<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:24:58.995483+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330228</id>
    <title>EUVD-2026-330228</title>
    <updated>2026-10-02T17:24:59.001187+00:00</updated>
    <content>EUVD-2026-330228</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330228"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40211</id>
    <title>fkie_cve-2026-40211</title>
    <updated>2026-10-02T17:24:59.001218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it might be possible to open enough concurrent DoH3 streams to trigger an out-of-memory condition, resulting in a denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8mqg-g8g6-fvw6</id>
    <title>GHSA-8mqg-g8g6-fvw6</title>
    <updated>2026-10-02T17:24:59.001249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it might be possible to open enough concurrent DoH3 streams to trigger an out-of-memory condition, resulting in a denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8mqg-g8g6-fvw6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11411-1</id>
    <title>openSUSE-SU-2026:11411-1 — dnsdist-2.0.7-1.1 on GA media</title>
    <updated>2026-10-02T17:24:59.001266+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dnsdist-2.0.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11411-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23123-1</id>
    <title>SUSE-SU-2026:23123-1 — Security update for dnsdist</title>
    <updated>2026-10-02T17:24:59.001285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for dnsdist</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23123-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40211</id>
    <title>UBUNTU-CVE-2026-40211</title>
    <updated>2026-10-02T17:24:59.001300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: dnsdist, Ubuntu:Pro:18.04:LTS: dnsdist, Ubuntu:Pro:20.04:LTS: dnsdist, Ubuntu:Pro:22.04:LTS: dnsdist, Ubuntu:Pro:24.04:LTS: dnsdist, Ubuntu:25.10: dnsdist, Ubuntu:26.04:LTS: dnsdist</p>
<p>An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it might be possible to open enough concurrent DoH3 streams to trigger an out-of-memory condition, resulting in a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2091</id>
    <title>WID-SEC-W-2026-2091 — PowerDNS: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:24:59.001329+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in PowerDNS ausnutzen, um Denial-of-Service-Zustände herbeizuführen, DNS-Caches zu manipulieren, Sicherheitsprüfungen zu umgehen, vertrauliche Informationen offenzulegen, DNSSEC-Validierungen zu beeinträchtigen oder die Integrität und Verfügbarkeit der DNS-Auflösung zu beeinflussen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2091"/>
  </entry>
</feed>
