<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:44:02.303322+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00351</id>
    <title>bdu:2022-00351</title>
    <updated>2026-10-03T07:44:02.646352+00:00</updated>
    <content>bdu:2022-00351</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00351"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-3618</id>
    <title>Withdrawn: BELL-CVE-2021-3618 — CVE-2021-3618 does not affect BellSoft software</title>
    <updated>2026-10-03T07:44:02.646392+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-3618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-nginx-2021-3618</id>
    <title>BIT-nginx-2021-3618</title>
    <updated>2026-10-03T07:44:02.646412+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: nginx</p>
<p>ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-nginx-2021-3618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0866</id>
    <title>certfr-2024-avi-0866 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent…</title>
    <updated>2026-10-03T07:44:02.646444+00:00</updated>
    <content>certfr-2024-avi-0866</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0866"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-em10035</id>
    <title>Withdrawn: CLEANSTART-2026-EM10035 — Security fixes in nginx 1.20.1-r1</title>
    <updated>2026-10-03T07:44:02.646460+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: nginx</p>
<p>Package nginx version 1.20.1-r1 fixes 1 vulnerabilities: CVE-2021-3618</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-em10035"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-20936</id>
    <title>EUVD-2026-20936</title>
    <updated>2026-10-03T07:44:02.646480+00:00</updated>
    <content>EUVD-2026-20936</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-20936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3618</id>
    <title>fkie_cve-2021-3618</title>
    <updated>2026-10-03T07:44:02.646492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r9r5-jxp7-whr4</id>
    <title>GHSA-r9r5-jxp7-whr4</title>
    <updated>2026-10-03T07:44:02.646515+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r9r5-jxp7-whr4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3618</id>
    <title>gsd-2021-3618</title>
    <updated>2026-10-03T07:44:02.646532+00:00</updated>
    <content>gsd-2021-3618</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3618</id>
    <title>msrc_CVE-2021-3618 — ALPACA is an application layer protocol content confusion attack exploiting TLS servers implementing different protocol…</title>
    <updated>2026-10-03T07:44:02.646543+00:00</updated>
    <content>msrc_CVE-2021-3618</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-3618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1637</id>
    <title>OESA-2022-1637 — nginx security update</title>
    <updated>2026-10-03T07:44:02.646561+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: nginx, openEuler:20.03-LTS-SP3: nginx, openEuler:22.03-LTS: nginx</p>
<p>NGINX is a free, open-source, high-performance HTTP server and reverse proxy, as well as an IMAP/POP3 proxy server.

Security Fix(es):
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.(CVE-2021-3618)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sca-2025-0009</id>
    <title>SCA-2025-0009 — Vulnerabilities affecting SICK TDC-E210GC</title>
    <updated>2026-10-03T07:44:02.646601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009. A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact. The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbitrary files in the client's download directory by creating a crafted subdirectory anywhere on the remote server. The victim must use the command scp -rp to download a file hierarchy containing, anywhere inside, this crafted subdirectory. NOTE: the vendor points out that "this attack can achieve no more than a hostile peer is already able to achieve within the scp protocol" and "utimes does not fail under normal circumstances. An unauthorized access vulnerabiitly exists in all versions of Portainer, which could let a malicious user obtain sensitive information. NOTE: Portainer has received no detail of this CVE report. There is also no response after multiple attempts of contacting the original source. In ISC DHCP 4.1-ESV-R…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sca-2025-0009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2022:0655-1</id>
    <title>SUSE-RU-2022:0655-1 — Recommended update for vsftpd</title>
    <updated>2026-10-03T07:44:02.646681+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for vsftpd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2022:0655-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3618</id>
    <title>UBUNTU-CVE-2021-3618</title>
    <updated>2026-10-03T07:44:02.646698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: nginx, Ubuntu:14.04:LTS: sendmail, Ubuntu:14.04:LTS: vsftpd, Ubuntu:Pro:16.04:LTS: nginx, Ubuntu:16.04:LTS: vsftpd, Ubuntu:16.04:LTS: sendmail, Ubuntu:18.04:LTS: nginx, Ubuntu:18.04:LTS: vsftpd, Ubuntu:18.04:LTS: sendmail, Ubuntu:20.04:LTS: nginx and 4 more</p>
<p>ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1482</id>
    <title>WID-SEC-W-2022-1482 — TLS Implementierungen: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-03T07:44:02.646738+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in verschiedenen TLS Implementierungen ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1482"/>
  </entry>
</feed>
