<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:52:22.055873+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-00588</id>
    <title>bdu:2024-00588</title>
    <updated>2026-10-03T09:52:22.254844+00:00</updated>
    <content>bdu:2024-00588</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-00588"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-1007</id>
    <title>certfr-2023-avi-1007 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T09:52:22.254903+00:00</updated>
    <content>certfr-2023-avi-1007</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-1007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cu18187</id>
    <title>Withdrawn: CLEANSTART-2026-CU18187 — Security fixes in stargate 1.0.90-r4</title>
    <updated>2026-10-03T09:52:22.254939+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: stargate</p>
<p>Package stargate version 1.0.90-r4 fixes 87 vulnerabilities: ghsa-76h9-2vwh-w278, ghsa-pqr6-cmr2-h8hf, ghsa-fjpj-2g6w-x25r, ghsa-qcwq-55hx-v3vh, ghsa-55g7-9cwv-5qfv...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cu18187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-187480</id>
    <title>EUVD-2026-187480</title>
    <updated>2026-10-03T09:52:22.254988+00:00</updated>
    <content>EUVD-2026-187480</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-187480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-43642</id>
    <title>fkie_cve-2023-43642</title>
    <updated>2026-10-03T09:52:22.255010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-43642"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-55g7-9cwv-5qfv</id>
    <title>GHSA-55g7-9cwv-5qfv — snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact</title>
    <updated>2026-10-03T09:52:22.255051+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.xerial.snappy:snappy-java</p>
<p>### Summary</p>
<p>snappy-java is a data compression library in Java. Its SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too-large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur.</p>
<p>### Scope</p>
<p>All versions of snappy-java including the latest released version 1.1.10.3.  A fix is applied in 1.1.10.4</p>
<p>### Details
While performing mitigation efforts related to [CVE-2023-34455](https://nvd.nist.gov/vuln/detail/CVE-2023-34455) in Confluent products, our Application Security team closely analyzed the fix that was accepted and merged into snappy-java version 1.1.10.1 in [this](https://github.com/xerial/snappy-java/commit/3bf67857fcf70d9eea56eed4af7c925671e8eaea) commit. The check on [line 421](https://github.com/xerial/snappy-java/commit/3bf67857fcf70d9eea56eed4af7c925671e8eaea#diff-c3e53610267092989965e8c7dd2d4417d355ff7f560f9e8075b365f32569079fR421) only attempts to check if chunkSize is not a negative value. We believe that this is an inadequate fix as it misses an upper-bounds check for overly positive values such as 0x7FFFFFFF (or (2,147,483,647 in decimal) before actually [attempting to allocate](https://github.com/xerial/snappy-java/commit/3bf67857fcf70d9eea56eed4af7c925671e8eaea#diff-c3e53610267092989965e8c7dd2d4417d355ff7f560f9e8075b365f32569079fR429) the provided unverified number of bytes via the “chunkSize” variable. This missing upper-bounds check can lead to t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-55g7-9cwv-5qfv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-43642</id>
    <title>gsd-2023-43642</title>
    <updated>2026-10-03T09:52:22.255126+00:00</updated>
    <content>gsd-2023-43642</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-43642"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1700</id>
    <title>OESA-2023-1700 — snappy-java security update</title>
    <updated>2026-10-03T09:52:22.255146+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: snappy-java, openEuler:20.03-LTS-SP3: snappy-java, openEuler:22.03-LTS: snappy-java, openEuler:22.03-LTS-SP1: snappy-java, openEuler:22.03-LTS-SP2: snappy-java</p>
<p>A Java port of the snappy, a fast compresser/decompresser written in C++.

Security Fix(es):

snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.(CVE-2023-43642)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1700"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7612</id>
    <title>RHSA-2023:7612 — Red Hat Security Advisory: Red Hat build of Quarkus 3.2.9 release and security update</title>
    <updated>2026-10-03T09:52:22.255203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>quarkus: GraphQL operations over WebSockets bypass apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK snappy-java: Missing upper bound check on chunk length in snappy-java can lead to Denial of Service (DoS) impact</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7612"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43642</id>
    <title>UBUNTU-CVE-2023-43642</title>
    <updated>2026-10-03T09:52:22.255271+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: snappy-java, Ubuntu:16.04:LTS: snappy-java, Ubuntu:18.04:LTS: snappy-java, Ubuntu:20.04:LTS: snappy-java, Ubuntu:22.04:LTS: snappy-java, Ubuntu:24.04:LTS: snappy-java, Ubuntu:25.10: snappy-java, Ubuntu:26.04:LTS: snappy-java</p>
<p>snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43642"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2935</id>
    <title>WID-SEC-W-2023-2935 — IBM Integration Bus: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T09:52:22.255328+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM Integration Bus ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2935"/>
  </entry>
</feed>
