<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:32:00.445800+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05841</id>
    <title>bdu:2023-05841</title>
    <updated>2026-10-02T20:32:00.949048+00:00</updated>
    <content>bdu:2023-05841</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1040</id>
    <title>certfr-2022-avi-1040 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
Protect. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T20:32:00.949124+00:00</updated>
    <content>certfr-2022-avi-1040</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-1040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-ik84393</id>
    <title>CLEANSTART-2024-IK84393 — attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take signif…</title>
    <updated>2026-10-02T20:32:00.949159+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: docker-cli-compose, CleanStart: gitea</p>
<p>CVE-2022-32149 affects multiple packages. An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-ik84393"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-239726</id>
    <title>EUVD-2026-239726</title>
    <updated>2026-10-02T20:32:00.949208+00:00</updated>
    <content>EUVD-2026-239726</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-239726"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-32149</id>
    <title>fkie_cve-2022-32149</title>
    <updated>2026-10-02T20:32:00.949228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-32149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-69ch-w2m2-3vjp</id>
    <title>GHSA-69ch-w2m2-3vjp — golang.org/x/text/language Denial of service via crafted Accept-Language header</title>
    <updated>2026-10-02T20:32:00.949264+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: golang.org/x/text</p>
<p>The BCP 47 tag parser has quadratic time complexity due to inherent aspects of its design. Since the parser is, by design, exposed to untrusted user input, this can be leveraged to force a program to consume significant time parsing Accept-Language headers. The parser cannot be easily rewritten to fix this behavior for various reasons. Instead the solution implemented in this CL is to limit the total complexity of tags passed into ParseAcceptLanguage by limiting the number of dashes in the string to 1000. This should be more than enough for the majority of real world use cases, where the number of tags being sent is likely to be in the single digits.</p>
<p>### Specific Go Packages Affected
golang.org/x/text/language</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-69ch-w2m2-3vjp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-32149</id>
    <title>gsd-2022-32149</title>
    <updated>2026-10-02T20:32:00.949309+00:00</updated>
    <content>gsd-2022-32149</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-32149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-32149</id>
    <title>msrc_CVE-2022-32149 — Denial of service via crafted Accept-Language header in golang.org/x/text/language</title>
    <updated>2026-10-02T20:32:00.949327+00:00</updated>
    <content>msrc_CVE-2022-32149</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-32149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1527</id>
    <title>OESA-2024-1527 — podman security update</title>
    <updated>2026-10-02T20:32:00.949353+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP2: podman</p>
<p>Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.

Security Fix(es):

An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.(CVE-2022-32149)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12426-1</id>
    <title>openSUSE-SU-2024:12426-1 — starboard-0.15.11-1.1 on GA media</title>
    <updated>2026-10-02T20:32:00.949386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>starboard-0.15.11-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12426-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2023:4275</id>
    <title>RHBA-2023:4275 — Red Hat Bug Fix Advisory: Red Hat Quay v3.8.11 bug fix release</title>
    <updated>2026-10-02T20:32:00.949412+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/http: handle server errors after sending GOAWAY golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags golang: net/url: JoinPath does not strip relative path components in all circumstances golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values golang: html/template: improper handling of JavaScript whitespace golang: html/template: improper handling of empty HTML attributes</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2023:4275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2023-3875</id>
    <title>SUSE-EL-9-CLIENT-TOOLS-2023-3875 — Security update for SUSE Manager Client Tools</title>
    <updated>2026-10-02T20:32:00.949473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for SUSE Manager Client Tools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2023-3875"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-32149</id>
    <title>UBUNTU-CVE-2022-32149</title>
    <updated>2026-10-02T20:32:00.949502+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: golang-x-text, Ubuntu:18.04:LTS: golang-x-text, Ubuntu:20.04:LTS: golang-golang-x-text, Ubuntu:20.04:LTS: golang-x-text, Ubuntu:22.04:LTS: golang-golang-x-text</p>
<p>An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-32149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2134</id>
    <title>WID-SEC-W-2022-2134 — IBM Spectrum Protect: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:32:00.949566+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes and Red Hat OpenShift ausnutzen, um einen Cross site Scripting Angriff durchzuführen, Informationen offenzulegen oder einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2134"/>
  </entry>
</feed>
