<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:48:30.160403+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:2161</id>
    <title>ALSA-2023:2161 — Moderate: fence-agents security and bug fix update</title>
    <updated>2026-10-02T23:48:30.180559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: fence-agents-aliyun, AlmaLinux:9: fence-agents-all, AlmaLinux:9: fence-agents-amt-ws, AlmaLinux:9: fence-agents-apc, AlmaLinux:9: fence-agents-apc-snmp, AlmaLinux:9: fence-agents-aws, AlmaLinux:9: fence-agents-azure-arm, AlmaLinux:9: fence-agents-bladecenter, AlmaLinux:9: fence-agents-brocade, AlmaLinux:9: fence-agents-cisco-mds and 45 more</p>
<p>The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.</p>
<p>Security Fix(es):</p>
<p>* python-oauthlib: DoS when attacker provides malicious IPV6 URI (CVE-2022-36087)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:2161"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-09877</id>
    <title>bdu:2025-09877</title>
    <updated>2026-10-02T23:48:30.180675+00:00</updated>
    <content>bdu:2025-09877</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-09877"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2022-36087</id>
    <title>BREW-ansible-CVE-2022-36087 — OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI</title>
    <updated>2026-10-02T23:48:30.180693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>### Impact
- Attacker providing malicious redirect uri can cause DoS to oauthlib's web application.
- Attacker can also leverage usage of `uri_validate` functions depending where it is used.</p>
<p>_What kind of vulnerability is it? Who is impacted?_</p>
<p>Oauthlib applications using OAuth2.0 provider support or use directly `uri_validate` function.</p>
<p>### Patches
_Has the problem been patched? What versions should users upgrade to?_</p>
<p>Issue fixed in 3.2.2 release.</p>
<p>### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_</p>
<p>The `redirect_uri` can be verified in web toolkit (i.e `bottle-oauthlib`, `django-oauth-toolkit`, ...) before oauthlib is called. A sample check if `:` is present to reject the request can prevent the DoS, assuming no port or IPv6 is fundamentally required.</p>
<p>### References
Attack Vector:
- Attacker providing malicious redirect uri:
https://github.com/oauthlib/oauthlib/blob/d4bafd9f1d0eba3766e933b1ac598cbbf37b8914/oauthlib/oauth2/rfc6749/grant_types/base.py#L232
- Vulnerable `uri_validate` functions:
https://github.com/oauthlib/oauthlib/blob/2b8a44855a51ad5a5b0c348a08c2564a2e197ea2/oauthlib/uri_validate.py</p>
<p>### PoC
```python
is_absolute_uri("http://[:::::::::::::::::::::::::::::::::::::::]/path")
```</p>
<p>### Acknowledgement
Special thanks to Sebastian Chnelik - PyUp.io</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2022-36087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</id>
    <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-02T23:48:30.180730+00:00</updated>
    <content>certfr-2025-avi-0969</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232621</id>
    <title>EUVD-2026-232621</title>
    <updated>2026-10-02T23:48:30.180747+00:00</updated>
    <content>EUVD-2026-232621</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232621"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36087</id>
    <title>fkie_cve-2022-36087</title>
    <updated>2026-10-02T23:48:30.180759+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly `uri_validate` are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-36087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3pgj-pg6c-r5p7</id>
    <title>GHSA-3pgj-pg6c-r5p7 — OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI</title>
    <updated>2026-10-02T23:48:30.180781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: oauthlib</p>
<p>### Impact
- Attacker providing malicious redirect uri can cause DoS to oauthlib's web application.
- Attacker can also leverage usage of `uri_validate` functions depending where it is used.</p>
<p>_What kind of vulnerability is it? Who is impacted?_</p>
<p>Oauthlib applications using OAuth2.0 provider support or use directly `uri_validate` function.</p>
<p>### Patches
_Has the problem been patched? What versions should users upgrade to?_</p>
<p>Issue fixed in 3.2.2 release.</p>
<p>### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_</p>
<p>The `redirect_uri` can be verified in web toolkit (i.e `bottle-oauthlib`, `django-oauth-toolkit`, ...) before oauthlib is called. A sample check if `:` is present to reject the request can prevent the DoS, assuming no port or IPv6 is fundamentally required.</p>
<p>### References
Attack Vector:
- Attacker providing malicious redirect uri:
https://github.com/oauthlib/oauthlib/blob/d4bafd9f1d0eba3766e933b1ac598cbbf37b8914/oauthlib/oauth2/rfc6749/grant_types/base.py#L232
- Vulnerable `uri_validate` functions:
https://github.com/oauthlib/oauthlib/blob/2b8a44855a51ad5a5b0c348a08c2564a2e197ea2/oauthlib/uri_validate.py</p>
<p>### PoC
```python
is_absolute_uri("http://[:::::::::::::::::::::::::::::::::::::::]/path")
```</p>
<p>### Acknowledgement
Special thanks to Sebastian Chnelik - PyUp.io</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3pgj-pg6c-r5p7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-36087</id>
    <title>gsd-2022-36087</title>
    <updated>2026-10-02T23:48:30.180814+00:00</updated>
    <content>gsd-2022-36087</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-36087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1971</id>
    <title>OESA-2022-1971 — python-oauthlib security update</title>
    <updated>2026-10-02T23:48:30.180825+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS: python-oauthlib</p>
<p>Security Fix(es):

OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly `uri_validate` are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.(CVE-2022-36087)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1971"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12339-1</id>
    <title>openSUSE-SU-2024:12339-1 — python310-oauthlib-3.2.1-1.1 on GA media</title>
    <updated>2026-10-02T23:48:30.180853+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-oauthlib-3.2.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12339-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2022-269</id>
    <title>PYSEC-2022-269</title>
    <updated>2026-10-02T23:48:30.180871+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: oauthlib</p>
<p>OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly `uri_validate` are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2022-269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36087</id>
    <title>UBUNTU-CVE-2022-36087</title>
    <updated>2026-10-02T23:48:30.180891+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: python-oauthlib</p>
<p>OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly `uri_validate` are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2378</id>
    <title>WID-SEC-W-2022-2378 — IBM Spectrum Protect: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T23:48:30.180910+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in IBM Spectrum Protect ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2378"/>
  </entry>
</feed>
