<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:04:43.482416+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-06663</id>
    <title>bdu:2024-06663</title>
    <updated>2026-10-03T11:04:44.372036+00:00</updated>
    <content>bdu:2024-06663</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-06663"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0878</id>
    <title>certfr-2024-avi-0878 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T11:04:44.372121+00:00</updated>
    <content>certfr-2024-avi-0878</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0878"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-vc45240</id>
    <title>CLEANSTART-2025-VC45240 — Security fix for CVE-2023-47108 applied in: cert-manager-webhook-pdns-fips 2.3.0-r0</title>
    <updated>2026-10-03T11:04:44.372144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: cert-manager-webhook-pdns-fips</p>
<p>Security vulnerability affects the cert-manager-webhook-pdns-fips package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-vc45240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-257052</id>
    <title>EUVD-2026-257052</title>
    <updated>2026-10-03T11:04:44.372179+00:00</updated>
    <content>EUVD-2026-257052</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-257052"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-47108</id>
    <title>fkie_cve-2023-47108</title>
    <updated>2026-10-03T11:04:44.372193+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to disable grpc metrics instrumentation by passing `otelgrpc.WithMeterProvider` option with `noop.NewMeterProvider`.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-47108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8pgv-569h-w5rw</id>
    <title>GHSA-8pgv-569h-w5rw — otelgrpc DoS vulnerability due to unbound cardinality metrics</title>
    <updated>2026-10-03T11:04:44.372221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc</p>
<p>### Summary</p>
<p>The grpc Unary Server Interceptor [opentelemetry-go-contrib/instrumentation/google.golang.org/grpc/otelgrpc/interceptor.go](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/9d4eb7e7706038b07d33f83f76afbe13f53d171d/instrumentation/google.golang.org/grpc/otelgrpc/interceptor.go#L327)</p>
<p>```
// UnaryServerInterceptor returns a grpc.UnaryServerInterceptor suitable
// for use in a grpc.NewServer call.
func UnaryServerInterceptor(opts ...Option) grpc.UnaryServerInterceptor {
```
  
out of the box adds labels</p>
<p>- `net.peer.sock.addr`
- `net.peer.sock.port`</p>
<p>that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent.</p>
<p>### Details</p>
<p>An attacker can easily flood the peer address and port for requests.</p>
<p>### PoC</p>
<p>Apply the attached patch to the example and run the client multiple times.  Observe how each request will create a unique histogram and how the memory consumption increases during it.
### Impact</p>
<p>In order to be affected, the program has to configure a metrics pipeline, use  [UnaryServerInterceptor](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/9d4eb7e7706038b07d33f83f76afbe13f53d171d/instrumentation/google.golang.org/grpc/otelgrpc/interceptor.go#L327), and does not filter any client IP address and ports via middleware or proxies, etc.</p>
<p>### Others</p>
<p>It is similar to already reported vulnerabilities.</p>
<p>* [GHSA-rcjv-mgp8-qvmr](https://github.com/open-telemetry/opentelemetry-go-…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8pgv-569h-w5rw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-47108</id>
    <title>gsd-2023-47108</title>
    <updated>2026-10-03T11:04:44.372271+00:00</updated>
    <content>gsd-2023-47108</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-47108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-47108</id>
    <title>msrc_CVE-2023-47108 — DoS vulnerability in otelgrpc (uncontrolled resource consumption) due to unbound cardinality metrics</title>
    <updated>2026-10-03T11:04:44.372284+00:00</updated>
    <content>msrc_CVE-2023-47108</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-47108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13615-1</id>
    <title>openSUSE-SU-2024:13615-1 — etcd-3.5.11-1.1 on GA media</title>
    <updated>2026-10-03T11:04:44.372302+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>etcd-3.5.11-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13615-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7197</id>
    <title>RHSA-2023:7197 — Red Hat Security Advisory: OpenShift Container Platform 4.15.0 security and extras update</title>
    <updated>2026-10-03T11:04:44.372319+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang.org/x/net/html: Cross site scripting opentelemetry: DoS vulnerability in otelhttp opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics ssh: Prefix truncation attack on Binary Packet Protocol (BPP) go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3188-1</id>
    <title>SUSE-SU-2024:3188-1 — Security update for containerd</title>
    <updated>2026-10-03T11:04:44.372344+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for containerd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3188-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-47108</id>
    <title>UBUNTU-CVE-2023-47108</title>
    <updated>2026-10-03T11:04:44.372361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: golang-opentelemetry-contrib, Ubuntu:26.04:LTS: golang-opentelemetry-contrib</p>
<p>OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to disable grpc metrics instrumentation by passing `otelgrpc.WithMeterProvider` option with `noop.NewMeterProvider`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-47108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0137</id>
    <title>WID-SEC-W-2024-0137 — Red Hat OpenShift Container Platform: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T11:04:44.372420+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Container Platform ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0137"/>
  </entry>
</feed>
