<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T13:48:54.603591+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-358598</id>
    <title>EUVD-2026-358598</title>
    <updated>2026-10-04T13:48:54.932477+00:00</updated>
    <content>EUVD-2026-358598</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-358598"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31812</id>
    <title>fkie_cve-2026-31812</title>
    <updated>2026-10-04T13:48:54.932521+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-31812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6xvm-j4wr-6v98</id>
    <title>GHSA-6xvm-j4wr-6v98 — Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing</title>
    <updated>2026-10-04T13:48:54.932557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: quinn-proto</p>
<p>### Summary
A remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable `quinn` versions by sending a crafted QUIC Initial packet containing malformed `quic_transport_parameters`. `In quinn-proto` parsing logic, attacker-controlled varints are decoded with `unwrap()`, so truncated encodings cause `Err(UnexpectedEnd)` and `panic`. This is reachable over the network with a single packet and no prior trust or authentication.</p>
<p>### Details
The issue is panic-on-untrusted-input in QUIC transport parameter parsing.
In `quinn-proto` (observed in `quinn-proto 0.11.13`), parsing of some transport parameters uses a fallible varint decode followed by `unwrap()`. For malformed/truncated parameter values, decode returns `UnexpectedEnd`, and `unwrap()` panics.</p>
<p>#### Observed output:
```
thread 'tokio-rt-worker' (2366474) panicked at quinn-proto/src/transport_parameters.rs:473:67:
called `Result::unwrap()` on an `Err` value: UnexpectedEnd
```</p>
<p>### PoC
#### Reproduces against the upstream Quinn server example.
1. Start server:
```
cargo run --example server -- ./
```
2. Prepare PoC client environment:
```
python3 -m venv .venv
source .venv/bin/activate
pip install aioquic
```
3. Run PoC script [attack.py](https://github.com/user-attachments/files/25741713/attack.py) against server QUIC listener (default example target shown):
```
python attack.py
```
#### Observed output
```
thread 'tokio-rt-worker' (2366903) panicked at quinn-proto/src/transport_param…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6xvm-j4wr-6v98"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10380-1</id>
    <title>openSUSE-SU-2026:10380-1 — python311-uv-0.10.11-1.1 on GA media</title>
    <updated>2026-10-04T13:48:54.932602+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-uv-0.10.11-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10380-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13545</id>
    <title>RHSA-2026:13545 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update</title>
    <updated>2026-10-04T13:48:54.932622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption aiohttp: aiohttp: Denial of Service via specially crafted POST request aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request ansible-lightspeed: Broken Object Level Authorization Leading to Cross-User AI Conversation Context Injection in Ansible Lightspeed API lodash: lodash: Arbitrary code execution via untrusted input in template imports path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions aap-controller: aap-gateway: Account hijacking and unauthorized access via unverified email linking aap-gateway: missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking net/url: Incorrect parsing of IPv6 host literals in net/url cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves crypto/x509: Incorrect enforcement of email constraints in crypto/x509 pyOpenSSL: DTLS cookie callback buffer overflow rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability svgo: SVGO: Denial of Service via XML entity expansion pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion quinn-proto: quinn-proto: Denial of Service via crafted QUIC Initial packet black: Black: Arbitrary file writes…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2026-0037</id>
    <title>RUSTSEC-2026-0037 — Denial of service in Quinn endpoints</title>
    <updated>2026-10-04T13:48:54.932686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: quinn-proto</p>
<p>Receiving QUIC transport parameters containing invalid values could lead to a panic.</p>
<p>Unfortunately the maintainers did not properly assess usage of `unwrap()` calls in the
transport parameters parsing code, and we did not have sufficient fuzzing coverage to find this
issue. We have since added a fuzzing target to cover this code path.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2026-0037"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21357-1</id>
    <title>SUSE-SU-2026:21357-1 — Security update for rust1.94</title>
    <updated>2026-10-04T13:48:54.932708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rust1.94</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21357-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31812</id>
    <title>UBUNTU-CVE-2026-31812</title>
    <updated>2026-10-04T13:48:54.932723+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: rust-quinn-proto, Ubuntu:25.10: rust-quinn-proto, Ubuntu:26.04:LTS: rust-quinn-proto</p>
<p>Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31812"/>
  </entry>
</feed>
