<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:53:03.069753+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07911</id>
    <title>bdu:2023-07911</title>
    <updated>2026-10-02T22:53:03.981171+00:00</updated>
    <content>bdu:2023-07911</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07911"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</id>
    <title>certfr-2024-avi-0145 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T22:53:03.981244+00:00</updated>
    <content>certfr-2024-avi-0145</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ep15881</id>
    <title>Withdrawn: CLEANSTART-2026-EP15881 — Security fixes in cert-manager-webhook-pdns-fips 2.3.0-r0</title>
    <updated>2026-10-02T22:53:03.981267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cert-manager-webhook-pdns-fips</p>
<p>Package cert-manager-webhook-pdns-fips version 2.3.0-r0 fixes 17 vulnerabilities: CVE-2022-1996, CVE-2023-45142, CVE-2023-25151, CVE-2022-21698, CVE-2022-30636...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ep15881"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216878</id>
    <title>EUVD-2026-216878</title>
    <updated>2026-10-02T22:53:03.981301+00:00</updated>
    <content>EUVD-2026-216878</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216878"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-45142</id>
    <title>fkie_cve-2023-45142</title>
    <updated>2026-10-02T22:53:03.981314+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent` and `http.method` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent to it. HTTP header User-Agent or HTTP method for requests can be easily set by an attacker to be random and long. The library internally uses `httpconv.ServerRequest` that records every value for HTTP `method` and `User-Agent`. In order to be affected, a program has to use the `otelhttp.NewHandler` wrapper and not filter any unknown HTTP methods or User agents on the level of CDN, LB, previous middleware, etc. Version 0.44.0 fixed this issue when the values collected for attribute `http.request.method` were changed to be restricted to a set of well-known values and other high cardinality attributes were removed. As a workaround to stop being affected, `otelhttp.WithFilter()` can be used, but it requires manual careful configuration to not log certain requests entirely. For convenience and safe usage of this library, it should by default mark with the label `unknown` non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-45142"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rcjv-mgp8-qvmr</id>
    <title>GHSA-rcjv-mgp8-qvmr — OpenTelemetry-Go Contrib vulnerable to denial of service in otelhttp due to unbound cardinality metrics</title>
    <updated>2026-10-02T22:53:03.981346+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp, Go: go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful, Go: go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin, Go: go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux, Go: go.opentelemetry.io/contrib/instrumentation/github.com/labstack/echo/otelecho, Go: go.opentelemetry.io/contrib/instrumentation/gopkg.in/macaron.v1/otelmacaron, Go: go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace</p>
<p>### Summary</p>
<p>This handler wrapper https://github.com/open-telemetry/opentelemetry-go-contrib/blob/5f7e6ad5a49b45df45f61a1deb29d7f1158032df/instrumentation/net/http/otelhttp/handler.go#L63-L65
out of the box adds labels</p>
<p>- `http.user_agent`
- `http.method`</p>
<p>that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent to it.</p>
<p>### Details</p>
<p>HTTP header User-Agent or HTTP method for requests can be easily set by an attacker to be random and long. The library internally uses [httpconv.ServerRequest](https://github.com/open-telemetry/opentelemetry-go/blob/v1.12.0/semconv/internal/v2/http.go#L159) that records every value for HTTP [method](https://github.com/open-telemetry/opentelemetry-go/blob/38e1b499c3da3107694ad2660b3888eee9c8b896/semconv/internal/v2/http.go#L204) and [User-Agent](https://github.com/open-telemetry/opentelemetry-go/blob/38e1b499c3da3107694ad2660b3888eee9c8b896/semconv/internal/v2/http.go#L223).</p>
<p>### PoC</p>
<p>Send many requests with long randomly generated HTTP methods or/and User agents (e.g. a million) and observe how memory consumption increases during it.</p>
<p>### Impact</p>
<p>In order to be affected, the program has to configure a metrics pipeline, use [otelhttp.NewHandler](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/5f7e6ad5a49b45df45f61a1deb29d7f1158032df/instrumentation/net/http/otelhttp/handler.go#L63-L65) wrapper, and does not filter any unknown HTTP methods or User agents on the level o…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rcjv-mgp8-qvmr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-45142</id>
    <title>gsd-2023-45142</title>
    <updated>2026-10-02T22:53:03.981408+00:00</updated>
    <content>gsd-2023-45142</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-45142"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-45142</id>
    <title>msrc_CVE-2023-45142 — OpenTelemetry-Go Contrib has DoS vulnerability in otelhttp due to unbound cardinality metrics</title>
    <updated>2026-10-02T22:53:03.981421+00:00</updated>
    <content>msrc_CVE-2023-45142</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-45142"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0211-1</id>
    <title>openSUSE-SU-2024:0211-1 — Security update for caddy</title>
    <updated>2026-10-02T22:53:03.981438+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for caddy</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:0211-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2023:7648</id>
    <title>RHBA-2023:7648 — Red Hat Bug Fix Advisory: MTV 2.5.3 Images</title>
    <updated>2026-10-02T22:53:03.981456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake opentelemetry: DoS vulnerability in otelhttp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2023:7648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3188-1</id>
    <title>SUSE-SU-2024:3188-1 — Security update for containerd</title>
    <updated>2026-10-02T22:53:03.981481+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for containerd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3188-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-45142</id>
    <title>UBUNTU-CVE-2023-45142</title>
    <updated>2026-10-02T22:53:03.981497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: golang-opentelemetry-contrib, Ubuntu:26.04:LTS: golang-opentelemetry-contrib</p>
<p>OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent` and `http.method` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent to it. HTTP header User-Agent or HTTP method for requests can be easily set by an attacker to be random and long. The library internally uses `httpconv.ServerRequest` that records every value for HTTP `method` and `User-Agent`. In order to be affected, a program has to use the `otelhttp.NewHandler` wrapper and not filter any unknown HTTP methods or User agents on the level of CDN, LB, previous middleware, etc. Version 0.44.0 fixed this issue when the values collected for attribute `http.request.method` were changed to be restricted to a set of well-known values and other high cardinality attributes were removed. As a workaround to stop being affected, `otelhttp.WithFilter()` can be used, but it requires manual careful configuration to not log certain requests entirely. For convenience and safe usage of this library, it should by default mark with the label `unknown` non-standard HTTP methods and User agents to show that such requests were made but do not increase cardinality. In case someone wants to stay with the current behavior, library API should allow to enable it.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-45142"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3067</id>
    <title>WID-SEC-W-2023-3067 — Red Hat OpenShift: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:53:03.981528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen und um Sicherheitsmechanismen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3067"/>
  </entry>
</feed>
