<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:32:18.344212+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:5721</id>
    <title>ALSA-2023:5721 — Important: go-toolset:rhel8 security update</title>
    <updated>2026-10-02T14:32:22.327650+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: delve, AlmaLinux:8: go-toolset, AlmaLinux:8: golang, AlmaLinux:8: golang-bin, AlmaLinux:8: golang-docs, AlmaLinux:8: golang-misc, AlmaLinux:8: golang-race, AlmaLinux:8: golang-src, AlmaLinux:8: golang-tests</p>
<p>Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.</p>
<p>Security Fix(es):</p>
<p>* golang: net/http, x/net/http2: rapid stream resets can cause excessive work [CVE-2023-44487] (CVE-2023-39325)
* HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:5721"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07013</id>
    <title>bdu:2023-07013</title>
    <updated>2026-10-02T14:32:22.327812+00:00</updated>
    <content>bdu:2023-07013</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-39325</id>
    <title>BELL-CVE-2023-39325</title>
    <updated>2026-10-02T14:32:22.327832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:stream: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-39325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2023-39325</id>
    <title>BIT-golang-2023-39325 — HTTP/2 rapid reset can cause excessive work in net/http</title>
    <updated>2026-10-02T14:32:22.327857+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2023-39325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199</id>
    <title>certfr-2024-avi-0199 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T14:32:22.327884+00:00</updated>
    <content>certfr-2024-avi-0199</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-eg56917</id>
    <title>Withdrawn: CLEANSTART-2026-EG56917 — Security fixes for CVE-2023-39325, CVE-2023-44487, CVE-2024-24786 applied in versions: 0.2.15-r1</title>
    <updated>2026-10-02T14:32:22.327901+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: zookeeper-operator</p>
<p>Multiple security vulnerabilities affect the zookeeper-operator package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-eg56917"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216695</id>
    <title>EUVD-2026-216695</title>
    <updated>2026-10-02T14:32:22.327922+00:00</updated>
    <content>EUVD-2026-216695</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-39325</id>
    <title>fkie_cve-2023-39325</title>
    <updated>2026-10-02T14:32:22.327934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-39325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4374-p667-p6c8</id>
    <title>GHSA-4374-p667-p6c8 — HTTP/2 rapid reset can cause excessive work in net/http</title>
    <updated>2026-10-02T14:32:22.327960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: golang.org/x/net</p>
<p>A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing.</p>
<p>With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection.</p>
<p>This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2.</p>
<p>The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4374-p667-p6c8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-39325</id>
    <title>gsd-2023-39325</title>
    <updated>2026-10-02T14:32:22.327988+00:00</updated>
    <content>gsd-2023-39325</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-39325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-39325</id>
    <title>msrc_CVE-2023-39325 — HTTP/2 rapid reset can cause excessive work in net/http</title>
    <updated>2026-10-02T14:32:22.328000+00:00</updated>
    <content>msrc_CVE-2023-39325</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-39325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1789</id>
    <title>OESA-2023-1789 — golang security update</title>
    <updated>2026-10-02T14:32:22.328017+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: golang, openEuler:20.03-LTS-SP3: golang, openEuler:22.03-LTS: golang, openEuler:22.03-LTS-SP1: golang, openEuler:22.03-LTS-SP2: golang</p>
<p>.

Security Fix(es):

The html/template package does not properly handle HTML-like &amp;quot;&amp;quot; comment tokens, nor hashbang &amp;quot;#!&amp;quot; comment tokens, in &amp;lt;script&amp;gt; contexts. This may cause the template parser to improperly interpret the contents of &amp;lt;script&amp;gt; contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack.(CVE-2023-39318)

The html/template package does not apply the proper rules for handling occurrences of &amp;quot;&amp;lt;script&amp;quot;, &amp;quot;&amp;lt;!--&amp;quot;, and &amp;quot;&amp;lt;/script&amp;quot; within JS literals in &amp;lt;script&amp;gt; contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack.(CVE-2023-39319)

Line directives (&amp;quot;//line&amp;quot;) can be used to bypass the restrictions on &amp;quot;//go:cgo_&amp;quot; directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running &amp;quot;go build&amp;quot;. The line directive requires the absolute path of the file in which the directive lives, which makes exploiting this issue significantly more complex.(CVE-2023-39323)

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resett…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1789"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2023:0360-1</id>
    <title>openSUSE-SU-2023:0360-1 — Security update for go1.21</title>
    <updated>2026-10-02T14:32:22.328064+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for go1.21</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2023:0360-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2023:5669</id>
    <title>RHBA-2023:5669 — Red Hat Bug Fix Advisory: OpenShift Compliance Operator bug fix and enhancement update</title>
    <updated>2026-10-02T14:32:22.328087+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2023:5669"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3342-1</id>
    <title>SUSE-SU-2024:3342-1 — Security update for kubernetes1.24</title>
    <updated>2026-10-02T14:32:22.328104+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for kubernetes1.24</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3342-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-39325</id>
    <title>UBUNTU-CVE-2023-39325</title>
    <updated>2026-10-02T14:32:22.328121+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: golang-1.10, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:16.04:LTS: golang-1.6, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:18.04:LTS: golang-1.8 and 12 more</p>
<p>A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-39325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2723</id>
    <title>WID-SEC-W-2023-2723 — Red Hat Satellite: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:32:22.328173+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Satellite ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2723"/>
  </entry>
</feed>
