<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:29:15.594332+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-4785</id>
    <title>BELL-CVE-2023-4785</title>
    <updated>2026-10-02T19:29:15.607374+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: grpc, Alpaquita:stream: grpc, BellSoft Hardened Containers:stream: grpc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-4785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-dstack-cve-2023-4785</id>
    <title>BREW-dstack-CVE-2023-4785 — Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)</title>
    <updated>2026-10-02T19:29:15.607427+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: dstack</p>
<p>Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-dstack-cve-2023-4785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0297</id>
    <title>certfr-2024-avi-0297 — De multiples vulnérabilités ont été découvertes dans Juniper. Certaines
d'entre elles permettent à un attaquant de prov…</title>
    <updated>2026-10-02T19:29:15.607456+00:00</updated>
    <content>certfr-2024-avi-0297</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0297"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265383</id>
    <title>EUVD-2026-265383</title>
    <updated>2026-10-02T19:29:15.607474+00:00</updated>
    <content>EUVD-2026-265383</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265383"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-4785</id>
    <title>fkie_cve-2023-4785</title>
    <updated>2026-10-02T19:29:15.607486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-4785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p25m-jpj4-qcrr</id>
    <title>GHSA-p25m-jpj4-qcrr — Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)</title>
    <updated>2026-10-02T19:29:15.607508+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: grpc, PyPI: grpcio</p>
<p>Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p25m-jpj4-qcrr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-4785</id>
    <title>gsd-2023-4785</title>
    <updated>2026-10-02T19:29:15.607533+00:00</updated>
    <content>gsd-2023-4785</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-4785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-4785</id>
    <title>msrc_CVE-2023-4785 — Denial of Service in gRPC Core</title>
    <updated>2026-10-02T19:29:15.607544+00:00</updated>
    <content>msrc_CVE-2023-4785</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-4785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1682</id>
    <title>OESA-2023-1682 — grpc security update</title>
    <updated>2026-10-02T19:29:15.607565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP3: grpc, openEuler:22.03-LTS: grpc, openEuler:22.03-LTS-SP1: grpc, openEuler:22.03-LTS-SP2: grpc</p>
<p>gRPC is a modern open source high performance RPC framework that can run in any environment. It can efficiently connect services in and across data centers with pluggable support for load balancing, tracing, health checking and authentication. It is also applicable in last mile of distributed computing to connect devices, mobile applications and browsers to backend services.

Security Fix(es):

Lack of error handling in the TCP server in Google&amp;apos;s gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected. (CVE-2023-4785)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1682"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13621-1</id>
    <title>openSUSE-SU-2024:13621-1 — grpc-devel-1.60.0-3.1 on GA media</title>
    <updated>2026-10-02T19:29:15.607594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grpc-devel-1.60.0-3.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13621-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1428</id>
    <title>PYSEC-2026-1428 — Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)</title>
    <updated>2026-10-02T19:29:15.607610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: grpcio</p>
<p>Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0797</id>
    <title>RHSA-2024:0797 — Red Hat Security Advisory: Satellite 6.14.2 Async Security Update</title>
    <updated>2026-10-02T19:29:15.607629+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>mosquitto: memory leak leads to unresponsive broker mosquitto: memory leak leads to unresponsive broker gRPC: file descriptor exhaustion leads to denial of service jetty-server: Cookie parsing of quoted values can exfiltrate values from other cookies sidekiq: DoS in dashboard-charts mosquitto: memory leak leads to unresponsive broker jetty: Improper addition of quotation marks to user inputs in CgiServlet curl: heap based buffer overflow in the SOCKS5 proxy handshake jetty: Improper validation of HTTP/1 content-length rubygem-puma: HTTP request smuggling when parsing chunked transfer encoding bodies and zero-length content-length headers</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-4785</id>
    <title>UBUNTU-CVE-2023-4785</title>
    <updated>2026-10-02T19:29:15.607655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grpc, Ubuntu:18.04:LTS: grpc, Ubuntu:20.04:LTS: grpc, Ubuntu:22.04:LTS: grpc, Ubuntu:24.04:LTS: grpc, Ubuntu:25.10: grpc, Ubuntu:26.04:LTS: grpc</p>
<p>Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) allows an attacker to cause a denial of service by initiating a significant number of connections with the server. Note that gRPC C++ Python, and Ruby are affected, but gRPC Java, and Go are NOT affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-4785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-073</id>
    <title>VDE-2024-073 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
    <updated>2026-10-02T19:29:15.607682+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Gvariant offset table entry size is not checked in is_normal() G_variant_byteswap() can take a long time with some non-normal inputs Gvariant deserialisation does not match spec for non-normal data Glibc: dos due to memory leak in getaddrinfo.c Glibc: buffer overflow in ld.so leading to privilege escalation Gnutls: incomplete fix for cve-2023-5981 Gnutls: rejects certificate chain with distributed trust Denial-of-Service in gRPC Information leak in gRPC Denial-of-Service in gRPC Denial of Service in gRPC Core  Libssh: proxycommand/proxyjump features allow injection of malicious code through hostname Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed) Incorrect cipher key &amp; IV length processing POLY1305 MAC implementation corrupts XMM registers on Windows Excessive time spent checking DH q parameter value SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow NULL Pointer Dereference in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Integer Overflow or Wraparound in vim/vim Use After Free in vim/vim Untrusted Search Path in vim/vim Out-of-bounds Write in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use After Free in vim/vim Heap-based Buffer Overflow in vim/vim Use-After-Free in win_close() in vim overflow in shift_line in vim Vim has heap-use-after-free at /src/charset.c:1770:12 in skipwhite Integer Overflow in :history command in Vim</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-073"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1591</id>
    <title>WID-SEC-W-2024-1591 — Juniper JUNOS: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:29:15.607733+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Juniper JUNOS ausnutzen, um einen Denial of Service  zu verursachen, Informationen offenzulegen, Privilegien zu erweitern und Sicherheitsmechanismen inklusive zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1591"/>
  </entry>
</feed>
