<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:40:58.003700+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-nats-2023-46129</id>
    <title>BIT-nats-2023-46129 — xkeys Seal encryption used fixed key for all encryption</title>
    <updated>2026-10-03T12:40:58.119423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: nats</p>
<p>NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts. In nkeys versions 0.4.0 through 0.4.5, corresponding with NATS server versions 2.10.0 through 2.10.3, the nkeys library's `xkeys` encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use. As a result, all encryption was actually to an all-zeros key. This affects encryption only, not signing.  
FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY. nkeys Go library 0.4.6, corresponding with NATS Server 2.10.4, has a patch for this issue. No known workarounds are available. For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-nats-2023-46129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756</id>
    <title>certfr-2025-avi-0756 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T12:40:58.119485+00:00</updated>
    <content>certfr-2025-avi-0756</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ji58569</id>
    <title>CLEANSTART-2026-JI58569 — Security fix for CVE-2023-46129 applied in: nats-server-fips 2.10.4-r0</title>
    <updated>2026-10-03T12:40:58.119506+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: nats-server-fips</p>
<p>Security vulnerability affects the nats-server-fips package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ji58569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-219599</id>
    <title>EUVD-2026-219599</title>
    <updated>2026-10-03T12:40:58.119527+00:00</updated>
    <content>EUVD-2026-219599</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-219599"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46129</id>
    <title>fkie_cve-2023-46129</title>
    <updated>2026-10-03T12:40:58.119540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts. In nkeys versions 0.4.0 through 0.4.5, corresponding with NATS server versions 2.10.0 through 2.10.3, the nkeys library's `xkeys` encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use. As a result, all encryption was actually to an all-zeros key. This affects encryption only, not signing.  
FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY. nkeys Go library 0.4.6, corresponding with NATS Server 2.10.4, has a patch for this issue. No known workarounds are available. For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-46129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mr45-rx8q-wcm9</id>
    <title>GHSA-mr45-rx8q-wcm9 — xkeys seal encryption used fixed key for all encryption</title>
    <updated>2026-10-03T12:40:58.119568+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/nats-io/nkeys, Go: github.com/nats-io/nats-server/v2</p>
<p>## Background</p>
<p>NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.</p>
<p>The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication.  This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts.</p>
<p>## Problem Description</p>
<p>The nkeys library's "xkeys" encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use.  As a result, all encryption was actually to an all-zeros key.</p>
<p>This affects encryption only, not signing.  
FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY.</p>
<p>## Affected versions</p>
<p>nkeys Go library:
 * 0.4.0 up to and including 0.4.5
 * Fixed with nats-io/nkeys: 0.4.6</p>
<p>NATS Server:
 * 2.10.0 up to and including 2.10.3
 * Fixed with nats-io/nats-server: 2.10.4</p>
<p>## Solution</p>
<p>Upgrade the nats-server.  
For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.</p>
<p>## Credits</p>
<p>Problem reported by Quentin Matillat (GitHub @tinou98).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mr45-rx8q-wcm9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-46129</id>
    <title>gsd-2023-46129</title>
    <updated>2026-10-03T12:40:58.119606+00:00</updated>
    <content>gsd-2023-46129</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-46129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-46129</id>
    <title>msrc_CVE-2023-46129 — xkeys Seal encryption used fixed key for all encryption</title>
    <updated>2026-10-03T12:40:58.119618+00:00</updated>
    <content>msrc_CVE-2023-46129</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-46129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7663</id>
    <title>RHSA-2023:7663 — Red Hat Security Advisory: Red Hat OpenShift distributed tracing 3.0.0 operator/operand containers</title>
    <updated>2026-10-03T12:40:58.119634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>opentelemetry: DoS vulnerability in otelhttp nkeys: xkeys Seal encryption used fixed key for all encryption</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7663"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46129</id>
    <title>UBUNTU-CVE-2023-46129</title>
    <updated>2026-10-03T12:40:58.119671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: golang-github-nats-io-nkeys, Ubuntu:22.04:LTS: golang-github-nats-io-nkeys</p>
<p>NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts. In nkeys versions 0.4.0 through 0.4.5, corresponding with NATS server versions 2.10.0 through 2.10.3, the nkeys library's `xkeys` encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use. As a result, all encryption was actually to an all-zeros key. This affects encryption only, not signing. FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY. nkeys Go library 0.4.6, corresponding with NATS Server 2.10.4, has a patch for this issue. No known workarounds are available. For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3067</id>
    <title>WID-SEC-W-2023-3067 — Red Hat OpenShift: Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:40:58.119702+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen und um Sicherheitsmechanismen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3067"/>
  </entry>
</feed>
