<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:58:55.965267+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:7762</id>
    <title>ALSA-2023:7762 — Moderate: skopeo security update</title>
    <updated>2026-10-03T10:58:56.072617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: skopeo, AlmaLinux:9: skopeo-tests</p>
<p>The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.</p>
<p>Security Fix(es):</p>
<p>* golang: crypto/tls: slow verification of certificate chains containing large RSA keys (CVE-2023-29409)
* golang: html/template: improper handling of HTML-like comments within script contexts (CVE-2023-39318)
* golang: html/template: improper handling of special tags within script contexts (CVE-2023-39319)
* golang: crypto/tls: panic when processing post-handshake message on QUIC connections (CVE-2023-39321)
* golang: crypto/tls: lack of a limit on buffered post-handshake (CVE-2023-39322)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:7762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-39322</id>
    <title>BELL-CVE-2023-39322</title>
    <updated>2026-10-03T10:58:56.072708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, BellSoft Hardened Containers:23: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-39322"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2023-39322</id>
    <title>BIT-golang-2023-39322 — Memory exhaustion in QUIC connection handling in crypto/tls</title>
    <updated>2026-10-03T10:58:56.072733+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2023-39322"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</id>
    <title>certfr-2024-avi-0646 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T10:58:56.072755+00:00</updated>
    <content>certfr-2024-avi-0646</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216694</id>
    <title>EUVD-2026-216694</title>
    <updated>2026-10-03T10:58:56.072773+00:00</updated>
    <content>EUVD-2026-216694</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216694"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-39322</id>
    <title>fkie_cve-2023-39322</title>
    <updated>2026-10-03T10:58:56.072785+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-39322"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-892h-r6cr-53g4</id>
    <title>GHSA-892h-r6cr-53g4</title>
    <updated>2026-10-03T10:58:56.072806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-892h-r6cr-53g4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-39322</id>
    <title>gsd-2023-39322</title>
    <updated>2026-10-03T10:58:56.072821+00:00</updated>
    <content>gsd-2023-39322</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-39322"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4067</id>
    <title>OESA-2026-4067 — git-lfs security update</title>
    <updated>2026-10-03T10:58:56.072831+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: git-lfs</p>
<p>Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.

Security Fix(es):</p>
<p>Processing an incomplete post-handshake message for a QUIC connection can cause a panic.(CVE-2023-39321)</p>
<p>QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.(CVE-2023-39322)</p>
<p>Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.(CVE-2025-22874)</p>
<p>Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository&amp;apos;s working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. The git lfs checkout and git lfs pull commands do not check for symbolic links before writing to files in the working tree, allowing an attacker to craft a repository containing symbolic or hard links that cause Git LFS to write to arbitrary file system locations accessible to the user running these comman…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2023:0360-1</id>
    <title>openSUSE-SU-2023:0360-1 — Security update for go1.21</title>
    <updated>2026-10-03T10:58:56.072881+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.21</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2023:0360-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2023:6863</id>
    <title>RHBA-2023:6863 — Red Hat Bug Fix Advisory: LVMS 4.14.z Bug Fix and Enhancement update</title>
    <updated>2026-10-03T10:58:56.072904+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang.org/x/net/html: Cross site scripting golang: crypto/tls: slow verification of certificate chains containing large RSA keys golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2023:6863"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-39322</id>
    <title>Withdrawn: UBUNTU-CVE-2023-39322</title>
    <updated>2026-10-03T10:58:56.072933+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:20.04:LTS: golang-1.21, Ubuntu:22.04:LTS: golang-1.21, Ubuntu:24.04:LTS: golang-1.21</p>
<p>QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-39322"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2280</id>
    <title>WID-SEC-W-2023-2280 — Golang Go: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:58:56.072956+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Code auszuführen oder einen Denial of Service zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2280"/>
  </entry>
</feed>
