<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:24:27.426702+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:3254</id>
    <title>ALSA-2024:3254 — Important: container-tools:rhel8 security update</title>
    <updated>2026-10-02T13:24:28.779271+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more</p>
<p>The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.</p>
<p>Security Fix(es):</p>
<p>* buildah: full container escape at build time (CVE-2024-1753)
* golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)
* golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)
* golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786)
* jose-go: improper handling of highly compressed data (CVE-2024-28180)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:3254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01928</id>
    <title>bdu:2024-01928</title>
    <updated>2026-10-02T13:24:28.779406+00:00</updated>
    <content>bdu:2024-01928</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0514</id>
    <title>certfr-2024-avi-0514 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T13:24:28.779427+00:00</updated>
    <content>certfr-2024-avi-0514</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-sy26301</id>
    <title>CLEANSTART-2024-SY26301 — Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards</title>
    <updated>2026-10-02T13:24:28.779465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: buildah</p>
<p>Security vulnerability affects the buildah package. Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-sy26301"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-217366</id>
    <title>EUVD-2026-217366</title>
    <updated>2026-10-02T13:24:28.779504+00:00</updated>
    <content>EUVD-2026-217366</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-217366"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-28180</id>
    <title>fkie_cve-2024-28180</title>
    <updated>2026-10-02T13:24:28.779565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-28180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c5q2-7r4c-mv6g</id>
    <title>GHSA-c5q2-7r4c-mv6g — Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)</title>
    <updated>2026-10-02T13:24:28.779591+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/go-jose/go-jose/v4, Go: github.com/go-jose/go-jose/v3, Go: gopkg.in/go-jose/go-jose.v2, Go: gopkg.in/square/go-jose.v2</p>
<p>### Impact
An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). Thanks to Enze Wang@Alioth and Jianjun Chen@Zhongguancun Lab (@zer0yu and @chenjj) for reporting.</p>
<p>### Patches
The problem is fixed in the following packages and versions:
- github.com/go-jose/go-jose/v4 version 4.0.1
- github.com/go-jose/go-jose/v3 version 3.0.3
- gopkg.in/go-jose/go-jose.v2 version 2.6.3</p>
<p>The problem will not be fixed in the following package because the package is archived:
- gopkg.in/square/go-jose.v2</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c5q2-7r4c-mv6g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-28180</id>
    <title>gsd-2024-28180</title>
    <updated>2026-10-02T13:24:28.779623+00:00</updated>
    <content>gsd-2024-28180</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-28180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-28180</id>
    <title>msrc_CVE-2024-28180 — Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)</title>
    <updated>2026-10-02T13:24:28.779635+00:00</updated>
    <content>msrc_CVE-2024-28180</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-28180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1472</id>
    <title>OESA-2024-1472 — cri-o security update</title>
    <updated>2026-10-02T13:24:28.779652+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: cri-o</p>
<p>Open Container Initiative-based implementation of Kubernetes Container Runtime Interface.

Security Fix(es):

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.
(CVE-2024-28180)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13905-1</id>
    <title>openSUSE-SU-2024:13905-1 — cmctl-1.14.5-1.1 on GA media</title>
    <updated>2026-10-02T13:24:28.779674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cmctl-1.14.5-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13905-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:1772</id>
    <title>RHBA-2025:1772 — Red Hat Bug Fix Advisory: Updated 7.1 container image is now available in the Red Hat Ecosystem Catalog</title>
    <updated>2026-10-02T13:24:28.779690+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON jose: resource exhaustion jose-go: improper handling of highly compressed data envoy: HTTP/2 CPU exhaustion due to CONTINUATION frame flood go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion keepalived: Integer overflow vulnerability in vrrp_ipsets_handler</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:1772"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1987-2</id>
    <title>SUSE-SU-2024:1987-2 — Security update for skopeo</title>
    <updated>2026-10-02T13:24:28.779722+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for skopeo</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1987-2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28180</id>
    <title>Withdrawn: UBUNTU-CVE-2024-28180</title>
    <updated>2026-10-02T13:24:28.779737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:24.10: golang-github-go-jose-go-jose, Ubuntu:24.04:LTS: golang-github-go-jose-go-jose, Ubuntu:25.04: golang-github-go-jose-go-jose</p>
<p>Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0947</id>
    <title>WID-SEC-W-2024-0947 — Red Hat OpenShift: Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:24:28.779760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter authentifizierter Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0947"/>
  </entry>
</feed>
