<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T07:05:02.077510+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-10993</id>
    <title>bdu:2025-10993</title>
    <updated>2026-10-04T07:05:02.285493+00:00</updated>
    <content>bdu:2025-10993</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-10993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0754</id>
    <title>certfr-2025-avi-0754 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-04T07:05:02.285556+00:00</updated>
    <content>certfr-2025-avi-0754</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0754"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cl03013</id>
    <title>Withdrawn: CLEANSTART-2026-CL03013 — Netty is an asynchronous, event-driven network application framework</title>
    <updated>2026-10-04T07:05:02.285577+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-hive</p>
<p>Multiple security vulnerabilities affect the apache-hive package. Netty is an asynchronous, event-driven network application framework. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cl03013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-260033</id>
    <title>EUVD-2026-260033</title>
    <updated>2026-10-04T07:05:02.285608+00:00</updated>
    <content>EUVD-2026-260033</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-260033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55163</id>
    <title>fkie_cve-2025-55163</title>
    <updated>2026-10-04T07:05:02.285622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-55163"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-prj3-ccx8-p6x4</id>
    <title>GHSA-prj3-ccx8-p6x4 — Netty affected by MadeYouReset HTTP/2 DDoS vulnerability</title>
    <updated>2026-10-04T07:05:02.285645+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.netty:netty-codec-http2, Maven: io.grpc:grpc-netty-shaded</p>
<p>Below is a technical explanation of a newly discovered vulnerability in HTTP/2, which we refer to as “MadeYouReset.”</p>
<p>### MadeYouReset Vulnerability Summary
The MadeYouReset DDoS vulnerability is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service.</p>
<p>### Mechanism
The vulnerability uses malformed HTTP/2 control frames, or malformed flow, in order to make the server reset streams created by the client (using the RST_STREAM frame). 
The vulnerability could be triggered by several primitives, defined by the RFC of HTTP/2 (RFC 9113). The Primitives are:
1. WINDOW_UPDATE frame with an increment of 0 or an increment that makes the window exceed 2^31 - 1. (section 6.9 + 6.9.1)
2. HEADERS or DATA frames sent on a half-closed (remote) stream (which was closed using the END_STREAM flag). (note that for some implementations it's possible a CONTINUATION frame to trigger that as well - but it's very rare). (Section 5.1)
3. PRIORITY frame with a length other than 5. (section 6.3)
From our experience, the primitives are likely to exist in the decreasing order listed above.
Note that based on the implementation of the library, other primitives (which are not defined by the RFC) might exist - meaning scenarios in which RST_STREAM is not supposed to be sent, but in the implementation it does. On the other hand - some RFC-defined primi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-prj3-ccx8-p6x4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-020740</id>
    <title>jvndb-2026-020740</title>
    <updated>2026-10-04T07:05:02.285702+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Hitachi Infrastructure Analytics Advisor contains the following vulnerability:

CVE-2025-48924

Hitachi Ops Center Analyzer contains the following vulnerabilities:

CVE-2025-48924

Hitachi Ops Center Analyzer viewpoint contains the following vulnerability:

CVE-2025-48924

Hitachi Ops Center Viewpoint contains the following vulnerabilities:

CVE-2023-35116, CVE-2025-24970, CVE-2025-25193, CVE-2025-48924, CVE-2025-55163, CVE-2025-58056, CVE-2025-58057</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-020740"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0022</id>
    <title>NCSC-2026-0022 — Kwetsbaarheden verholpen in Oracle Communications producten</title>
    <updated>2026-10-04T07:05:02.285722+00:00</updated>
    <content>NCSC-2026-0022</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15483-1</id>
    <title>openSUSE-SU-2025:15483-1 — netty-4.1.124-1.1 on GA media</title>
    <updated>2026-10-04T07:05:02.285782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>netty-4.1.124-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15483-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:14004</id>
    <title>RHSA-2025:14004 — Red Hat Security Advisory: Red Hat build of Quarkus 3.15.6.SP1 security update</title>
    <updated>2026-10-04T07:05:02.285799+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:14004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:03021-1</id>
    <title>SUSE-SU-2025:03021-1 — Security update for netty</title>
    <updated>2026-10-04T07:05:02.285815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for netty</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:03021-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55163</id>
    <title>UBUNTU-CVE-2025-55163</title>
    <updated>2026-10-04T07:05:02.285829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty, Ubuntu:Pro:22.04:LTS: netty, Ubuntu:24.04:LTS: netty, Ubuntu:Pro:24.04:LTS: netty, Ubuntu:25.10: netty</p>
<p>Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-55163"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1830</id>
    <title>WID-SEC-W-2025-1830 — http/2 Implementierungen: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-04T07:05:02.285861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in verschiednen http/2 Implementierungen ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1830"/>
  </entry>
</feed>
