<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T05:48:38.007579+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:6712</id>
    <title>ALSA-2023:6712 — Moderate: python-wheel security update</title>
    <updated>2026-10-04T05:48:38.059430+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: python3-wheel, AlmaLinux:9: python3-wheel-wheel</p>
<p>Wheel is the reference implementation of the Python wheel packaging standard, as defined in PEP 427.</p>
<p>Security Fix(es):</p>
<p>* python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli (CVE-2022-40898)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:6712"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-08101</id>
    <title>bdu:2023-08101</title>
    <updated>2026-10-04T05:48:38.059501+00:00</updated>
    <content>bdu:2023-08101</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-08101"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-bzt-cve-2022-40898</id>
    <title>BREW-bzt-CVE-2022-40898 — pypa/wheel vulnerable to Regular Expression denial of service (ReDoS)</title>
    <updated>2026-10-04T05:48:38.059519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: bzt</p>
<p>Python Packaging Authority (PyPA) Wheel is a reference implementation of the Python wheel packaging standard. Wheel 0.37.1 and earlier are vulnerable to a Regular Expression denial of service via attacker controlled input to the wheel cli. The vulnerable regex is used to verify the validity of Wheel file names. This has been patched in version 0.38.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-bzt-cve-2022-40898"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0272</id>
    <title>certfr-2023-avi-0272 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
    <updated>2026-10-04T05:48:38.059541+00:00</updated>
    <content>certfr-2023-avi-0272</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0272"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-230114</id>
    <title>EUVD-2026-230114</title>
    <updated>2026-10-04T05:48:38.059557+00:00</updated>
    <content>EUVD-2026-230114</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-230114"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-40898</id>
    <title>fkie_cve-2022-40898</title>
    <updated>2026-10-04T05:48:38.059568+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-40898"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qwmp-2cf2-g9g6</id>
    <title>GHSA-qwmp-2cf2-g9g6 — pypa/wheel vulnerable to Regular Expression denial of service (ReDoS)</title>
    <updated>2026-10-04T05:48:38.059588+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: wheel</p>
<p>Python Packaging Authority (PyPA) Wheel is a reference implementation of the Python wheel packaging standard. Wheel 0.37.1 and earlier are vulnerable to a Regular Expression denial of service via attacker controlled input to the wheel cli. The vulnerable regex is used to verify the validity of Wheel file names. This has been patched in version 0.38.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qwmp-2cf2-g9g6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-40898</id>
    <title>gsd-2022-40898</title>
    <updated>2026-10-04T05:48:38.059608+00:00</updated>
    <content>gsd-2022-40898</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-40898"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-40898</id>
    <title>msrc_CVE-2022-40898 — An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a de…</title>
    <updated>2026-10-04T05:48:38.059618+00:00</updated>
    <content>msrc_CVE-2022-40898</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-40898"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1904</id>
    <title>OESA-2023-1904 — python-wheel security update</title>
    <updated>2026-10-04T05:48:38.059633+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: python-wheel, openEuler:20.03-LTS-SP3: python-wheel, openEuler:22.03-LTS: python-wheel, openEuler:22.03-LTS-SP1: python-wheel, openEuler:22.03-LTS-SP2: python-wheel</p>
<p>A built-package format for Python. A wheel is a ZIP-format archive with a specially formatted filename and the .whl extension. It is designed to contain all the files for a PEP 376 compatible install in a way that is very close to the on-disk format.

Security Fix(es):

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.(CVE-2022-40898)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1904"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12645-1</id>
    <title>openSUSE-SU-2024:12645-1 — python310-ciscoconfparse-1.7.7-1.1 on GA media</title>
    <updated>2026-10-04T05:48:38.059659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-ciscoconfparse-1.7.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12645-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2022-43017</id>
    <title>PYSEC-2022-43017</title>
    <updated>2026-10-04T05:48:38.059674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: wheel</p>
<p>An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2022-43017"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:6793</id>
    <title>RHSA-2023:6793 — Red Hat Security Advisory: rh-python38-python security update</title>
    <updated>2026-10-04T05:48:38.059691+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python: tarfile module directory traversal pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli python: CPU denial of service via inefficient IDNA decoder python-cryptography: memory corruption via immutable objects python: urllib.parse url blocklisting bypass python-requests: Unintended leak of Proxy-Authorization header python: TLS handshake bypass</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:6793"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2023:6712</id>
    <title>RLSA-2023:6712 — Moderate: python-wheel security update</title>
    <updated>2026-10-04T05:48:38.059714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: python-wheel</p>
<p>Wheel is the reference implementation of the Python wheel packaging standard, as defined in PEP 427.</p>
<p>Security Fix(es):</p>
<p>* python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli (CVE-2022-40898)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the Rocky Linux 9.3 Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2023:6712"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:0088-2</id>
    <title>SUSE-SU-2023:0088-2 — Security update for python-wheel</title>
    <updated>2026-10-04T05:48:38.059736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-wheel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:0088-2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-40898</id>
    <title>UBUNTU-CVE-2022-40898</title>
    <updated>2026-10-04T05:48:38.059749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:14.04:LTS: wheel, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:16.04:LTS: wheel, Ubuntu:18.04:LTS: python-pip, Ubuntu:18.04:LTS: wheel, Ubuntu:20.04:LTS: python-pip, Ubuntu:20.04:LTS: wheel, Ubuntu:22.04:LTS: python-pip, Ubuntu:22.04:LTS: wheel</p>
<p>An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-40898"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1424</id>
    <title>WID-SEC-W-2023-1424 — Xerox FreeFlow Print Server für Solaris: Mehrere Schwachstellen</title>
    <updated>2026-10-04T05:48:38.059777+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1424"/>
  </entry>
</feed>
