<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:17:15.870684+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-03918</id>
    <title>bdu:2025-03918</title>
    <updated>2026-10-03T03:17:16.033026+00:00</updated>
    <content>bdu:2025-03918</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-03918"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2024-34069</id>
    <title>BREW-aws-sam-cli-CVE-2024-34069 — Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain</title>
    <updated>2026-10-03T03:17:16.033110+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aws-sam-cli</p>
<p>The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to interact with a domain and subdomain they control, and enter the debugger PIN, but if they are successful it allows access to the debugger even if it is only running on localhost. This also requires the attacker to guess a URL in the developer's application that will trigger the debugger.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2024-34069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</id>
    <title>certfr-2024-avi-0579 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T03:17:16.033178+00:00</updated>
    <content>certfr-2024-avi-0579</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261</id>
    <title>Withdrawn: CLEANSTART-2026-AZ09261 — Security fixes for CVE-2023-46136, CVE-2024-12797, CVE-2024-34069, CVE-2024-49766, CVE-2024-49767, CVE-2025-62727, CVE-…</title>
    <updated>2026-10-03T03:17:16.033199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: airflow-3</p>
<p>Multiple security vulnerabilities affect the airflow-3 package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-218587</id>
    <title>EUVD-2026-218587</title>
    <updated>2026-10-03T03:17:16.033230+00:00</updated>
    <content>EUVD-2026-218587</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-218587"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-34069</id>
    <title>fkie_cve-2024-34069</title>
    <updated>2026-10-03T03:17:16.033243+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to interact with a domain and subdomain they control, and enter the debugger PIN, but if they are successful it allows access to the debugger even if it is only running on localhost. This also requires the attacker to guess a URL in the developer's application that will trigger the debugger. This vulnerability is fixed in 3.0.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-34069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2g68-c3qc-8985</id>
    <title>GHSA-2g68-c3qc-8985 — Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain</title>
    <updated>2026-10-03T03:17:16.033269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Werkzeug</p>
<p>The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to interact with a domain and subdomain they control, and enter the debugger PIN, but if they are successful it allows access to the debugger even if it is only running on localhost. This also requires the attacker to guess a URL in the developer's application that will trigger the debugger.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2g68-c3qc-8985"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-34069</id>
    <title>msrc_CVE-2024-34069 — Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution</title>
    <updated>2026-10-03T03:17:16.033291+00:00</updated>
    <content>msrc_CVE-2024-34069</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-34069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1997</id>
    <title>OESA-2025-1997 — python-werkzeug security update</title>
    <updated>2026-10-03T03:17:16.033309+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: python-werkzeug</p>
<p>A comprehensive WSGI web application library

Security Fix(es):</p>
<p>Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are appended chunk by chunk into internal bytearray and lookup for boundary is performed on growing buffer. This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. This vulnerability has been patched in version 3.0.1.(CVE-2023-46136)</p>
<p>Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer&amp;apos;s machine under some circumstances. This requires the attacker to get the developer to interact with a domain and subdomain they control, and enter the debugger PIN, but if they are successful it allows access to the debugger even if it is only running on localhost. This also requires the attacker to guess a URL in the developer&amp;apos;s application that will trigger the debugger. This vulnerability is fixed in 3.0.3.(CVE-2024-34069)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1997"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14042-1</id>
    <title>openSUSE-SU-2024:14042-1 — python310-Werkzeug-3.0.3-1.1 on GA media</title>
    <updated>2026-10-03T03:17:16.033351+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-Werkzeug-3.0.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14042-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2043</id>
    <title>PYSEC-2026-2043 — Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domain</title>
    <updated>2026-10-03T03:17:16.033386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: werkzeug</p>
<p>The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to interact with a domain and subdomain they control, and enter the debugger PIN, but if they are successful it allows access to the debugger even if it is only running on localhost. This also requires the attacker to guess a URL in the developer's application that will trigger the debugger.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2043"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:10696</id>
    <title>RHSA-2024:10696 — Red Hat Security Advisory: Red Hat OpenStack Platform 16.2 (python-werkzeug) security update</title>
    <updated>2026-10-03T03:17:16.033431+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-werkzeug: user may execute code on a developer's machine</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:10696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1572-1</id>
    <title>SUSE-SU-2024:1572-1 — Security update for python-Werkzeug</title>
    <updated>2026-10-03T03:17:16.033451+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Werkzeug</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1572-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-34069</id>
    <title>UBUNTU-CVE-2024-34069</title>
    <updated>2026-10-03T03:17:16.033468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: python-werkzeug, Ubuntu:Pro:18.04:LTS: python-werkzeug, Ubuntu:20.04:LTS: python-werkzeug, Ubuntu:22.04:LTS: python-werkzeug, Ubuntu:24.04:LTS: python-werkzeug</p>
<p>Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to interact with a domain and subdomain they control, and enter the debugger PIN, but if they are successful it allows access to the debugger even if it is only running on localhost. This also requires the attacker to guess a URL in the developer's application that will trigger the debugger. This vulnerability is fixed in 3.0.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-34069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1642</id>
    <title>WID-SEC-W-2024-1642 — Oracle Communications: Mehrere Schwachstellen</title>
    <updated>2026-10-03T03:17:16.033499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1642"/>
  </entry>
</feed>
