<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:36:39.277967+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:3083</id>
    <title>ALSA-2023:3083 — Moderate: go-toolset:rhel8 security and bug fix update</title>
    <updated>2026-10-03T13:36:40.164289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: delve, AlmaLinux:8: go-toolset, AlmaLinux:8: golang, AlmaLinux:8: golang-bin, AlmaLinux:8: golang-docs, AlmaLinux:8: golang-misc, AlmaLinux:8: golang-race, AlmaLinux:8: golang-src, AlmaLinux:8: golang-tests</p>
<p>Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.</p>
<p>Security Fix(es):</p>
<p>* golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724)
* golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* Backport fix for https://github.com/golang/go/issues/56891 (BZ#2167412)
* Update Go to 1.19.6 (BZ#2174430)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:3083"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-03152</id>
    <title>bdu:2024-03152</title>
    <updated>2026-10-03T13:36:40.164408+00:00</updated>
    <content>bdu:2024-03152</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-03152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-41724</id>
    <title>Withdrawn: BELL-CVE-2022-41724 — CVE-2022-41724 does not affect BellSoft software</title>
    <updated>2026-10-03T13:36:40.164427+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-41724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2022-41724</id>
    <title>BIT-golang-2022-41724 — Panic on large handshake records in crypto/tls</title>
    <updated>2026-10-03T13:36:40.164443+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &gt;= RequestClientCert).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2022-41724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0272</id>
    <title>certfr-2023-avi-0272 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
    <updated>2026-10-03T13:36:40.164467+00:00</updated>
    <content>certfr-2023-avi-0272</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0272"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-221298</id>
    <title>EUVD-2026-221298</title>
    <updated>2026-10-03T13:36:40.164484+00:00</updated>
    <content>EUVD-2026-221298</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-221298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41724</id>
    <title>fkie_cve-2022-41724</title>
    <updated>2026-10-03T13:36:40.164495+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &gt;= RequestClientCert).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-41724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-89mw-w342-mqrr</id>
    <title>GHSA-89mw-w342-mqrr</title>
    <updated>2026-10-03T13:36:40.164518+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &gt;= RequestClientCert).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-89mw-w342-mqrr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-41724</id>
    <title>gsd-2022-41724</title>
    <updated>2026-10-03T13:36:40.164535+00:00</updated>
    <content>gsd-2022-41724</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-41724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-41724</id>
    <title>msrc_CVE-2022-41724 — Panic on large handshake records in crypto/tls</title>
    <updated>2026-10-03T13:36:40.164546+00:00</updated>
    <content>msrc_CVE-2022-41724</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-41724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1192</id>
    <title>OESA-2023-1192 — golang security update</title>
    <updated>2026-10-03T13:36:40.164574+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: golang, openEuler:20.03-LTS-SP3: golang, openEuler:22.03-LTS: golang, openEuler:22.03-LTS-SP1: golang</p>
<p>The Go Programming Language.



Security Fix(es):

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.(CVE-2022-41723)

Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &amp;gt;= RequestClientCert).(CVE-2022-41724)

A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. ReadForm takes a maxMemory parameter, and is documented as storing &amp;quot;up to maxMemory bytes +10MB (reserved for non-file parts) in memory&amp;quot;. File parts which cannot be stored in memory are stored on disk in temporary files. The unconfigurable 10MB reserved for non-file parts is excessively large and can potentially open a denial of service vector on its own. However, ReadForm did…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1192"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12707-1</id>
    <title>openSUSE-SU-2024:12707-1 — go1.19-1.19.6-1.1 on GA media</title>
    <updated>2026-10-03T13:36:40.164647+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go1.19-1.19.6-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12707-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2023:4275</id>
    <title>RHBA-2023:4275 — Red Hat Bug Fix Advisory: Red Hat Quay v3.8.11 bug fix release</title>
    <updated>2026-10-03T13:36:40.164682+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/http: handle server errors after sending GOAWAY golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags golang: net/url: JoinPath does not strip relative path components in all circumstances golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values golang: html/template: improper handling of JavaScript whitespace golang: html/template: improper handling of empty HTML attributes</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2023:4275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41724</id>
    <title>UBUNTU-CVE-2022-41724</title>
    <updated>2026-10-03T13:36:40.164749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.13, Ubuntu:20.04:LTS: golang-1.14, Ubuntu:Pro:20.04:LTS: golang-1.16, Ubuntu:22.04:LTS: golang-1.17 and 2 more</p>
<p>Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &gt;= RequestClientCert).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0523</id>
    <title>WID-SEC-W-2023-0523 — IBM DataPower Gateway: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T13:36:40.164790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in IBM DataPower Gateway ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0523"/>
  </entry>
</feed>
