<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:32:29.119954+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:2925</id>
    <title>ALSA-2019:2925 — Important: nodejs:10 security update</title>
    <updated>2026-10-02T19:32:29.873409+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging</p>
<p>Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.</p>
<p>The following packages have been upgraded to a later upstream version: nodejs (10.16.3).</p>
<p>Security Fix(es):</p>
<p>* HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511)</p>
<p>* HTTP/2: flood using PING frames results in unbounded memory growth (CVE-2019-9512)</p>
<p>* HTTP/2: flood using PRIORITY frames results in excessive resource consumption (CVE-2019-9513)</p>
<p>* HTTP/2: flood using HEADERS frames results in unbounded memory growth (CVE-2019-9514)</p>
<p>* HTTP/2: flood using SETTINGS frames results in unbounded memory growth (CVE-2019-9515)</p>
<p>* HTTP/2: 0-length headers lead to denial of service (CVE-2019-9516)</p>
<p>* HTTP/2: request for large response leads to denial of service (CVE-2019-9517)</p>
<p>* HTTP/2: flood using empty frames results in excessive resource consumption (CVE-2019-9518)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:2925"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-02995</id>
    <title>bdu:2019-02995</title>
    <updated>2026-10-02T19:32:29.873529+00:00</updated>
    <content>bdu:2019-02995</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-02995"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2019-9514</id>
    <title>Withdrawn: BELL-CVE-2019-9514 — CVE-2019-9514 does not affect BellSoft software</title>
    <updated>2026-10-02T19:32:29.873556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2019-9514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2019-avi-388</id>
    <title>certfr-2019-avi-388 — De multiples vulnérabilités ont été découvertes dans Apple SwiftNIO.
Elles permettent à un attaquant de provoquer un dé…</title>
    <updated>2026-10-02T19:32:29.873573+00:00</updated>
    <content>certfr-2019-avi-388</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2019-avi-388"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-af65508</id>
    <title>CLEANSTART-2025-AF65508 — Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service</title>
    <updated>2026-10-02T19:32:29.873589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: containerd</p>
<p>Security vulnerability affects the containerd package. Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-af65508"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-52957</id>
    <title>EUVD-2026-52957</title>
    <updated>2026-10-02T19:32:29.873611+00:00</updated>
    <content>EUVD-2026-52957</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-52957"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-9514</id>
    <title>fkie_cve-2019-9514</title>
    <updated>2026-10-02T19:32:29.873623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-9514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-39qc-96h7-956f</id>
    <title>GHSA-39qc-96h7-956f — golang.org/x/net/http vulnerable to a reset flood</title>
    <updated>2026-10-02T19:32:29.873646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: golang.org/x/net</p>
<p>Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. Servers that accept direct connections from untrusted clients could be remotely made to allocate an unlimited amount of memory, until the program crashes. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.</p>
<p>### Specific Go Packages Affected
golang.org/x/net/http2</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-39qc-96h7-956f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-9514</id>
    <title>gsd-2019-9514</title>
    <updated>2026-10-02T19:32:29.873669+00:00</updated>
    <content>gsd-2019-9514</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-9514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1052</id>
    <title>OESA-2025-1052 — podman security update</title>
    <updated>2026-10-02T19:32:29.873680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: podman</p>
<p>Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.

Security Fix(es):

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.(CVE-2019-9514)

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)

Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request&amp;apos;s Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.(CVE-2022-2880)

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1052"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2019:2000-1</id>
    <title>openSUSE-SU-2019:2000-1 — Security update for go1.12</title>
    <updated>2026-10-02T19:32:29.873719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.12</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2019:2000-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2019:2819</id>
    <title>RHBA-2019:2819 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.1.17 packages update</title>
    <updated>2026-10-02T19:32:29.873738+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>HTTP/2: flood using PING frames results in unbounded memory growth HTTP/2: flood using HEADERS frames results in unbounded memory growth</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2019:2819"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2024-0003</id>
    <title>RUSTSEC-2024-0003 — Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)</title>
    <updated>2026-10-02T19:32:29.873757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: h2</p>
<p>An attacker with an HTTP/2 connection to an affected endpoint can send a steady stream of invalid frames to force the
generation of reset frames on the victim endpoint.
By closing their recv window, the attacker could then force these resets to be queued in an unbounded fashion,
resulting in Out Of Memory (OOM) and high CPU usage.</p>
<p>This fix is corrected in [hyperium/h2#737](https://github.com/hyperium/h2/pull/737), which limits the total number of
internal error resets emitted by default before the connection is closed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2024-0003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2019:14246-1</id>
    <title>SUSE-SU-2019:14246-1 — Security update for Mozilla Firefox</title>
    <updated>2026-10-02T19:32:29.873777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for Mozilla Firefox</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2019:14246-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-9514</id>
    <title>UBUNTU-CVE-2019-9514</title>
    <updated>2026-10-02T19:32:29.873854+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: golang-1.10, Ubuntu:Pro:14.04:LTS: nodejs, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:16.04:LTS: golang-google-grpc, Ubuntu:16.04:LTS: grpc, Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:16.04:LTS: trafficserver, Ubuntu:18.04:LTS: twisted, Ubuntu:18.04:LTS: golang-1.10 and 19 more</p>
<p>Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-9514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770</id>
    <title>WID-SEC-W-2022-0770 — IBM DB2: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:32:29.873906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um seine Privilegien zu erhöhen oder einen Denial of Service zu verursachen</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0770"/>
  </entry>
</feed>
