<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T20:34:15.187950+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:3275</id>
    <title>ALSA-2024:3275 — Moderate: python-dns security update</title>
    <updated>2026-10-04T20:34:15.684784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python3-dns</p>
<p>The python-dns package contains the dnslib module that implements a DNS client and additional modules that define certain symbolic constants used by DNS, such as dnstype, dnsclass and dnsopcode.</p>
<p>Security Fix(es):</p>
<p>* dnspython: denial of service in stub resolver (CVE-2023-29483)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:3275"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-03301</id>
    <title>bdu:2025-03301</title>
    <updated>2026-10-04T20:34:15.684861+00:00</updated>
    <content>bdu:2025-03301</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-03301"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2023-29483</id>
    <title>BREW-ansible-CVE-2023-29483 — Potential DoS via the Tudoor mechanism in eventlet and dnspython</title>
    <updated>2026-10-04T20:34:15.684890+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2023-29483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385</id>
    <title>certfr-2024-avi-0385 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-04T20:34:15.684939+00:00</updated>
    <content>certfr-2024-avi-0385</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0385"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258973</id>
    <title>EUVD-2026-258973</title>
    <updated>2026-10-04T20:34:15.684960+00:00</updated>
    <content>EUVD-2026-258973</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258973"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-29483</id>
    <title>fkie_cve-2023-29483</title>
    <updated>2026-10-04T20:34:15.684973+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-29483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3rq5-2g8h-59hc</id>
    <title>GHSA-3rq5-2g8h-59hc — Potential DoS via the Tudoor mechanism in eventlet and dnspython</title>
    <updated>2026-10-04T20:34:15.684997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: eventlet, PyPI: dnspython</p>
<p>eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3rq5-2g8h-59hc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-29483</id>
    <title>gsd-2023-29483</title>
    <updated>2026-10-04T20:34:15.685022+00:00</updated>
    <content>gsd-2023-29483</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-29483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1138</id>
    <title>OESA-2025-1138 — python-dns security update</title>
    <updated>2026-10-04T20:34:15.685033+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: python-dns</p>
<p>\

Security Fix(es):</p>
<p>eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a &amp;quot;TuDoor&amp;quot; attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.(CVE-2023-29483)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14047-1</id>
    <title>openSUSE-SU-2024:14047-1 — python310-eventlet-0.36.1-1.1 on GA media</title>
    <updated>2026-10-04T20:34:15.685059+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-eventlet-0.36.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14047-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1307</id>
    <title>PYSEC-2026-1307 — Potential DoS via the Tudoor mechanism in eventlet and dnspython</title>
    <updated>2026-10-04T20:34:15.685091+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: dnspython</p>
<p>eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1307"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0045</id>
    <title>RHSA-2024:0045 — Red Hat Security Advisory: OpenShift Container Platform 4.16.0 security update</title>
    <updated>2026-10-04T20:34:15.685130+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dnspython: denial of service in stub resolver golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm containers/image: digest type does not guarantee valid type golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm golang: net/mail: comments in display names are incorrectly handled golang: html/template: errors returned from MarshalJSON methods may break template escaping golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON jose: resource exhaustion</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0045"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:2605-1</id>
    <title>SUSE-SU-2024:2605-1 — Security update for python-dnspython</title>
    <updated>2026-10-04T20:34:15.685192+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-dnspython</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:2605-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-29483</id>
    <title>UBUNTU-CVE-2023-29483</title>
    <updated>2026-10-04T20:34:15.685218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: dnspython, Ubuntu:16.04:LTS: dnspython, Ubuntu:18.04:LTS: dnspython, Ubuntu:20.04:LTS: dnspython, Ubuntu:22.04:LTS: dnspython</p>
<p>eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-29483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1213</id>
    <title>WID-SEC-W-2024-1213 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-04T20:34:15.685271+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter anonymer Angreifer kann mehrere Schwachstellen in verschiedenen Komponenten von Red Hat Enterprise Linux ausnutzen, um beliebigen Code auszuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1213"/>
  </entry>
</feed>
