<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:54:45.594034+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-34993</id>
    <title>BREW-aider-CVE-2026-34993 — AIOHTTP is Vulnerable to Deserialization of Untrusted Data</title>
    <updated>2026-10-02T23:54:47.035244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aider</p>
<p>### Summary</p>
<p>Using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution.</p>
<p>### Impact</p>
<p>Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications.</p>
<p>### Workaround</p>
<p>If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitise the files before loading.</p>
<p>-----</p>
<p>Patch: https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-34993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933</id>
    <title>certfr-2026-avi-0933 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T23:54:47.035346+00:00</updated>
    <content>certfr-2026-avi-0933</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-hl56908</id>
    <title>CLEANSTART-2026-HL56908 — Security fix for CVE-2026-34993 applied in: kserve-storage-controller 0.19.0-r0</title>
    <updated>2026-10-02T23:54:47.035369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: kserve-storage-controller</p>
<p>Security vulnerability affects the kserve-storage-controller package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-hl56908"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-370212</id>
    <title>EUVD-2026-370212</title>
    <updated>2026-10-02T23:54:47.035393+00:00</updated>
    <content>EUVD-2026-370212</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-370212"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34993</id>
    <title>fkie_cve-2026-34993</title>
    <updated>2026-10-02T23:54:47.035406+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34993"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jg22-mg44-37j8</id>
    <title>GHSA-jg22-mg44-37j8 — AIOHTTP is Vulnerable to Deserialization of Untrusted Data</title>
    <updated>2026-10-02T23:54:47.035431+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiohttp</p>
<p>### Summary</p>
<p>Using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution.</p>
<p>### Impact</p>
<p>Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications.</p>
<p>### Workaround</p>
<p>If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitise the files before loading.</p>
<p>-----</p>
<p>Patch: https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jg22-mg44-37j8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2562</id>
    <title>OESA-2026-2562 — python-aiohttp security update</title>
    <updated>2026-10-02T23:54:47.035457+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-aiohttp</p>
<p>Async http client/server framework (asyncio).

Security Fix(es):</p>
<p>Most applications using this function will be doing so with the user&amp;apos;s own data, so this is unlikely to affect many applications.(CVE-2026-34993)</p>
<p>If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect.(CVE-2026-47265)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2562"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10963-1</id>
    <title>openSUSE-SU-2026:10963-1 — python311-aiohttp-3.14.0-1.1 on GA media</title>
    <updated>2026-10-02T23:54:47.035479+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-aiohttp-3.14.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10963-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2104</id>
    <title>PYSEC-2026-2104</title>
    <updated>2026-10-02T23:54:47.035496+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: aiohttp</p>
<p>AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2104"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:24977</id>
    <title>RHSA-2026:24977 — Red Hat Security Advisory: RHOAI 2.25.7 - Red Hat OpenShift AI</title>
    <updated>2026-10-02T23:54:47.035517+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests golang: net/url: Memory exhaustion in query parameter parsing in net/url axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization aiohttp: aiohttp: Denial of Service via specially crafted POST request aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request keras: Keras: Arbitrary Code Execution Vulnerability Bypassing Safe Mode lodash: lodash: Arbitrary code execution via untrusted input in template imports fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID pytorch: PyTorch: Arbitrary code execution via malicious checkpoint file loading xgrammar: xgrammar: Denial of Service via multi-level nested syntax vLLM: vLLM: Server-Side Request Forgery bypass via inconsistent URL parsing onnx: ONNX: Information Disclosure via Path Traversal Vulnerability vllm: vLLM: Remote code execution due to hardcoded trust_remote_code setting onnx: ONNX: Untrusted Model Repository Warnings Suppressed python-dotenv: python-dotenv: Arbitrary file overwrite via symbolic link following immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution svgo: SVGO: Denial of Service via XML entity expansion tornado-pyth…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:24977"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22173-1</id>
    <title>SUSE-SU-2026:22173-1 — Security update for python-aiohttp</title>
    <updated>2026-10-02T23:54:47.035596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-aiohttp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22173-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34993</id>
    <title>UBUNTU-CVE-2026-34993</title>
    <updated>2026-10-02T23:54:47.035618+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: python-aiohttp, Ubuntu:Pro:18.04:LTS: python-aiohttp, Ubuntu:Pro:20.04:LTS: python-aiohttp, Ubuntu:Pro:22.04:LTS: python-aiohttp, Ubuntu:Pro:24.04:LTS: python-aiohttp, Ubuntu:25.10: python-aiohttp, Ubuntu:Pro:26.04:LTS: python-aiohttp</p>
<p>AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34993"/>
  </entry>
</feed>
