<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T05:06:57.916592+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-12594</id>
    <title>bdu:2025-12594</title>
    <updated>2026-10-04T05:06:58.270446+00:00</updated>
    <content>bdu:2025-12594</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-12594"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0903</id>
    <title>certfr-2025-avi-0903 — De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T05:06:58.270516+00:00</updated>
    <content>certfr-2025-avi-0903</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bl34124</id>
    <title>Withdrawn: CLEANSTART-2026-BL34124 — Security fixes in strimzi-kafka-operator 0.46.1-r4</title>
    <updated>2026-10-04T05:06:58.270537+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: strimzi-kafka-operator</p>
<p>Package strimzi-kafka-operator version 0.46.1-r4 fixes 1 vulnerabilities: CVE-2025-58057</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bl34124"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-252003</id>
    <title>EUVD-2026-252003</title>
    <updated>2026-10-04T05:06:58.270572+00:00</updated>
    <content>EUVD-2026-252003</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-252003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58057</id>
    <title>fkie_cve-2025-58057</title>
    <updated>2026-10-04T05:06:58.270585+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp; clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-58057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3p8m-j85q-pgmj</id>
    <title>GHSA-3p8m-j85q-pgmj — Netty's decoders vulnerable to DoS via zip bomb style attack</title>
    <updated>2026-10-04T05:06:58.270612+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.netty:netty-codec-compression, Maven: io.netty:netty-codec</p>
<p>### Summary</p>
<p>With specially crafted input, `BrotliDecoder` and some other decompressing decoders will allocate a large number of reachable byte buffers, which can lead to denial of service.</p>
<p>### Details</p>
<p>`BrotliDecoder.decompress` has no limit in how often it calls `pull`, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is basically a zip bomb.</p>
<p>Tested on 4.1.118, but there were no changes to the decoder since.</p>
<p>### PoC</p>
<p>Run this test case with `-Xmx1G`:</p>
<p>```java
import io.netty.buffer.Unpooled;
import io.netty.channel.embedded.EmbeddedChannel;</p>
<p>import java.util.Base64;</p>
<p>public class T {
    public static void main(String[] args) {
        EmbeddedChannel channel = new EmbeddedChannel(new BrotliDecoder());
        channel.writeInbound(Unpooled.wrappedBuffer(Base64.getDecoder().decode("aPpxD1tETigSAGj6cQ8vRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oEgBo+nEPW0ROKBIAaPpxD1tETigSAGj6cQ9bRE4oE…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3p8m-j85q-pgmj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-020740</id>
    <title>jvndb-2026-020740</title>
    <updated>2026-10-04T05:06:58.270671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Hitachi Infrastructure Analytics Advisor contains the following vulnerability:

CVE-2025-48924

Hitachi Ops Center Analyzer contains the following vulnerabilities:

CVE-2025-48924

Hitachi Ops Center Analyzer viewpoint contains the following vulnerability:

CVE-2025-48924

Hitachi Ops Center Viewpoint contains the following vulnerabilities:

CVE-2023-35116, CVE-2025-24970, CVE-2025-25193, CVE-2025-48924, CVE-2025-55163, CVE-2025-58056, CVE-2025-58057</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-020740"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0022</id>
    <title>NCSC-2026-0022 — Kwetsbaarheden verholpen in Oracle Communications producten</title>
    <updated>2026-10-04T05:06:58.270692+00:00</updated>
    <content>NCSC-2026-0022</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15520-1</id>
    <title>openSUSE-SU-2025:15520-1 — netty-4.1.126-1.1 on GA media</title>
    <updated>2026-10-04T05:06:58.270757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>netty-4.1.126-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15520-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:17187</id>
    <title>RHSA-2025:17187 — Red Hat Security Advisory: Red Hat build of Quarkus 3.15.7 release and security update</title>
    <updated>2026-10-04T05:06:58.270774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:17187"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58057</id>
    <title>UBUNTU-CVE-2025-58057</title>
    <updated>2026-10-04T05:06:58.270793+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: netty, Ubuntu:Pro:16.04:LTS: netty, Ubuntu:Pro:18.04:LTS: netty, Ubuntu:Pro:20.04:LTS: netty, Ubuntu:22.04:LTS: netty, Ubuntu:24.04:LTS: netty, Ubuntu:25.10: netty</p>
<p>Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers &amp; clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2098</id>
    <title>WID-SEC-W-2025-2098 — IBM SPSS: Mehrere Schwachstellen</title>
    <updated>2026-10-04T05:06:58.270826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM SPSS ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2098"/>
  </entry>
</feed>
