<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:55:34.599547+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:1129</id>
    <title>ALSA-2024:1129 — Moderate: curl security update</title>
    <updated>2026-10-02T12:55:35.124483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: curl, AlmaLinux:9: curl-minimal, AlmaLinux:9: libcurl, AlmaLinux:9: libcurl-devel, AlmaLinux:9: libcurl-minimal</p>
<p>The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.</p>
<p>Security Fix(es):</p>
<p>* curl: information disclosure by exploiting a mixed case flaw (CVE-2023-46218)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:1129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02420</id>
    <title>bdu:2024-02420</title>
    <updated>2026-10-02T12:55:35.124569+00:00</updated>
    <content>bdu:2024-02420</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02420"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-46218</id>
    <title>BELL-CVE-2023-46218</title>
    <updated>2026-10-02T12:55:35.124587+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: curl, Alpaquita:stream: curl, BellSoft Hardened Containers:stream: curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-46218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145</id>
    <title>certfr-2024-avi-0145 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T12:55:35.124609+00:00</updated>
    <content>certfr-2024-avi-0145</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0145"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527</id>
    <title>Withdrawn: CLEANSTART-2026-AY18527 — Security fixes for CVE-2014-0138, CVE-2014-0139, CVE-2016-5419, CVE-2016-5420, CVE-2016-5421, CVE-2016-7141, CVE-2016-7…</title>
    <updated>2026-10-02T12:55:35.124626+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: curl</p>
<p>Multiple security vulnerabilities affect the curl package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ay18527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336248</id>
    <title>EUVD-2026-336248</title>
    <updated>2026-10-02T12:55:35.124656+00:00</updated>
    <content>EUVD-2026-336248</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336248"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46218</id>
    <title>fkie_cve-2023-46218</title>
    <updated>2026-10-02T12:55:35.124668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that then would get sent to
different and unrelated sites and domains.</p>
<p>It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with `domain=co.UK` when the URL used a lower
case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-46218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-59mm-6rr4-j9p2</id>
    <title>GHSA-59mm-6rr4-j9p2</title>
    <updated>2026-10-02T12:55:35.124693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that then would get sent to
different and unrelated sites and domains.</p>
<p>It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with `domain=co.UK` when the URL used a lower
case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-59mm-6rr4-j9p2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-46218</id>
    <title>gsd-2023-46218</title>
    <updated>2026-10-02T12:55:35.124711+00:00</updated>
    <content>gsd-2023-46218</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-46218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-137-07</id>
    <title>ICSA-24-137-07 — Siemens SIMATIC RTLS Locating Manager</title>
    <updated>2026-10-02T12:55:35.124722+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications on the Windows 64 platform when running on newer X86_64 processors supporting the AVX512-IFMA instructions. Impact summary: If in an application that uses the OpenSSL library an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC (message authentication code) implementation in OpenSSL does not save the contents of non-volatile XMM registers on Windows 64 platform when calculating the MAC of data larger than 64 bytes. Before returning to the caller all the XMM registers are set to zero rather than restoring their previous content. The vulnerable code is used only on newer x86_64 processors supporting the AVX512-IFMA instructions. The consequences of this kind of internal application state corruption can be various - from no consequences, if the calling application does not depend on the contents of non-volatile XMM registers at all, to the worst consequences, where the attacker could get complete control of the application process. However given the contents of the registers are just zeroized so the attacker cannot put arbitrary values inside, the most likely consequence, if any, would be an incorrect result of some application dependent calculations or a crash leading to a denial of service. The POLY1305 MAC alg…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-137-07"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-46218</id>
    <title>msrc_CVE-2023-46218 — This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than…</title>
    <updated>2026-10-02T12:55:35.124833+00:00</updated>
    <content>msrc_CVE-2023-46218</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-46218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1913</id>
    <title>OESA-2023-1913 — curl security update</title>
    <updated>2026-10-02T12:55:35.124852+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: curl, openEuler:20.03-LTS-SP3: curl, openEuler:22.03-LTS: curl, openEuler:22.03-LTS-SP1: curl, openEuler:22.03-LTS-SP2: curl</p>
<p>cURL is a computer software project providing a library (libcurl) and command-line tool (curl) for transferring data using various protocols.

Security Fix(es):

This flaw allows a malicious HTTP server to set &amp;quot;super cookies&amp;quot; in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that then would get sent to
different and unrelated sites and domains.

It could do this by exploiting a mixed case flaw in curl&amp;apos;s function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with `domain=co.UK` when the URL used a lower
case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
(CVE-2023-46218)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13509-1</id>
    <title>openSUSE-SU-2024:13509-1 — curl-8.5.0-1.1 on GA media</title>
    <updated>2026-10-02T12:55:35.124885+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl-8.5.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13509-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0428</id>
    <title>RHSA-2024:0428 — Red Hat Security Advisory: curl security and bug fix update</title>
    <updated>2026-10-02T12:55:35.124902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl: Incorrect handling of control code characters in cookies curl: Use-after-free triggered by an HTTP proxy deny response curl: FTP too eager connection reuse curl: GSS delegation too eager connection re-use curl: more POST-after-PUT confusion curl: information disclosure by exploiting a mixed case flaw</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-082556</id>
    <title>SSA-082556 — SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5</title>
    <updated>2026-10-02T12:55:35.124925+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p>
<p>Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-082556"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:4650-1</id>
    <title>SUSE-SU-2023:4650-1 — Security update for curl</title>
    <updated>2026-10-02T12:55:35.125108+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for curl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:4650-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46218</id>
    <title>UBUNTU-CVE-2023-46218</title>
    <updated>2026-10-02T12:55:35.125125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: curl, Ubuntu:Pro:18.04:LTS: curl, Ubuntu:20.04:LTS: curl, Ubuntu:22.04:LTS: curl</p>
<p>This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-46218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-073</id>
    <title>VDE-2024-073 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
    <updated>2026-10-02T12:55:35.125152+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gvariant offset table entry size is not checked in is_normal() G_variant_byteswap() can take a long time with some non-normal inputs Gvariant deserialisation does not match spec for non-normal data Glibc: dos due to memory leak in getaddrinfo.c Glibc: buffer overflow in ld.so leading to privilege escalation Gnutls: incomplete fix for cve-2023-5981 Gnutls: rejects certificate chain with distributed trust Denial-of-Service in gRPC Information leak in gRPC Denial-of-Service in gRPC Denial of Service in gRPC Core  Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed) Incorrect cipher key &amp; IV length processing POLY1305 MAC implementation corrupts XMM registers on Windows Excessive time spent checking DH q parameter value SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow NULL Pointer Dereference in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Integer Overflow or Wraparound in vim/vim Use After Free in vim/vim Untrusted Search Path in vim/vim Out-of-bounds Write in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use-After-Free in win_close() in vim overflow in shift_line in vim Vim has heap-use-after-free at /src/charset.c:1770:12 in skipwhite Integer Overflow in :history command in Vim</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3060</id>
    <title>WID-SEC-W-2023-3060 — cURL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T12:55:35.125231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in cURL ausnutzen, um Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3060"/>
  </entry>
</feed>
