<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T04:11:08.044694+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-kc30064</id>
    <title>Withdrawn: CLEANSTART-2026-KC30064 — Security fixes in akhq 0.27.1-r5</title>
    <updated>2026-10-04T04:11:08.100844+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: akhq</p>
<p>Package akhq version 0.27.1-r5 fixes 27 vulnerabilities: CVE-2026-58062, CVE-2026-59638, CVE-2026-59646, CVE-2026-12802, CVE-2026-59639...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-kc30064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335498</id>
    <title>EUVD-2026-335498</title>
    <updated>2026-10-04T04:11:08.100907+00:00</updated>
    <content>EUVD-2026-335498</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44241</id>
    <title>fkie_cve-2026-44241</title>
    <updated>2026-10-04T04:11:08.100924+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, 3.10.6, and 3.8.14, TimeConverterRegistrar caches DateTimeFormatter instances in an unbounded ConcurrentHashMap&lt;String, DateTimeFormatter&gt; whose key is derived from the @Format annotation pattern concatenated with the locale from the HTTP Accept-Language header. Because Locale.forLanguageTag() accepts arbitrary BCP 47 private-use extensions (en-x-a001, en-x-a002, …), an unauthenticated attacker can generate an unlimited number of unique cache keys by sending requests with novel locale tags, growing the cache until heap memory is exhausted and the JVM crashes. This vulnerability is fixed in 4.10.22, 3.10.6, and 3.8.14.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44241"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8hjv-92q9-g4xj</id>
    <title>GHSA-8hjv-92q9-g4xj — Micronaut has unbounded `formattersCache` in `TimeConverterRegistrar` that Allows Memory Exhaustion via `Accept-Languag…</title>
    <updated>2026-10-04T04:11:08.100958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: io.micronaut:micronaut-context</p>
<p>## Summary</p>
<p>`TimeConverterRegistrar` caches `DateTimeFormatter` instances in an unbounded `ConcurrentHashMap&lt;String, DateTimeFormatter&gt;` whose key is derived from the `@Format` annotation pattern concatenated with the locale from the HTTP `Accept-Language` header. Because `Locale.forLanguageTag()` accepts arbitrary BCP 47 private-use extensions (`en-x-a001`, `en-x-a002`, …), an unauthenticated attacker can generate an unlimited number of unique cache keys by sending requests with novel locale tags, growing the cache until heap memory is exhausted and the JVM crashes. This is structurally identical to the recently patched GHSA-2hcp-gjrf-7fhc (`DefaultHtmlErrorResponseBodyProvider`), but `TimeConverterRegistrar.formattersCache` was not covered by that fix.</p>
<p>## Details</p>
<p>The vulnerable cache is declared in `context/src/main/java/io/micronaut/runtime/converters/time/TimeConverterRegistrar.java` at line 123:</p>
<p>```java
// TimeConverterRegistrar.java:123
private final Map&lt;String, DateTimeFormatter&gt; formattersCache = new ConcurrentHashMap&lt;&gt;();
```</p>
<p>The `getFormatter` method at line 434 inserts into this map with no eviction or size limit:</p>
<p>```java
// TimeConverterRegistrar.java:434-443
private DateTimeFormatter getFormatter(String pattern, ConversionContext context) {
    var key = pattern + context.getLocale();        // locale from Accept-Language header
    var cachedFormatter = formattersCache.get(key);
    if (cachedFormatter != null) {
        return cachedFormatter;
    }
    v…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8hjv-92q9-g4xj"/>
  </entry>
</feed>
