<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T00:34:11.586792+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-331228</id>
    <title>EUVD-2026-331228</title>
    <updated>2026-10-06T00:34:11.676181+00:00</updated>
    <content>EUVD-2026-331228</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-331228"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-1057</id>
    <title>fkie_cve-2025-1057</title>
    <updated>2026-10-06T00:34:11.676218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries created by previous versions, for example, 7.11.0. Specifically, older versions store agent registration data as bytes, whereas the updated registrar expects str. This issue leads to an exception when processing agent registration requests, causing the agent to fail.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-1057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9jxq-5x44-gx23</id>
    <title>GHSA-9jxq-5x44-gx23 — Keylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0</title>
    <updated>2026-10-06T00:34:11.676253+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: keylime</p>
<p>### Impact
The Keylime `registrar` implemented more strict type checking on version 7.12.0. As a result, when updated to version 7.12.0, the `registrar` will not accept the format of the data previously stored in the database by versions  &gt;= 7.8.0, raising an exception.</p>
<p>This makes the Keylime `registrar` vulnerable to a Denial-of-Service attack in an update scenario, as an attacker could populate the `registrar` database by creating multiple valid agent registrations with different UUIDs while the version is still &lt; 7.12.0. Then, when the Keylime `registrar` is updated to the 7.12.0 version, any query to the database matching any of the entries populated by the attacker will result in failure.</p>
<p>### Patches
Users should upgrade to versions &gt;= 7.12.1</p>
<p>### Workarounds
- Remove the registrar database and re-register all agents</p>
<p>### Credit</p>
<p>Reported by: Anderson Toshiyuki Sasaki/@ansasaki
Patched by: Anderson Toshiyuki Sasaki/@ansasaki</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9jxq-5x44-gx23"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14813-1</id>
    <title>openSUSE-SU-2025:14813-1 — keylime-config-7.12.1-1.1 on GA media</title>
    <updated>2026-10-06T00:34:11.676289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keylime-config-7.12.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:14813-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1488</id>
    <title>PYSEC-2026-1488 — Keylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0</title>
    <updated>2026-10-06T00:34:11.676307+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: keylime</p>
<p>### Impact
The Keylime `registrar` implemented more strict type checking on version 7.12.0. As a result, when updated to version 7.12.0, the `registrar` will not accept the format of the data previously stored in the database by versions  &gt;= 7.8.0, raising an exception.</p>
<p>This makes the Keylime `registrar` vulnerable to a Denial-of-Service attack in an update scenario, as an attacker could populate the `registrar` database by creating multiple valid agent registrations with different UUIDs while the version is still &lt; 7.12.0. Then, when the Keylime `registrar` is updated to the 7.12.0 version, any query to the database matching any of the entries populated by the attacker will result in failure.</p>
<p>### Patches
Users should upgrade to versions &gt;= 7.12.1</p>
<p>### Workarounds
- Remove the registrar database and re-register all agents</p>
<p>### Credit</p>
<p>Reported by: Anderson Toshiyuki Sasaki/@ansasaki
Patched by: Anderson Toshiyuki Sasaki/@ansasaki</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1488"/>
  </entry>
</feed>
