<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:08:34.988747+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:6346</id>
    <title>ALSA-2023:6346 — Moderate: toolbox security and bug fix update</title>
    <updated>2026-10-02T22:08:35.535770+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: toolbox, AlmaLinux:9: toolbox-tests</p>
<p>Toolbox is a tool for Linux operating systems, which allows the use of containerized command line environments. It is built on top of Podman and other standard container technologies from OCI.</p>
<p>Security Fix(es):</p>
<p>* go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)
* golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540)
* net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)
* golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)
* golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534)
* golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536)
* golang: html/template: backticks not treated as string delimiters (CVE-2023-24538)
* golang: html/template: improper sanitization of CSS values (CVE-2023-24539)
* golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400)
* golang: net/http: insufficient sanitization of Host header (CVE-2023-29406)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References se…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:6346"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ki12594</id>
    <title>Withdrawn: CLEANSTART-2026-KI12594 — Security fixes in cluster-proportional-autoscaler 1.7.1-r0</title>
    <updated>2026-10-02T22:08:35.535866+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cluster-proportional-autoscaler</p>
<p>Package cluster-proportional-autoscaler version 1.7.1-r0 fixes 7 vulnerabilities: CVE-2021-3121, CVE-2022-3064, CVE-2020-8559, CVE-2019-11254, CVE-2019-11250...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ki12594"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-229054</id>
    <title>EUVD-2026-229054</title>
    <updated>2026-10-02T22:08:35.535893+00:00</updated>
    <content>EUVD-2026-229054</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-229054"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-3064</id>
    <title>fkie_cve-2022-3064</title>
    <updated>2026-10-02T22:08:35.535908+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-3064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6q6q-88xp-6f2r</id>
    <title>GHSA-6q6q-88xp-6f2r — yaml package for Go can consume excessive amounts of CPU or memory</title>
    <updated>2026-10-02T22:08:35.535929+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: gopkg.in/yaml.v2</p>
<p>Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6q6q-88xp-6f2r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-3064</id>
    <title>gsd-2022-3064</title>
    <updated>2026-10-02T22:08:35.535949+00:00</updated>
    <content>gsd-2022-3064</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-3064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-3064</id>
    <title>msrc_CVE-2022-3064 — Excessive resource consumption in gopkg.in/yaml.v2</title>
    <updated>2026-10-02T22:08:35.535960+00:00</updated>
    <content>msrc_CVE-2022-3064</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-3064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1168</id>
    <title>OESA-2025-1168 — etcd security update</title>
    <updated>2026-10-02T22:08:35.535976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: etcd</p>
<p>%{expand:

Security Fix(es):</p>
<p>Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.(CVE-2021-28235)</p>
<p>Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.(CVE-2022-3064)</p>
<p>Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor&amp;apos;s position is that this is not a vulnerability.(CVE-2022-34038)</p>
<p>A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.(CVE-2022-41723)</p>
<p>etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) associated to a lease when `Keys` parameter is true, even a user doesn&amp;apos;t have read permission to the keys. The impact is limited to a cluster which enables auth (RBAC). Versions 3.4.26 and 3.5.9 fix this issue. There are no known workarounds.(CVE-2023-32082)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:0698</id>
    <title>RHSA-2023:0698 — Red Hat Security Advisory: OpenShift Container Platform 4.10.52 security update</title>
    <updated>2026-10-02T22:08:35.536006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:0698"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-3064</id>
    <title>UBUNTU-CVE-2022-3064</title>
    <updated>2026-10-02T22:08:35.536024+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: golang-yaml.v2, Ubuntu:Pro:18.04:LTS: golang-yaml.v2, Ubuntu:Pro:18.04:LTS: singularity-container, Ubuntu:18.04:LTS: webhook, Ubuntu:20.04:LTS: golang-yaml.v2, Ubuntu:20.04:LTS: golang-github-coreos-discovery-etcd-io, Ubuntu:20.04:LTS: webhook, Ubuntu:22.04:LTS: golang-github-coreos-discovery-etcd-io, Ubuntu:22.04:LTS: webhook, Ubuntu:24.04:LTS: golang-github-coreos-discovery-etcd-io and 8 more</p>
<p>Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-3064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0468</id>
    <title>WID-SEC-W-2023-0468 — Red Hat OpenShift: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T22:08:35.536066+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0468"/>
  </entry>
</feed>
