<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:56:02.469085+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-03945</id>
    <title>bdu:2025-03945</title>
    <updated>2026-10-02T14:56:02.808696+00:00</updated>
    <content>bdu:2025-03945</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-03945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2023-46136</id>
    <title>BREW-aws-sam-cli-CVE-2023-46136 — Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the…</title>
    <updated>2026-10-02T14:56:02.808740+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aws-sam-cli</p>
<p>Werkzeug multipart data parser needs to find a boundary that may be between consecutive chunks. That's why parsing is based on looking for newline characters. Unfortunately, code looking for partial boundary in the buffer is written inefficiently, so if we upload a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer.</p>
<p>This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. The amount of RAM required can trigger an out of memory kill of the process. If many concurrent requests are sent continuously, this can exhaust or kill all available workers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2023-46136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0074</id>
    <title>certfr-2024-avi-0074 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T14:56:02.808783+00:00</updated>
    <content>certfr-2024-avi-0074</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0074"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261</id>
    <title>Withdrawn: CLEANSTART-2026-AZ09261 — Security fixes for CVE-2023-46136, CVE-2024-12797, CVE-2024-34069, CVE-2024-49766, CVE-2024-49767, CVE-2025-62727, CVE-…</title>
    <updated>2026-10-02T14:56:02.808800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: airflow-3</p>
<p>Multiple security vulnerabilities affect the airflow-3 package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319774</id>
    <title>EUVD-2026-319774</title>
    <updated>2026-10-02T14:56:02.808828+00:00</updated>
    <content>EUVD-2026-319774</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319774"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46136</id>
    <title>fkie_cve-2023-46136</title>
    <updated>2026-10-02T14:56:02.808840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1 and 2.3.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-46136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hrfv-mqp8-q5rw</id>
    <title>GHSA-hrfv-mqp8-q5rw — Werkzeug DoS: High resource usage when parsing multipart/form-data containing a large part with CR/LF character at the…</title>
    <updated>2026-10-02T14:56:02.808864+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Werkzeug</p>
<p>Werkzeug multipart data parser needs to find a boundary that may be between consecutive chunks. That's why parsing is based on looking for newline characters. Unfortunately, code looking for partial boundary in the buffer is written inefficiently, so if we upload a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer.</p>
<p>This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. The amount of RAM required can trigger an out of memory kill of the process. If many concurrent requests are sent continuously, this can exhaust or kill all available workers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hrfv-mqp8-q5rw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-46136</id>
    <title>gsd-2023-46136</title>
    <updated>2026-10-02T14:56:02.808890+00:00</updated>
    <content>gsd-2023-46136</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-46136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-46136</id>
    <title>msrc_CVE-2023-46136 — Werkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF characte…</title>
    <updated>2026-10-02T14:56:02.808901+00:00</updated>
    <content>msrc_CVE-2023-46136</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-46136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1996</id>
    <title>OESA-2025-1996 — python-werkzeug security update</title>
    <updated>2026-10-02T14:56:02.808918+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP2: python-werkzeug</p>
<p>A comprehensive WSGI web application library

Security Fix(es):</p>
<p>Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1.(CVE-2023-46136)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1996"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13375-1</id>
    <title>openSUSE-SU-2024:13375-1 — python310-Werkzeug-3.0.1-1.1 on GA media</title>
    <updated>2026-10-02T14:56:02.808940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-Werkzeug-3.0.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13375-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2023-221</id>
    <title>PYSEC-2023-221</title>
    <updated>2026-10-02T14:56:02.808957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: werkzeug</p>
<p>Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2023-221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7473</id>
    <title>RHSA-2023:7473 — Red Hat Security Advisory: OpenShift Container Platform 4.14.4 packages and security update</title>
    <updated>2026-10-02T14:56:02.808977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-werkzeug: high resource usage when parsing multipart form data with many fields haproxy: Proxy forwards malformed empty Content-Length headers python-werkzeug: high resource consumption leading to denial of service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7473"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3024</id>
    <title>WID-SEC-W-2023-3024 — Red Hat OpenShift: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T14:56:02.808996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3024"/>
  </entry>
</feed>
