<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:57:12.933217+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:1702</id>
    <title>ALSA-2021:1702 — Moderate: brotli security update</title>
    <updated>2026-10-02T16:57:13.322662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: brotli, AlmaLinux:8: brotli-devel, AlmaLinux:8: python3-brotli</p>
<p>Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression.</p>
<p>Security Fix(es):</p>
<p>* brotli: buffer overflow when input chunk is larger than 2GiB (CVE-2020-8927)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:1702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-01775</id>
    <title>bdu:2021-01775</title>
    <updated>2026-10-02T16:57:13.322756+00:00</updated>
    <content>bdu:2021-01775</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-01775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-8927</id>
    <title>Withdrawn: BELL-CVE-2020-8927 — CVE-2020-8927 does not affect BellSoft software</title>
    <updated>2026-10-02T16:57:13.322780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-8927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-brotli-2020-8927</id>
    <title>BIT-brotli-2020-8927 — Buffer overflow in Brotli library</title>
    <updated>2026-10-02T16:57:13.322805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: brotli</p>
<p>A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-brotli-2020-8927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-exiftool-cve-2020-36846</id>
    <title>BREW-exiftool-CVE-2020-36846</title>
    <updated>2026-10-02T16:57:13.322845+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: exiftool</p>
<p>A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-exiftool-cve-2020-36846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</id>
    <title>certfr-2021-avi-791 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T16:57:13.322883+00:00</updated>
    <content>certfr-2021-avi-791</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-791"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-xn11840</id>
    <title>CLEANSTART-2024-XN11840 — buffer overflow exists in the Brotli library versions prior to 1</title>
    <updated>2026-10-02T16:57:13.322909+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: brotli</p>
<p>Security vulnerability affects the brotli package. A buffer overflow exists in the Brotli library versions prior to 1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-xn11840"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-323038</id>
    <title>EUVD-2026-323038</title>
    <updated>2026-10-02T16:57:13.322940+00:00</updated>
    <content>EUVD-2026-323038</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-323038"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8927</id>
    <title>fkie_cve-2020-8927</title>
    <updated>2026-10-02T16:57:13.322959+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-8927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5v8v-66v8-mwm7</id>
    <title>GHSA-5v8v-66v8-mwm7 — Integer overflow in the bundled Brotli C library</title>
    <updated>2026-10-02T16:57:13.322998+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: compu-brotli-sys, NuGet: Microsoft.NETCore.App.Runtime.linux-arm, NuGet: Microsoft.NETCore.App.Runtime.linux-arm64, NuGet: Microsoft.NETCore.App.Runtime.linux-musl-arm64, NuGet: Microsoft.NETCore.App.Runtime.linux-x64, NuGet: Microsoft.NETCore.App.Runtime.osx-x64, NuGet: Microsoft.NETCore.App.Runtime.win-arm, NuGet: Microsoft.NETCore.App.Runtime.win-arm64, NuGet: Microsoft.NETCore.App.Runtime.win-x64, NuGet: Microsoft.NETCore.App.Runtime.win-x86 and 108 more</p>
<p>A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5v8v-66v8-mwm7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-8927</id>
    <title>gsd-2020-8927</title>
    <updated>2026-10-02T16:57:13.323379+00:00</updated>
    <content>gsd-2020-8927</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-8927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1578-1</id>
    <title>openSUSE-SU-2020:1578-1 — Security update for brotli</title>
    <updated>2026-10-02T16:57:13.323395+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for brotli</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:1578-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2020-29</id>
    <title>PYSEC-2020-29</title>
    <updated>2026-10-02T16:57:13.323414+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: brotli</p>
<p>A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2020-29"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:0828</id>
    <title>RHSA-2022:0828 — Red Hat Security Advisory: .NET 5.0 on RHEL 7 security and bugfix update</title>
    <updated>2026-10-02T16:57:13.323435+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>brotli: buffer overflow when input chunk is larger than 2GiB dotnet: ASP.NET Denial of Service via FormPipeReader dotnet: double parser stack buffer overrun</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:0828"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2021-0131</id>
    <title>RUSTSEC-2021-0131 — Integer overflow in the bundled Brotli C library</title>
    <updated>2026-10-02T16:57:13.323455+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: brotli-sys</p>
<p>A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB.</p>
<p>An updated version of `brotli-sys` has not been released. If one cannot update the C library, its authors recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.</p>
<p>In Rust the issue can be mitigated by migrating to the `brotli` crate, which provides a Rust implementation of Brotli compression and decompression that is not affected by this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2021-0131"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:3942-1</id>
    <title>SUSE-SU-2021:3942-1 — Security update for brotli</title>
    <updated>2026-10-02T16:57:13.323496+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for brotli</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:3942-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8927</id>
    <title>UBUNTU-CVE-2020-8927</title>
    <updated>2026-10-02T16:57:13.323512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: brotli, Ubuntu:18.04:LTS: brotli, Ubuntu:20.04:LTS: brotli</p>
<p>A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</id>
    <title>WID-SEC-W-2025-0227 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:57:13.323537+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227"/>
  </entry>
</feed>
