<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:32:26.738508+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-13518</id>
    <title>bdu:2025-13518</title>
    <updated>2026-10-03T14:32:27.460844+00:00</updated>
    <content>bdu:2025-13518</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-13518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-241991</id>
    <title>EUVD-2026-241991</title>
    <updated>2026-10-03T14:32:27.460902+00:00</updated>
    <content>EUVD-2026-241991</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-241991"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-12224</id>
    <title>fkie_cve-2024-12224</title>
    <updated>2026-10-03T14:32:27.460917+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-12224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h97m-ww89-6jmq</id>
    <title>GHSA-h97m-ww89-6jmq — `idna` accepts Punycode labels that do not produce any non-ASCII when decoded</title>
    <updated>2026-10-03T14:32:27.460948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: idna</p>
<p>`idna` 0.5.0 and earlier accepts Punycode labels that do not produce any non-ASCII output, which means that either ASCII labels or the empty root label can be masked such that they appear unequal without IDNA processing or when processed with a different implementation and equal when processed with `idna` 0.5.0 or earlier.</p>
<p>Concretely, `example.org` and `xn--example-.org` become equal after processing by `idna` 0.5.0 or earlier. Also, `example.org.xn--` and `example.org.` become equal after processing by `idna` 0.5.0 or earlier.</p>
<p>In applications using `idna` (but not in `idna` itself) this may be able to lead to privilege escalation when host name comparison is part of a privilege check and the behavior is combined with a client that resolves domains with such labels instead of treating them as errors that preclude DNS resolution / URL fetching and with the attacker managing to introduce a DNS entry (and TLS certificate) for an `xn--`-masked name that turns into the name of the target when processed by `idna` 0.5.0 or earlier.</p>
<p>## Remedy</p>
<p>Upgrade to `idna` 1.0.3 or later, if depending on `idna` directly, or to `url` 2.5.4 or later, if depending on `idna` via `url`. (This issue was fixed in `idna` 1.0.0, but versions earlier than 1.0.3 are not recommended for other reasons.)</p>
<p>When upgrading, please take a moment to read about [alternative Unicode back ends for `idna`](https://docs.rs/crate/idna_adapter/latest).</p>
<p>If you are using Rust earlier than 1.81 in combination with SQLx…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h97m-ww89-6jmq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2944</id>
    <title>OESA-2026-2944 — rpm-ostree security update</title>
    <updated>2026-10-03T14:32:27.460993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: rpm-ostree</p>
<p>rpm-ostree is a hybrid image/package system.  It supports &amp;amp;quot;composing&amp;amp;quot; packages on a build server into an OSTree repository, which can then be replicated by client systems with atomic upgrades. Additionally, unlike many &amp;amp;quot;pure&amp;amp;quot; image systems, with rpm-ostree each client system can layer on additional packages, providing a &amp;amp;quot;best of both worlds&amp;amp;quot; approach.

Security Fix(es):</p>
<p>The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.(CVE-2023-53159)</p>
<p>Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.(CVE-2024-12224)</p>
<p>A flaw was found in OpenSSL&amp;apos;s handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string.(CVE-2025-3416)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2944"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15201-1</id>
    <title>openSUSE-SU-2025:15201-1 — python311-nh3-0.2.17-2.1 on GA media</title>
    <updated>2026-10-03T14:32:27.461025+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-nh3-0.2.17-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15201-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:17340</id>
    <title>RHSA-2025:17340 — Red Hat Security Advisory: thunderbird security update</title>
    <updated>2026-10-03T14:32:27.461043+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded firefox: thunderbird: Sandbox escape due to use-after-free in the Graphics: Canvas2D component firefox: thunderbird: Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component firefox: thunderbird: Same-origin policy bypass in the Layout component firefox: thunderbird: Incorrect boundary conditions in the JavaScript: GC component firefox: thunderbird: Integer overflow in the SVG component firefox: thunderbird: Information disclosure in the Networking: Cache component firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:17340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2024-0421</id>
    <title>RUSTSEC-2024-0421 — `idna` accepts Punycode labels that do not produce any non-ASCII when decoded</title>
    <updated>2026-10-03T14:32:27.461072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: idna</p>
<p>`idna` 0.5.0 and earlier accepts Punycode labels that do not produce any non-ASCII output, which means that either ASCII labels or the empty root label can be masked such that they appear unequal without IDNA processing or when processed with a different implementation and equal when processed with `idna` 0.5.0 or earlier.</p>
<p>Concretely, `example.org` and `xn--example-.org` become equal after processing by `idna` 0.5.0 or earlier. Also, `example.org.xn--` and `example.org.` become equal after processing by `idna` 0.5.0 or earlier.</p>
<p>In applications using `idna` (but not in `idna` itself) this may be able to lead to privilege escalation when host name comparison is part of a privilege check and the behavior is combined with a client that resolves domains with such labels instead of treating them as errors that preclude DNS resolution / URL fetching and with the attacker managing to introduce a DNS entry (and TLS certificate) for an `xn--`-masked name that turns into the name of the target when processed by `idna` 0.5.0 or earlier.</p>
<p>## Remedy</p>
<p>Upgrade to `idna` 1.0.3 or later, if depending on `idna` directly, or to `url` 2.5.4 or later, if depending on `idna` via `url`. (This issue was fixed in `idna` 1.0.0, but versions earlier than 1.0.3 are not recommended for other reasons.)</p>
<p>When upgrading, please take a moment to read about [alternative Unicode back ends for `idna`](https://docs.rs/crate/idna_adapter/latest).</p>
<p>If you are using Rust earlier than 1.81 in combination with SQLx…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2024-0421"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02809-1</id>
    <title>SUSE-SU-2025:02809-1 — Security update for rust-keylime</title>
    <updated>2026-10-03T14:32:27.461107+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rust-keylime</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02809-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12224</id>
    <title>UBUNTU-CVE-2024-12224</title>
    <updated>2026-10-03T14:32:27.461124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: rust-idna, Ubuntu:22.04:LTS: rust-idna, Ubuntu:24.04:LTS: rust-idna, Ubuntu:25.10: rust-idna, Ubuntu:26.04:LTS: rust-idna</p>
<p>Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part of a system might treat as distinct while another part of that system would treat as equivalent to another hostname.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0686</id>
    <title>WID-SEC-W-2025-0686 — IBM DataPower Gateway: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:32:27.461148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM DataPower Gateway ausnutzen, um einen Denial of Service Angriff durchzuführen, oder seine Privilegien zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0686"/>
  </entry>
</feed>
