770"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7xx3-m584-x994</id>
    <title>GHSA-7xx3-m584-x994 — A poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack</title>
    <updated>2026-10-03T10:52:59.064456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: puma</p>
<p>## Keepalive thread overload/DoS</p>
<p>### Impact</p>
<p>A poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack.</p>
<p>If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough.</p>
<p>### Patches</p>
<p>This vulnerability is patched in Puma 4.3.1 and 3.12.2.</p>
<p>### Workarounds</p>
<p>Reverse proxies in front of Puma could be configured to always allow less than X keepalive connections to a Puma cluster or process, where X is the number of threads configured in Puma's thread pool.</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory:</p>
<p>* Open an issue at [puma](github.com/puma/puma).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7xx3-m584-x994"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-16770</id>
    <title>gsd-2019-16770</title>
    <updated>2026-10-03T10:52:59.064492+00:00</updated>
    <content>gsd-2019-16770</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-16770"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1993-1</id>
    <title>openSUSE-SU-2020:1993-1 — Security update for rmt-server</title>
    <updated>2026-10-03T10:52:59.064504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rmt-server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:1993-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:2060-1</id>
    <title>SUSE-SU-2020:2060-1 — Security update for rubygem-puma</title>
    <updated>2026-10-03T10:52:59.064528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rubygem-puma</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:2060-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16770</id>
    <title>Withdrawn: UBUNTU-CVE-2019-16770</title>
    <updated>2026-10-03T10:52:59.064544+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:20.04:LTS: puma</p>
<p>In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough. This vulnerability is patched in Puma 4.3.1 and 3.12.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-16770"/>
  </entry>
</feed>
