<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:39:16.341728+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03823</id>
    <title>bdu:2023-03823</title>
    <updated>2026-10-03T13:39:17.103691+00:00</updated>
    <content>bdu:2023-03823</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03823"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-363</id>
    <title>certfr-2022-avi-363 — De multiples vulnérabilités ont été découvertes dans Oracle Database
Server. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T13:39:17.103759+00:00</updated>
    <content>certfr-2022-avi-363</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-363"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ju62349</id>
    <title>Withdrawn: CLEANSTART-2026-JU62349 — Security fixes for CVE-2018-10237, CVE-2020-8908, CVE-2021-22569, CVE-2021-22570, CVE-2022-3171, CVE-2022-3509, CVE-202…</title>
    <updated>2026-10-03T13:39:17.103782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-hive</p>
<p>Multiple security vulnerabilities affect the apache-hive package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ju62349"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232104</id>
    <title>EUVD-2026-232104</title>
    <updated>2026-10-03T13:39:17.103819+00:00</updated>
    <content>EUVD-2026-232104</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232104"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22569</id>
    <title>fkie_cve-2021-22569</title>
    <updated>2026-10-03T13:39:17.103832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-22569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wrvw-hg22-4m67</id>
    <title>GHSA-wrvw-hg22-4m67 — A potential Denial of Service issue in protobuf-java</title>
    <updated>2026-10-03T13:39:17.103855+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.google.protobuf:protobuf-java, RubyGems: google-protobuf, Maven: com.google.protobuf:protobuf-kotlin</p>
<p>## Summary</p>
<p>A potential Denial of Service issue in protobuf-java was discovered in the parsing procedure for binary data.</p>
<p>Reporter: [OSS-Fuzz](https://github.com/google/oss-fuzz)</p>
<p>Affected versions: All versions of Java Protobufs (including Kotlin and JRuby) prior to the versions listed below. Protobuf "javalite" users (typically Android) are not affected.</p>
<p>## Severity</p>
<p>[CVE-2021-22569](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22569) **High** - CVSS Score: 7.5,  An implementation weakness in how unknown fields are parsed in Java. A small (~800 KB) malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated GC pauses.</p>
<p>## Proof of Concept</p>
<p>For reproduction details, please refer to the oss-fuzz issue that identifies the specific inputs that exercise this parsing weakness.</p>
<p>## Remediation and Mitigation</p>
<p>Please update to the latest available versions of the following packages:</p>
<p>- protobuf-java (3.16.1, 3.18.2, 3.19.2) 
- protobuf-kotlin (3.18.2, 3.19.2)
- google-protobuf [JRuby  gem only] (3.19.2)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wrvw-hg22-4m67"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-22569</id>
    <title>gsd-2021-22569</title>
    <updated>2026-10-03T13:39:17.103899+00:00</updated>
    <content>gsd-2021-22569</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-22569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-22569</id>
    <title>msrc_CVE-2021-22569 — Denial of Service of protobuf-java parsing procedure</title>
    <updated>2026-10-03T13:39:17.103911+00:00</updated>
    <content>msrc_CVE-2021-22569</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-22569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1694</id>
    <title>OESA-2022-1694 — protobuf security update</title>
    <updated>2026-10-03T13:39:17.103928+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS: protobuf</p>
<p>Protocol Buffers (a.k.a., protobuf) are Google&amp;apos;s language-neutral, platform-neutral, extensible mechanism for serializing structured data. You can find protobuf&amp;apos;s documentation on the Google Developers site.

Security Fix(es):

An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.(CVE-2021-22569)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1694"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:1013</id>
    <title>RHSA-2022:1013 — Red Hat Security Advisory: Red Hat Integration Camel Extensions for Quarkus 2.2.1 security update</title>
    <updated>2026-10-03T13:39:17.103952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>guava: local information disclosure via temporary directory created with unsafe permissions bouncycastle: Timing issue within the EC math library mysql-connector-java: unauthorized access to critical kubernetes-client: Insecure deserialization in unmarshalYaml method protobuf-java: potential DoS in the parsing procedure for binary data maven: Block repositories using http by default jersey: Local information disclosure via system temporary directory jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn't restrict chunk length and may buffer skippable chunks in an unnecessary way xml-security: XPath Transform abuse allows for information disclosure cron-utils: template Injection leading to unauthenticated Remote Code Execution h2: Remote Code Execution in Console</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:1013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:2783-2</id>
    <title>SUSE-SU-2023:2783-2 — Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcry…</title>
    <updated>2026-10-03T13:39:17.103993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:2783-2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22569</id>
    <title>UBUNTU-CVE-2021-22569</title>
    <updated>2026-10-03T13:39:17.104019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: protobuf, Ubuntu:Pro:16.04:LTS: protobuf, Ubuntu:18.04:LTS: protobuf, Ubuntu:20.04:LTS: protobuf, Ubuntu:22.04:LTS: protobuf</p>
<p>An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-22569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607</id>
    <title>WID-SEC-W-2022-0607 — Red Hat FUSE: Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:39:17.104045+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat FUSE ausnutzen, um vertrauliche Informationen offenzulegen, beliebigen Code auszuführen, einen Denial of Service Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten und Informationen zu manipulieren und seine Privilegien zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0607"/>
  </entry>
</feed>
