<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:46:06.956070+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05160</id>
    <title>bdu:2022-05160</title>
    <updated>2026-10-03T19:46:07.265321+00:00</updated>
    <content>bdu:2022-05160</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05160"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2022-30187</id>
    <title>BREW-azure-cli-CVE-2022-30187 — Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library</title>
    <updated>2026-10-03T19:46:07.265364+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: azure-cli</p>
<p>### Summary</p>
<p>The Azure Storage Encryption library in Java and other languages is vulnerable to a CBC Padding Oracle attack, similar to CVE-2020-8911. The library is not vulnerable to the equivalent of CVE-2020-8912, but only because it currently only supports AES-CBC as encryption mode.</p>
<p>### Severity</p>
<p>Moderate - The vulnerability poses insider risks/privilege escalation risks, circumventing controls for stored data.</p>
<p>### Further Analysis
The Java Azure Blob Storage Encryption SDK is impacted by an issue that can result in loss of confidentiality and message forgery. The attack requires write access to the container in question, and that the attacker has access to an endpoint that reveals decryption failures (without revealing the plaintext) and that when encrypting the CBC option was chosen as content cipher.</p>
<p>This advisory describes the plaintext revealing vulnerabilities in the Java Azure Blob Storage Encryption SDK, with a similar issue in the other blob storage SDKs being present as well.</p>
<p>In the current version of the Azure Blob Storage crypto SDK, the only algorithm option that allows users to encrypt files is to AES-CBC, without computing a MAC on the data.</p>
<p>This exposes a padding oracle vulnerability: If the attacker has write access to the blob container bucket and can observe whether or not an endpoint with access to the key can decrypt a file (without observing the file contents that the endpoint learns in the process), they can reconstruct the plaintext with (on…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2022-30187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-634</id>
    <title>certfr-2022-avi-634 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Microsoft Azure&lt;/span&gt;. Elles permettent à un a…</title>
    <updated>2026-10-03T19:46:07.265423+00:00</updated>
    <content>certfr-2022-avi-634</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-634"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-246779</id>
    <title>EUVD-2026-246779</title>
    <updated>2026-10-03T19:46:07.265442+00:00</updated>
    <content>EUVD-2026-246779</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-246779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-30187</id>
    <title>fkie_cve-2022-30187</title>
    <updated>2026-10-03T19:46:07.265454+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Azure Storage Library Information Disclosure Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-30187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-64x4-9hc6-r2h6</id>
    <title>GHSA-64x4-9hc6-r2h6 — Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library</title>
    <updated>2026-10-03T19:46:07.265475+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: Azure.Storage.Queues, NuGet: Azure.Storage.Blobs, Maven: com.azure:azure-storage-blob, PyPI: azure-storage-queue, PyPI: azure-storage-blob</p>
<p>### Summary</p>
<p>The Azure Storage Encryption library in Java and other languages is vulnerable to a CBC Padding Oracle attack, similar to CVE-2020-8911. The library is not vulnerable to the equivalent of CVE-2020-8912, but only because it currently only supports AES-CBC as encryption mode.</p>
<p>### Severity</p>
<p>Moderate - The vulnerability poses insider risks/privilege escalation risks, circumventing controls for stored data.</p>
<p>### Further Analysis
The Java Azure Blob Storage Encryption SDK is impacted by an issue that can result in loss of confidentiality and message forgery. The attack requires write access to the container in question, and that the attacker has access to an endpoint that reveals decryption failures (without revealing the plaintext) and that when encrypting the CBC option was chosen as content cipher.</p>
<p>This advisory describes the plaintext revealing vulnerabilities in the Java Azure Blob Storage Encryption SDK, with a similar issue in the other blob storage SDKs being present as well.</p>
<p>In the current version of the Azure Blob Storage crypto SDK, the only algorithm option that allows users to encrypt files is to AES-CBC, without computing a MAC on the data.</p>
<p>This exposes a padding oracle vulnerability: If the attacker has write access to the blob container bucket and can observe whether or not an endpoint with access to the key can decrypt a file (without observing the file contents that the endpoint learns in the process), they can reconstruct the plaintext with (on…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-64x4-9hc6-r2h6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-30187</id>
    <title>gsd-2022-30187</title>
    <updated>2026-10-03T19:46:07.265529+00:00</updated>
    <content>gsd-2022-30187</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-30187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-30187</id>
    <title>msrc_CVE-2022-30187 — Azure Storage Library Information Disclosure Vulnerability</title>
    <updated>2026-10-03T19:46:07.265545+00:00</updated>
    <content>msrc_CVE-2022-30187</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-30187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12283-1</id>
    <title>openSUSE-SU-2024:12283-1 — python310-azure-storage-blob-12.13.1-2.1 on GA media</title>
    <updated>2026-10-03T19:46:07.265563+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-azure-storage-blob-12.13.1-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12283-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2388</id>
    <title>PYSEC-2026-2388 — Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library</title>
    <updated>2026-10-03T19:46:07.265580+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: azure-storage-queue</p>
<p>### Summary</p>
<p>The Azure Storage Encryption library in Java and other languages is vulnerable to a CBC Padding Oracle attack, similar to CVE-2020-8911. The library is not vulnerable to the equivalent of CVE-2020-8912, but only because it currently only supports AES-CBC as encryption mode.</p>
<p>### Severity</p>
<p>Moderate - The vulnerability poses insider risks/privilege escalation risks, circumventing controls for stored data.</p>
<p>### Further Analysis
The Java Azure Blob Storage Encryption SDK is impacted by an issue that can result in loss of confidentiality and message forgery. The attack requires write access to the container in question, and that the attacker has access to an endpoint that reveals decryption failures (without revealing the plaintext) and that when encrypting the CBC option was chosen as content cipher.</p>
<p>This advisory describes the plaintext revealing vulnerabilities in the Java Azure Blob Storage Encryption SDK, with a similar issue in the other blob storage SDKs being present as well.</p>
<p>In the current version of the Azure Blob Storage crypto SDK, the only algorithm option that allows users to encrypt files is to AES-CBC, without computing a MAC on the data.</p>
<p>This exposes a padding oracle vulnerability: If the attacker has write access to the blob container bucket and can observe whether or not an endpoint with access to the key can decrypt a file (without observing the file contents that the endpoint learns in the process), they can reconstruct the plaintext with (on…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2388"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:4215</id>
    <title>RHSA-2026:4215 — Red Hat Security Advisory: Red Hat Quay 3.14.6</title>
    <updated>2026-10-03T19:46:07.265616+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion requests: Requests vulnerable to .netrc credentials leak via malicious URLs node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications qs: qs: Denial of Service via improper input validation in array parsing setuptools: Path Traversal Vulnerability in setuptools PackageIndex golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects golang: archive/tar: Unbounded allocation when parsing GNU sparse map axios: Axios DoS via lack of data size check authlib: Authlib RFC violation crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate authlib: Authlib Denial of Service node-jws: auth0/node-jws: Improper signature verification in HS256 algorithm urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redi…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:4215"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:4609-1</id>
    <title>SUSE-SU-2023:4609-1 — Security update for python-azure-storage-queue</title>
    <updated>2026-10-03T19:46:07.265676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-azure-storage-queue</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:4609-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30187</id>
    <title>UBUNTU-CVE-2022-30187</title>
    <updated>2026-10-03T19:46:07.265693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: python-azure-storage, Ubuntu:20.04:LTS: python-azure-storage, Ubuntu:22.04:LTS: python-azure</p>
<p>Azure Storage Library Information Disclosure Vulnerability</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-30187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0654</id>
    <title>WID-SEC-W-2022-0654 — Microsoft Azure Site Recovery und Azure Storage: Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:46:07.265714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Microsoft Azure Site Recovery und Azure Storage ausnutzen, um seine Privilegien zu erhöhen, Informationen offenzulegen oder beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0654"/>
  </entry>
</feed>
